- 28
- 0
- 约5.27万字
- 约 17页
- 2017-06-05 发布于河南
- 举报
如何简单获取目标网站的数据库(国外英文资料)
如何简单获取目标网站的数据库(国外英文资料)
SQL injection has been around for a long time, and were looking for bugs to get things in the database, such as username and password. (of course, the MSSQL database is also available for access). Wouldnt it be nice if we could get the entire database without injecting it? The mob became a more simple intrusion than an injection.
About BaoKu method, experts often raise in the invasion of the article, but many are one has brought, some just talk a certain way, also is more methods were discussed. A recent article in the use of the % 5c is a summary of the mob, so it is widely circulated in the Internet. But still there is no principle, and the conclusion is just that experience, rather than that, is a decision to talk about the principles and laws of the mob.
One, about the % 5c mob:
This approach is known as a flash mob, and it has been popular for a while (and as you know more people, your defenses are strengthened, not as effective as before). This is a simple way of saying that when you open a web page, change the / in the address to % 5c and submit it, and then you can break the path of the database.
In fact, not all sites are effective, it is necessary to asp? Id = this page address (for the behavior of the call database), if you confirm the web database have a call, behind can not so, for example chklogin. Asp can also. (of course, there are other conditions, too.)
Let me give you an example,
_blank _blank 6/yddown%5cview.asp? Id = 3
Change the second / to % 5c
_blank _blank 6/yddown%5cview.asp? Id = 3
The following results will be submitted as follows:
Microsoft JET Database Engine errorD: \ 111 \ admin \ rds_dbd213fg.mdb is not a valid path. Determine whether the path name is spelled correctly and whether it is connected to the server where the file is stored.
/ yddown/conn. Asp,
(note: this is a website, black against the laboratory BaoKu is they deliberately open, because its mark is not injection, but after entering t
您可能关注的文档
最近下载
- 林大心理学课程.ppt VIP
- PICC穿刺点感染个案护理.pptx VIP
- 河南苗氏人口村落分布统计.docx VIP
- 课程总结-经济209.pptx VIP
- 【高清可复制】昆明市市政排水管道和附属构筑物设计安装图集2013版.pdf VIP
- 第一单元第1课《入古出新》课件-2025-2026学年人美版初中美术八年级下册.pptx VIP
- 全圆针梁钢模台车组件详解与技术性能介绍.pdf VIP
- 新教科版五年级下册科学全册复习资料知识点(重点版).doc VIP
- 机器人视觉技术及应用教学课件(共8章)第8章 机器视觉系统项目实践.pptx VIP
- 摩托罗拉MOTO602数字无绳电话说明书.pdf VIP
原创力文档

文档评论(0)