基本社工查询(数据+代码)

CREATE TABLE IF NOT EXISTS `users` ( 
  `id` int(10) unsigned NOT NULL AUTO_INCREMENT, 
  `unamename` char(20) NOT NULL DEFAULT '', 
  `password` char(32) NOT NULL DEFAULT '', 
  `email` char(30) NOT NULL DEFAULT '', 
  `salt` char(30) NOT NULL DEFAULT '', 
  PRIMARY KEY (`id`) 
) ENGINE=MyISAM DEFAULT CHARSET=gbk;

数据库结构

查询代码

 
  
 
社工库查询 
 
  
 
社工社工库查询




method="post"> 请输入帐号:
id 帐号 密码 邮箱

sqlin.php

|<|=|in|like)|\\/\\*.+?\\*\\/|<\\s*script\\b|\\bEXEC\\b|UNION.+?SELECT|UPDATE.+?SET|INSERT\\s+INTO.+?VALUES|(SELECT|DELETE).+?FROM|(CREATE|ALTER|DROP|TRUNCATE)\\s+(TABLE|DATABASE)"; 
$postfilter="\\b(and|or)\\b.{1,6}?(=|>|<|\\bin\\b|\\blike\\b)|\\/\\*.+?\\*\\/|<\\s*script\\b|\\bEXEC\\b|UNION.+?SELECT|UPDATE.+?SET|INSERT\\s+INTO.+?VALUES|(SELECT|DELETE).+?FROM|(CREATE|ALTER|DROP|TRUNCATE)\\s+(TABLE|DATABASE)"; 
$cookiefilter="\\b(and|or)\\b.{1,6}?(=|>|<|\\bin\\b|\\blike\\b)|\\/\\*.+?\\*\\/|<\\s*script\\b|\\bEXEC\\b|UNION.+?SELECT|UPDATE.+?SET|INSERT\\s+INTO.+?VALUES|(SELECT|DELETE).+?FROM|(CREATE|ALTER|DROP|TRUNCATE)\\s+(TABLE|DATABASE)"; 
function StopAttack($StrFiltKey,$StrFiltValue,$ArrFiltReq){ 
  
if(is_array($StrFiltValue)) 
{ 
$StrFiltValue=implode($StrFiltValue); 
} 
if (preg_match("/".$ArrFiltReq."/is",$StrFiltValue)==1){ 
//slog 
(" 
操作IP: ".$_SERVER["REMOTE_ADDR"]."
操作时间: ".strftime("%Y-%m-%d %H:%M:%S")."
操作页面:".$_SERVER["PHP_SELF"]."
提交方式: ".$_SERVER["REQUEST_METHOD"]."
提交参数: ".$StrFiltKey."
提交数据: ".$StrFiltValue); 
print "F4ck Team notice:Illegal operation!"; 
exit(); 
} 
} 
//$ArrPGC=array_merge($_GET,$_POST,$_COOKIE); 
foreach($_GET as $key=>$value){ 
StopAttack($key,$value,$getfilter); 
} 
foreach($_POST as $key=>$value){ 
StopAttack($key,$value,$postfilter); 
} 
foreach($_COOKIE as $key=>$value){ 
StopAttack($key,$value,$cookiefilter); 
} 
if (file_exists('sqlin.php')) { 
echo "请重命名文件sqlin.php,防止黑客利用 
"; 
die(); 
} 
function slog($logs) 
{ 
$toppath=$_SERVER["DOCUMENT_ROOT"]."/log.htm"; 
$Ts=fopen($toppath,"a+"); 
fputs($Ts,$logs."\r\n"); 
fclose($Ts); 
} 
?>
点赞