当前位置:网站首页>【SQL注入】联合查询(最简单的注入方法)
【SQL注入】联合查询(最简单的注入方法)
2022-07-03 04:33:00 【黑色地带(崛起)】
目录
一、介绍:
是最简单的一种注入方法
联合查询注入 报错查询注入 布尔型注入 延时注入 堆叠查询注入
二、原理:
就是可合并多个查询的结果的合集,顾名思义,就是将一个表追加到另一个表后,从而实现查询结果组合在一起。
在URL的参数位置中,将构造的语句注入到参数位置中
select (原始查询内容) union select (构造的内容)
三、前提条件
①存在注入点,即未被过滤
②有显示位,即能回显结果
③两表列数相同,即order by 或union select 去判断列 数
④数据类型相同
四、利用过程
1、判断是否存在注入点
(1)在参数位置修改参数值,eg:id=1修改为2后是否数据改变
(2)插入单、双引号的检测方法(常用),未闭合的单引号会引起SQL语句单引号未闭合的错误提示
2、判断注入点还是整形或字符型
(1)数字型:通过and 1=1
(2)字符串型:闭合单引号测试语句'and'1'='1进行判断
3、判断查询列数
order by 或 union select
4、判断显示位
报错回显,用不存在的id=-1加上union select……
或者and1=2加上union select……
下面的就都是通过报错后,在显示位构造要查找的信息
5、获取所有数据库名
6、获取数据库所有表名
7、获取字段名
8、获取字段中的数据
边栏推荐
- 2022 t elevator repair simulation examination question bank and t elevator repair simulation examination question bank
- Games101 Lesson 9 shading 3 Notes
- 使用BENCHMARKSQL工具对KingbaseES预热数据时执行:select sys_prewarm(‘NDX_OORDER_2 ‘)报错
- 会员积分商城系统的功能介绍
- Employee attendance management system based on SSM
- Internationalization and localization, dark mode and dark mode in compose
- SSM based campus part-time platform for College Students
- Which Bluetooth headset is cost-effective? Four Bluetooth headsets with high cost performance are recommended
- C language series - Section 3 - functions
- Youdao cloud notes
猜你喜欢

2022 P cylinder filling test content and P cylinder filling simulation test questions

arthas watch 抓取入参的某个字段/属性

Preliminary cognition of C language pointer

Number of 1 in binary (simple difficulty)

Which Bluetooth headset is good about 400? Four Bluetooth headsets with strong noise reduction are recommended

Employee attendance management system based on SSM
![[literature reading] sparse in deep learning: practicing and growth for effective information and training in NN](/img/7e/50fa6f65b5a4f0bb60909f57daff56.png)
[literature reading] sparse in deep learning: practicing and growth for effective information and training in NN

Internationalization and localization, dark mode and dark mode in compose
![[Thesis Writing] how to write the overall design of JSP tourism network](/img/02/841e8870c2ef871c182b9bb8252a83.jpg)
[Thesis Writing] how to write the overall design of JSP tourism network

BMZCTF simple_ pop
随机推荐
使用BENCHMARKSQL工具对KingbaseES执行测试时报错funcs sh file not found
Which Bluetooth headset is cost-effective? Four Bluetooth headsets with high cost performance are recommended
有道云笔记
[PCL self study: filtering] introduction and use of various filters in PCL (continuously updated)
Priv-app permission异常
Employee attendance management system based on SSM
Know that Chuangyu cloud monitoring - scanv Max update: Ecology OA unauthorized server request forgery and other two vulnerabilities can be detected
Two drawing interfaces - 1 Matlab style interface
AWS VPC
2022 registration examination for safety production management personnel of hazardous chemical production units and examination skills for safety production management personnel of hazardous chemical
Leetcode simple question: check whether the array is sorted and rotated
金仓KFS数据双向同步场景部署
Leetcode simple problem delete an element to strictly increment the array
Reptile exercise 02
多板块轮动策略编写技巧----策略编写学习教材
Why should programmers learn microservice architecture if they want to enter a large factory?
Triangular rasterization
跨境电商多商户系统怎么选
Integration of Android high-frequency interview questions (including reference answers)
商城系统搭建完成后需要设置哪些功能