当前位置:网站首页>记一次api接口SQL注入实战
记一次api接口SQL注入实战
2022-07-06 09:22:00 【又懒有菜】
目录
0x01 思路:google hacking语法asmx?wsdl
指导 某迪导师
0x01 思路:google hacking语法asmx?wsdl
点击url:domain/WebServices/InboxWS.asmx

0x02 发现两个接口 并且能够异地调用

火狐中抓包
测试
0x03 抓包repeat判断
四个参数加 ' 报nynax错误 由此推断可能存在sql注入
最后用sqlmap跑出sqlserver数据库 延时注入
这里由于接近12点接口服务不稳定 先就搞到这里
0x04 暴库
sqlmap语法
python sqlmap.py -r 1.txt --batch
python sqlmap.py -r 1.txt --dbs --batch
点到为止
边栏推荐
- 7-15 h0161. Find the greatest common divisor and the least common multiple (PTA program design)
- Implementation principle of automatic capacity expansion mechanism of ArrayList
- 7-7 7003 combination lock (PTA program design)
- Programme de jeu de cartes - confrontation homme - machine
- Matlab opens M file garbled solution
- Strengthen basic learning records
- [insert, modify and delete data in the headsong educator data table]
- [au cours de l'entrevue] - Comment expliquer le mécanisme de transmission fiable de TCP
- MySQL lock summary (comprehensive and concise + graphic explanation)
- JS several ways to judge whether an object is an array
猜你喜欢

This time, thoroughly understand the MySQL index

实验六 继承和多态

HackMyvm靶机系列(1)-webmaster

Leetcode. 3. Longest substring without repeated characters - more than 100% solution

扑克牌游戏程序——人机对抗

"Gold, silver and four" job hopping needs to be cautious. Can an article solve the interview?

Programme de jeu de cartes - confrontation homme - machine

1143_ SiCp learning notes_ Tree recursion

Record a penetration of the cat shed from outside to inside. Library operation extraction flag

3. Input and output functions (printf, scanf, getchar and putchar)
随机推荐
7-11 机工士姆斯塔迪奥(PTA程序设计)
7-9 制作门牌号3.0(PTA程序设计)
Strengthen basic learning records
7-1 output all primes between 2 and n (PTA programming)
7-8 7104 约瑟夫问题(PTA程序设计)
简单理解ES6的Promise
Middleware vulnerability recurrence Apache
The difference between abstract classes and interfaces
Canvas foundation 1 - draw a straight line (easy to understand)
Using qcommonstyle to draw custom form parts
The difference between overloading and rewriting
Detailed explanation of redis' distributed lock principle
强化学习基础记录
撲克牌遊戲程序——人機對抗
强化学习基础记录
TypeScript快速入门
HackMyvm靶机系列(7)-Tron
7-7 7003 组合锁(PTA程序设计)
. Net6: develop modern 3D industrial software based on WPF (2)
HackMyvm靶机系列(4)-vulny