当前位置:网站首页>BUUCTF刷题笔记——[极客大挑战 2019]EasySQL 1
BUUCTF刷题笔记——[极客大挑战 2019]EasySQL 1
2022-07-06 02:58:00 【永远是少年啊】
今天继续刷BUUCTF的题,今天解决[极客大挑战 2019]EasySQL 1。
一、题目基本信息

我们进入链接,打开网站,结果如下所示:
二、解题思路
从上图中可以看出,我们的目标站点是一个登录页面。结合题目信息,我们可以猜测该题目是解题为SQL注入方向。
我们简单的在用户名处尝试带有单引号的用户名admin’,结果如下所示:
从上图可以看出,这是一个简单的报错的SQL注入。
接下来,我们尝试在刚才的用户名后面添加一个#,尝试过滤后面的内容,结果如下所示:
三、拿到flag
从上述尝试很容易分析处,这个题目非常简单,基本上没有进行过滤,我们尝试使用万能密码,用户名admin’ or 1=1#,密码随意,点击登录后,结果如下所示:
从上图中可以看出,我们成功拿到了该题目的flag。
原创不易,转载请说明出处:https://blog.csdn.net/weixin_40228200
边栏推荐
- [kubernetes series] learn the exposed application of kubernetes service security
- 【Unity3D】GUI控件
- [ruoyi] enable Mini navigation bar
- Microservice registration and discovery
- Era5 reanalysis data download strategy
- [network security interview question] - how to penetrate the test file directory through
- PMP practice once a day | don't get lost in the exam -7.5
- [matlab] access of variables and files
- CSP numeric sort
- 【指针训练——八道题】
猜你喜欢

MySQL advanced notes
![[network security interview question] - how to penetrate the test file directory through](/img/48/be645442c8ff4cc5417c115963b217.jpg)
[network security interview question] - how to penetrate the test file directory through
![[Yunju entrepreneurial foundation notes] Chapter II entrepreneur test 11](/img/6a/398d9cceecdd9d7c9c4613d8b5ca27.jpg)
[Yunju entrepreneurial foundation notes] Chapter II entrepreneur test 11

My C language learning record (blue bridge) -- under the pointer

Shell script updates stored procedure to database
![Huawei, H3C, Cisco command comparison, mind map form from the basic, switching, routing three directions [transferred from wechat official account network technology alliance station]](/img/3b/385d19e51340ecd6281df47b39f40c.png)
Huawei, H3C, Cisco command comparison, mind map form from the basic, switching, routing three directions [transferred from wechat official account network technology alliance station]

米家、涂鸦、Hilink、智汀等生态哪家强?5大主流智能品牌分析

Deeply analyze the chain 2+1 mode, and subvert the traditional thinking of selling goods?

#PAT#day10

Apt installation ZABBIX
随机推荐
[ruoyi] set theme style
建模规范:命名规范
Game theory matlab
Reverse repackaging of wechat applet
Daily question brushing plan-2-13 fingertip life
Installation and use tutorial of cobaltstrike-4.4-k8 modified version
[network security interview question] - how to penetrate the test file directory through
A copy can also produce flowers
[Yunju entrepreneurial foundation notes] Chapter II entrepreneur test 21
1. Dynamic parameters of function: *args, **kwargs
codeforces每日5題(均1700)-第六天
DDoS "fire drill" service urges companies to be prepared
[Yunju entrepreneurial foundation notes] Chapter II entrepreneur test 6
Huawei, H3C, Cisco command comparison, mind map form from the basic, switching, routing three directions [transferred from wechat official account network technology alliance station]
Communication between microservices
Microsoft speech synthesis assistant v1.3 text to speech tool, real speech AI generator
Function knowledge points
Technology sharing | what if Undo is too big
How does yyds dry inventory deal with repeated messages in the consumption process?
2.13 simulation summary