当前位置:网站首页>SQL injection cookie injection
SQL injection cookie injection
2022-07-07 05:04:00 【In a word, the Trojan horse (the growth road of Wang an Xiaobai)】
One 、 What is? cookie
cookie Sent by the server and stored in the browser , So the next time this unique visitor comes back to the web server , This information can be read back from the browser . It's very useful , Let the browser remember the specific information of this visitor , Like the location of the last visit 、 Time spent or user preferences
Two 、cookie Injection principle
cookie The principle of injection and others SQL The principle of injection is the same , It's just that we used the previous parameters get perhaps post Mode submission , and cookie Injection parameters we use cookie Submitted by .
3、 ... and 、cookie Injected demo
1. Start by opening sqlilabs/Less-20/index.php, The account number and password entered are admin Log in .
2. Enter the page to see the information displayed by the display bit , You can see that the backend gets the information from cookie Information about
3. open burp suite, Click Run in the browser , Grab the data packet as shown in the figure below
4. stay burp suite Of repeater Module for editing
5. Try to close according to the returned error message
payload:Cookie: uname=admin'and 1=1 --+ Found no error reported . You can do it here cookie Inject
6. Get the current database name ( You can use Boolean blind injection or error reporting injection , Error reporting injection is used here )
payload:Cookie: uname=admin'and updatexml(1,concat(0x7e,(select database()),0x7e),1) --+
View error message :
边栏推荐
- R descriptive statistics and hypothesis testing
- AttributeError: module ‘torch._ C‘ has no attribute ‘_ cuda_ setDevice‘
- JS also exports Excel
- 3GPP信道模型路损基础知识
- 一文搞懂常见的网络I/O模型
- 【PHP SPL笔记】
- Stm32f103ze+sht30 detection of ambient temperature and humidity (IIC simulation sequence)
- 如何设计 API 接口,实现统一格式返回?
- Vscode automatically adds a semicolon and jumps to the next line
- offer如何选择该考虑哪些因素
猜你喜欢
U++ game learning notes
Mysql database (basic)
Field data acquisition and edge calculation scheme of CNC machine tools
Function pointer and pointer function in C language
JDBC link Oracle reference code
A simple and beautiful regression table is produced in one line of code~
Gavin teacher's perception of transformer live class - rasa project actual combat e-commerce retail customer service intelligent business dialogue robot microservice code analysis and dialogue experim
No experts! Growth secrets for junior and intermediate programmers and "quasi programmers" who are still practicing in Universities
Ansible overview and module explanation (you just passed today, but yesterday came to your face)
Why do many people misunderstand technical debt
随机推荐
AOSP ~Binder 通信原理 (一) - 概要
sublime使用技巧
STM32封装ESP8266一键配置函数:实现实现AP模式和STA模式切换、服务器与客户端创建
最全常用高数公式
Analysis -- MySQL statement execution process & MySQL architecture
高手勿进!写给初中级程序员以及还在大学修炼的“准程序员”的成长秘籍
Development thoughts of adding new requirements in secondary development
ThinkPHP关联预载入with
Monitoring cannot be started after Oracle modifies the computer name
Analyse approfondie de kubebuilder
Ansible中的inventory主机清单(预祝你我有数不尽的鲜花和浪漫)
U++4 interface learning notes
AttributeError: module ‘torch._ C‘ has no attribute ‘_ cuda_ setDevice‘
R descriptive statistics and hypothesis testing
Function pointer and pointer function in C language
【opencv】图像形态学操作-opencv标记不同连通域的位置
[ArcGIS tutorial] thematic map production - population density distribution map - population density analysis
NiO related knowledge points (I)
3GPP信道模型路损基础知识
《二》标签