当前位置:网站首页>sqli-labs第1关
sqli-labs第1关
2022-07-02 06:29:00 【藤原千花的败北】
草草写的一篇记录文章
概念
SQL注入就是将恶意代码拼接到业务正常的数据库查询,造成数据库信息泄露等危害。
我觉得
要弄懂SQL注入,需要一点计网的知识,最好知道Web开发的整个流程,中间用了哪些技术,为什么需要这种技术。当然,你首先得懂得数据库以及SQL查询,并且程序设计语言和SQL语言之间的结合(推荐一本书《数据库系统概论》)。有了这些基础,SQL注入就自然而然会懂的。
通关思路
输入id,登录正常
尝试闭合语句
单引号报错,推测后端查询语句为:
select * from table where id = ’ input ’

通过order by 枚举,可知字段数为3
由于回显信息较多,优先联合注入
由上图可知,第2、第3个字段为回显信息,故可构造payload,开始注入
库名:
表名:
http://127.0.0.1/sqli-labs/Less-1/?id=-1’ union select 1,2,group_concat(table_name) from information_schema.tables where table_schema=‘security’ --+
字段名:
字段内容:
union select 1,2,group_concat(users,0x7e,password) from users --+
看过几篇教程做题时的记录
1、输入不同id,有不同回显结果,猜测后台sql语句为:select * from table where id= input;
2、单引号测试,报错,推测后台sql语句为:select * from table where id = ‘input’;
3、构造语句,单引号闭合,order by 4出错 ---->3列字段,select 1,2,3,–>回显位置;
4、联合注入: union select 1,2,(构造语句查询信息)–+
1.找漏洞
2.猜解字段数
3.获取数据库名字
4.查表
5.查字段名和字段数值
边栏推荐
- CarSim problem failed to start solver: path_ ID_ OBJ(X) was set to Y; no corresponding value of XXXXX?
- 什么是SQL注入
- Linked list classic interview questions (reverse the linked list, middle node, penultimate node, merge and split the linked list, and delete duplicate nodes)
- Method recursion (Fibonacci sequence, frog jumping steps, tower of Hanoi problem)
- Analysis of the use of comparable, comparator and clonable interfaces
- Common shortcut keys of Jupiter notebook (you can also view it by pressing h in command mode)
- How to wrap qstring strings
- Global and Chinese market of electric cheese grinder 2022-2028: Research Report on technology, participants, trends, market size and share
- Causes of laptop jam
- My VIM profile
猜你喜欢

ARP及ARP欺骗

Vs code configuration problem

W10 is upgraded to W11 system, but the screen is black, but the mouse and desktop shortcuts can be used. How to solve it

Data reverse attack under federated learning -- gradinversion

Valin cable: BI application promotes enterprise digital transformation

Method recursion (Fibonacci sequence, frog jumping steps, tower of Hanoi problem)

2022 Heilongjiang latest construction eight members (materialman) simulated examination questions and answers

Sqlyog remote connection to MySQL database under centos7 system

Carsim-路面3D形状文件参数介绍

Chinese garbled code under vscade
随机推荐
C语言实现XML生成解析库(XML扩展)
In depth understanding of prototype drawings
Jupyter Notebook常用快捷键(在命令模式中按H也可查看)
STL速查手册
Carsim-实时仿真的动画同步问题
Makefile基本原理
STM32-新建工程(参考正点原子)
Matlab-其它
Carsim 学习心得-粗略翻译1
力扣每日一题刷题总结:栈与队列篇(持续更新)
力扣方法总结:查找类
Global and Chinese markets for magnetic resonance imaging (MRI) transmission 2022-2028: Research Report on technology, participants, trends, market size and share
OpenCV3 6.3 用滤波器进行缩减像素采样
OpenCV常用方法出处链接(持续更新)
install. IMG production method
TCP/IP—传输层
c语言自定义类型枚举,联合(枚举的巧妙使用,联合体大小的计算)
St-link connection error invalid ROM table of STM32 difficult and miscellaneous diseases
Linked list classic interview questions (reverse the linked list, middle node, penultimate node, merge and split the linked list, and delete duplicate nodes)
STL quick reference manual