当前位置:网站首页>记一次edu,SQL注入实战
记一次edu,SQL注入实战
2022-07-06 09:22:00 【又懒有菜】
目录
0x01 思路:inurl: exam result
(存在漏洞的可能性比较大)
探针用rad爬虫+jsfinder爬取到查询接口post
这种功能都有sql select语句(如果过滤不严谨存在注入可能性就比较大)
js前端:身份证号又前端校检18位 绕过才能够抓包
0x02 判断注入
正常发包
单引号报synax语法错误
0x03 报错注入
0x04 sqlmap
剩下的一些直接扔到sqlmap里面跑
边栏推荐
- [hand tearing code] single case mode and producer / consumer mode
- 7-14 error ticket (PTA program design)
- 强化学习系列(一):基本原理和概念
- [au cours de l'entrevue] - Comment expliquer le mécanisme de transmission fiable de TCP
- 简述xhr -xhr的基本使用
- Meituan dynamic thread pool practice ideas, open source
- 【educoder数据库实验 索引】
- 记一次,修改密码逻辑漏洞实战
- Relationship between hashcode() and equals()
- 记一次猫舍由外到内的渗透撞库操作提取-flag
猜你喜欢
Canvas foundation 1 - draw a straight line (easy to understand)
Middleware vulnerability recurrence Apache
小程序web抓包-fiddler
Poker game program - man machine confrontation
HackMyvm靶机系列(3)-visions
2022泰迪杯数据挖掘挑战赛C题思路及赛后总结
A comprehensive summary of MySQL transactions and implementation principles, and no longer have to worry about interviews
Package bedding of components
FAQs and answers to the imitation Niuke technology blog project (I)
【VMware异常问题】问题分析&解决办法
随机推荐
Attach the simplified sample database to the SQLSERVER database instance
1. First knowledge of C language (1)
. Net6: develop modern 3D industrial software based on WPF (2)
SRC挖掘思路及方法
记一次,修改密码逻辑漏洞实战
Programme de jeu de cartes - confrontation homme - machine
7-3 构造散列表(PTA程序设计)
Hackmyvm target series (6) -videoclub
7-9 make house number 3.0 (PTA program design)
简述xhr -xhr的基本使用
HackMyvm靶机系列(7)-Tron
网络层—简单的arp断网
Hackmyvm target series (4) -vulny
Mixlab unbounded community white paper officially released
(original) make an electronic clock with LCD1602 display to display the current time on the LCD. The display format is "hour: minute: Second: second". There are four function keys K1 ~ K4, and the fun
This time, thoroughly understand the MySQL index
Detailed explanation of redis' distributed lock principle
HackMyvm靶机系列(3)-visions
FAQs and answers to the imitation Niuke technology blog project (I)
Beautified table style