当前位置:网站首页>记一次edu,SQL注入实战
记一次edu,SQL注入实战
2022-07-06 09:22:00 【又懒有菜】
目录
0x01 思路:inurl: exam result
(存在漏洞的可能性比较大)
探针用rad爬虫+jsfinder爬取到查询接口post
这种功能都有sql select语句(如果过滤不严谨存在注入可能性就比较大)

js前端:身份证号又前端校检18位 绕过才能够抓包
0x02 判断注入
正常发包

单引号报synax语法错误

0x03 报错注入


0x04 sqlmap
剩下的一些直接扔到sqlmap里面跑
边栏推荐
- Intensive literature reading series (I): Courier routing and assignment for food delivery service using reinforcement learning
- 渗透测试学习与实战阶段分析
- Safe driving skills on ice and snow roads
- 7-9 make house number 3.0 (PTA program design)
- Wechat applet
- 7-8 7104 约瑟夫问题(PTA程序设计)
- 深度强化文献阅读系列(一):Courier routing and assignment for food delivery service using reinforcement learning
- 1. Preliminary exercises of C language (1)
- The United States has repeatedly revealed that the yield of interest rate hiked treasury bonds continued to rise
- Attach the simplified sample database to the SQLSERVER database instance
猜你喜欢

3. Input and output functions (printf, scanf, getchar and putchar)

The difference between cookies and sessions

Hackmyvm target series (7) -tron

小程序web抓包-fiddler

A comprehensive summary of MySQL transactions and implementation principles, and no longer have to worry about interviews

1. First knowledge of C language (1)

Safe driving skills on ice and snow roads

FAQs and answers to the imitation Niuke technology blog project (III)

记一次猫舍由外到内的渗透撞库操作提取-flag

"Gold, silver and four" job hopping needs to be cautious. Can an article solve the interview?
随机推荐
Experiment five categories and objects
1. First knowledge of C language (1)
Intensive literature reading series (I): Courier routing and assignment for food delivery service using reinforcement learning
7-1 output all primes between 2 and n (PTA programming)
【头歌educoder数据表中数据的插入、修改和删除】
Relationship between hashcode() and equals()
QT meta object qmetaobject indexofslot and other functions to obtain class methods attention
7-15 h0161. 求最大公约数和最小公倍数(PTA程序设计)
7-3 construction hash table (PTA program design)
【VMware异常问题】问题分析&解决办法
7-6 矩阵的局部极小值(PTA程序设计)
[MySQL table structure and integrity constraint modification (Alter)]
Hackmyvm target series (4) -vulny
Callback function ----------- callback
简述xhr -xhr的基本使用
SRC mining ideas and methods
HackMyvm靶机系列(7)-Tron
实验九 输入输出流(节选)
7-4 散列表查找(PTA程序设计)
7-14 错误票据(PTA程序设计)