当前位置:网站首页>Safety learning week4
Safety learning week4
2022-07-05 00:26:00 【Not Xiaosheng】
Safe learning Week4
Web Practical combat
1.[ Geek challenge 2019]EasySQL
Try directly with the default password
Add another ‘ See if you can report an error
Ok Then use or’1’=‘1 了
success
2【buu】[ Geek challenge 2019]LoveSQL
. Login successfully with universal password
Re explosion field
3 A field
Look at the echo
2,3 Echo point
Re explode the database
Explode the watch again
Directly check the column of the second database
Look it up directly
3.[ Geek challenge 2019]BabySQL
or Filtered
Pop field
Union and select It's also filtered
Then double write again
Wrong number of columns
Look at the echo
Check version
Check the library
From It seems to be filtered
Blast storage
Explosion meter
check ctf In the library Flag Tabular flag Column
4.[ Geek challenge 2019]HardSQL
An error is reported when a single quotation mark is found , Double quotation marks do not , There are no brackets , So it should be ordinary single quotation mark closed character injection
The burst field is found to be filtered Use error reporting injection
Get the library name
Name of Pop Watch
Name it
Explosion explosion
I didn't expect the second paragraph to be a }
Nb
5.[ Geek challenge 2019]EasySQL
use select Query library found to be filtered
Select stack injection
This posture is good
Query table
Query table structure
See flag I feel nervous and want to copy lately misc Do more and see flag Just want to copy
It's easy to know in this library
Use preprocessing statements + char() Function will select Of ASCII Code conversion to select character string , Then use concat() Function to get select Query statement , This bypasses the filter . Or use it directly concat() Function together select To bypass .
0’;PREPARE hacker from concat(char(115,101,108,101,99,116), ' * from `1919810931114514` ');EXECUTE hacker;#
Although my blog is not good But you try to see here Leave a compliment before you go
边栏推荐
- 他做国外LEAD,用了一年时间,把所有房贷都还清了
- Remember to build wheels repeatedly at one time (the setting instructions of obsidian plug-in are translated into Chinese)
- Oracle case: SMON rollback exception causes instance crash
- ORB(Oriented FAST and Rotated BRIEF)
- Huawei employs data management experts with an annual salary of 2million! The 100 billion market behind it deserves attention
- lambda表达式
- Best practice case of enterprise digital transformation: introduction and reference of cloud based digital platform system security measures
- Advanced template
- GDB常用命令
- JS convert pseudo array to array
猜你喜欢
Every time I look at the interface documents of my colleagues, I get confused and have a lot of problems...
Skills in analyzing the trend chart of London Silver
企业公司项目开发好一部分基础功能,重要的事保存到线上第一a
《论文笔记》Multi-UAV Collaborative Monocular SLAM
[selenium automation] common notes
What did I pay for it transfer to testing post from confusion to firmness?
Two numbers replace each other
两个数相互替换
[IELTS reading] Wang Xiwei reading P3 (heading)
P3304 [SDOI2013]直径(树的直径)
随机推荐
How many triangles are there in the golden K-line diagram?
Face recognition 5- insight face padding code practice notes
实战模拟│JWT 登录认证
青海省国家湿地公园功能区划数数据、全国湿地沼泽分布数据、全国省市县自然保护区
P4281 [AHOI2008]紧急集合 / 聚会(LCA)
Hash table, hash function, bloom filter, consistency hash
【selenium自动化】常用注解
Summary of week 22-07-02
业务场景功能的继续修改
跨域请求
Verilog tutorial (11) initial block in Verilog
Cross domain request
Upload avatar on uniapp
【北京大学】Tensorflow2.0-1-开篇
Is it safe to open and register new bonds? Is there any risk? Is it reliable?
公司要上监控,Zabbix 和 Prometheus 怎么选?这么选准没错!
Power operation and maintenance cloud platform: open the new mode of "unattended and few people on duty" of power system
Huawei employs data management experts with an annual salary of 2million! The 100 billion market behind it deserves attention
Detailed explanation of openharmony resource management
AcWing164. 可达性统计(拓扑排序+bitset)