当前位置:网站首页>Safety learning week4
Safety learning week4
2022-07-05 00:26:00 【Not Xiaosheng】
Safe learning Week4
Web Practical combat
1.[ Geek challenge 2019]EasySQL
Try directly with the default password

Add another ‘ See if you can report an error

Ok Then use or’1’=‘1 了
success
2【buu】[ Geek challenge 2019]LoveSQL
. Login successfully with universal password
Re explosion field
3 A field
Look at the echo

2,3 Echo point
Re explode the database

Explode the watch again

Directly check the column of the second database

Look it up directly
3.[ Geek challenge 2019]BabySQL
or Filtered

Pop field
Union and select It's also filtered
Then double write again

Wrong number of columns
Look at the echo
Check version

Check the library

From It seems to be filtered
Blast storage
Explosion meter

check ctf In the library Flag Tabular flag Column

4.[ Geek challenge 2019]HardSQL
An error is reported when a single quotation mark is found , Double quotation marks do not , There are no brackets , So it should be ordinary single quotation mark closed character injection

The burst field is found to be filtered Use error reporting injection

Get the library name

Name of Pop Watch

Name it

Explosion explosion


I didn't expect the second paragraph to be a }
Nb
5.[ Geek challenge 2019]EasySQL
use select Query library found to be filtered

Select stack injection
This posture is good

Query table

Query table structure


See flag I feel nervous and want to copy lately misc Do more and see flag Just want to copy
It's easy to know in this library
Use preprocessing statements + char() Function will select Of ASCII Code conversion to select character string , Then use concat() Function to get select Query statement , This bypasses the filter . Or use it directly concat() Function together select To bypass .
0’;PREPARE hacker from concat(char(115,101,108,101,99,116), ' * from `1919810931114514` ');EXECUTE hacker;#

Although my blog is not good But you try to see here Leave a compliment before you go
边栏推荐
- Enterprise application business scenarios, function addition and modification of C source code
- P4408 [NOI2003] 逃学的小孩(树的直径)
- How many triangles are there in the golden K-line diagram?
- 2022.07.03 (lc_6111_counts the number of ways to place houses)
- Distributed base theory
- JS 将伪数组转换成数组
- 22-07-02周总结
- Cross domain request
- The waterfall flow layout demo2 (method 2) used by the uniapp wechat applet (copy and paste can be used without other processing)
- Fast parsing intranet penetration helps enterprises quickly achieve collaborative office
猜你喜欢

lambda expressions
![P3304 [sdoi2013] diameter (diameter of tree)](/img/5c/984675bf4517481f80f54657c6c7ad.png)
P3304 [sdoi2013] diameter (diameter of tree)

Ap8022 switching power supply small household appliances ACDC chip offline switching power supply IC

2022.07.03(LC_6108_解密消息)

How to effectively monitor the DC column head cabinet

It's too convenient. You can complete the code release and approval by nailing it!

圖解網絡:什麼是網關負載均衡協議GLBP?

Build your own minecraft server with fast parsing

leetcode518,377

How to do the project of computer remote company in foreign Internet?
随机推荐
The company needs to be monitored. How do ZABBIX and Prometheus choose? That's the right choice!
ORB(Oriented FAST and Rotated BRIEF)
Design of emergency lighting evacuation indication system for urban rail transit station
How to avoid arc generation—— Aafd fault arc detector solves the problem for you
How to save your code works quickly to better protect your labor achievements
圖解網絡:什麼是網關負載均衡協議GLBP?
基本放大电路的学习
IELTS examination process, what to pay attention to and how to review?
Multilingual Wikipedia website source code development part II
分布式BASE理论
【路径规划】RRT增加动力模型进行轨迹规划
Get to know ROS for the first time
Upload avatar on uniapp
Consolidated expression C case simple variable operation
Summer challenge brings you to play harmoniyos multi terminal piano performance
PermissionError: [Errno 13] Permission denied: ‘data. csv‘
Réseau graphique: Qu'est - ce que le Protocole d'équilibrage de charge de passerelle glbp?
Detailed explanation of openharmony resource management
【雅思阅读】王希伟阅读P4(matching2段落信息配对题【困难】)
Hologres Query管理及超时处理