当前位置:网站首页>Safety learning week4
Safety learning week4
2022-07-05 00:26:00 【Not Xiaosheng】
Safe learning Week4
Web Practical combat
1.[ Geek challenge 2019]EasySQL
Try directly with the default password
Add another ‘ See if you can report an error
Ok Then use or’1’=‘1 了
success
2【buu】[ Geek challenge 2019]LoveSQL
. Login successfully with universal password
Re explosion field
3 A field
Look at the echo
2,3 Echo point
Re explode the database
Explode the watch again
Directly check the column of the second database
Look it up directly
3.[ Geek challenge 2019]BabySQL
or Filtered
Pop field
Union and select It's also filtered
Then double write again
Wrong number of columns
Look at the echo
Check version
Check the library
From It seems to be filtered
Blast storage
Explosion meter
check ctf In the library Flag Tabular flag Column
4.[ Geek challenge 2019]HardSQL
An error is reported when a single quotation mark is found , Double quotation marks do not , There are no brackets , So it should be ordinary single quotation mark closed character injection
The burst field is found to be filtered Use error reporting injection
Get the library name
Name of Pop Watch
Name it
Explosion explosion
I didn't expect the second paragraph to be a }
Nb
5.[ Geek challenge 2019]EasySQL
use select Query library found to be filtered
Select stack injection
This posture is good
Query table
Query table structure
See flag I feel nervous and want to copy lately misc Do more and see flag Just want to copy
It's easy to know in this library
Use preprocessing statements + char() Function will select Of ASCII Code conversion to select character string , Then use concat() Function to get select Query statement , This bypasses the filter . Or use it directly concat() Function together select To bypass .
0’;PREPARE hacker from concat(char(115,101,108,101,99,116), ' * from `1919810931114514` ');EXECUTE hacker;#
Although my blog is not good But you try to see here Leave a compliment before you go
边栏推荐
- 图解网络:什么是网关负载均衡协议GLBP?
- Pytoch --- use pytoch to realize linknet for semantic segmentation
- If you open an account of Huatai Securities by stock speculation, is it safe to open an account online?
- Acwing164. Accessibility Statistics (topological sorting +bitset)
- 多回路仪表在基站“转改直”方面的应用
- 模板的进阶
- 【C】(笔试题)指针与数组,指针
- uniapp上传头像
- ORB(Oriented FAST and Rotated BRIEF)
- How to save your code works quickly to better protect your labor achievements
猜你喜欢
Acrel-EMS综合能效平台在校园建设的意义
电力运维云平台:开启电力系统“无人值班、少人值守”新模式
js如何实现数组转树
【雅思阅读】王希伟阅读P4(matching2段落信息配对题【困难】)
[论文阅读] CarveMix: A Simple Data Augmentation Method for Brain Lesion Segmentation
《论文笔记》Multi-UAV Collaborative Monocular SLAM
How to avoid arc generation—— Aafd fault arc detector solves the problem for you
abc 258 G - Triangle(bitset)
Power operation and maintenance cloud platform: open the new mode of "unattended and few people on duty" of power system
JS how to realize array to tree
随机推荐
人脸识别5- insight-face-paddle-代码实战笔记
Introduction to ACM combination counting
Go pit - no required module provides Package: go. Mod file not found in current directory or any parent
Data on the number of functional divisions of national wetland parks in Qinghai Province, data on the distribution of wetlands and marshes across the country, and natural reserves in provinces, cities
Hologres query management and timeout processing
Consolidated expression C case simple variable operation
P4408 [noi2003] truant children (tree diameter)
JS convert pseudo array to array
【雅思阅读】王希伟阅读P4(matching2段落信息配对题【困难】)
Continuous modification of business scenario functions
兩個數相互替換
Using the uniapp rich text editor
Every time I look at the interface documents of my colleagues, I get confused and have a lot of problems...
他做国外LEAD,用了一年时间,把所有房贷都还清了
城市轨道交通站应急照明疏散指示系统设计
【雅思阅读】王希伟阅读P3(Heading)
Upload avatar on uniapp
Specification for fs4061a boost 8.4v charging IC chip and fs4061b boost 12.6V charging IC chip datasheet
Réseau graphique: Qu'est - ce que le Protocole d'équilibrage de charge de passerelle glbp?
The pit of sizeof operator in C language