当前位置:网站首页>Safety learning week4
Safety learning week4
2022-07-05 00:26:00 【Not Xiaosheng】
Safe learning Week4
Web Practical combat
1.[ Geek challenge 2019]EasySQL
Try directly with the default password
Add another ‘ See if you can report an error
Ok Then use or’1’=‘1 了
success
2【buu】[ Geek challenge 2019]LoveSQL
. Login successfully with universal password
Re explosion field
3 A field
Look at the echo
2,3 Echo point
Re explode the database
Explode the watch again
Directly check the column of the second database
Look it up directly
3.[ Geek challenge 2019]BabySQL
or Filtered
Pop field
Union and select It's also filtered
Then double write again
Wrong number of columns
Look at the echo
Check version
Check the library
From It seems to be filtered
Blast storage
Explosion meter
check ctf In the library Flag Tabular flag Column
4.[ Geek challenge 2019]HardSQL
An error is reported when a single quotation mark is found , Double quotation marks do not , There are no brackets , So it should be ordinary single quotation mark closed character injection
The burst field is found to be filtered Use error reporting injection
Get the library name
Name of Pop Watch
Name it
Explosion explosion
I didn't expect the second paragraph to be a }
Nb
5.[ Geek challenge 2019]EasySQL
use select Query library found to be filtered
Select stack injection
This posture is good
Query table
Query table structure
See flag I feel nervous and want to copy lately misc Do more and see flag Just want to copy
It's easy to know in this library
Use preprocessing statements + char() Function will select Of ASCII Code conversion to select character string , Then use concat() Function to get select Query statement , This bypasses the filter . Or use it directly concat() Function together select To bypass .
0’;PREPARE hacker from concat(char(115,101,108,101,99,116), ' * from `1919810931114514` ');EXECUTE hacker;#
Although my blog is not good But you try to see here Leave a compliment before you go
边栏推荐
- 如何有效对直流列头柜进行监测
- [论文阅读] CarveMix: A Simple Data Augmentation Method for Brain Lesion Segmentation
- He worked as a foreign lead and paid off all the housing loans in a year
- 巩固表达式C# 案例简单变量运算
- JS convert pseudo array to array
- 如果炒股开华泰证券的户,在网上开户安全吗?
- go踩坑——no required module provides package : go.mod file not found in current directory or any parent
- If you open an account of Huatai Securities by stock speculation, is it safe to open an account online?
- [IELTS reading] Wang Xiwei reading P3 (heading)
- How to avoid arc generation—— Aafd fault arc detector solves the problem for you
猜你喜欢
他做国外LEAD,用了一年时间,把所有房贷都还清了
分布式BASE理论
【C】 (written examination questions) pointer and array, pointer
Every time I look at the interface documents of my colleagues, I get confused and have a lot of problems...
基本放大电路的学习
"Xiaodeng" domain password policy enhancer in operation and maintenance
P3304 [sdoi2013] diameter (diameter of tree)
Fast parsing intranet penetration helps enterprises quickly achieve collaborative office
Hash table, hash function, bloom filter, consistency hash
abc 258 G - Triangle(bitset)
随机推荐
npm install报错 强制安装
Design of emergency lighting evacuation indication system for urban rail transit station
跨域请求
22-07-02周总结
Skills in analyzing the trend chart of London Silver
图解网络:什么是网关负载均衡协议GLBP?
企业应用业务场景,功能添加和修改C#源码
JS 将伪数组转换成数组
华为200万年薪聘请数据治理专家!背后的千亿市场值得关注
Life is changeable, and the large intestine covers the small intestine. This time, I can really go home to see my daughter-in-law...
Paper notes multi UAV collaborative monolithic slam
Detailed explanation of openharmony resource management
What is the difference between port mapping and port forwarding
C语言中sizeof操作符的坑
如何避免电弧产生?—— AAFD故障电弧探测器为您解决
P3304 [SDOI2013]直径(树的直径)
Learning of basic amplification circuit
Continuous modification of business scenario functions
业务实现-日志写到同一个行数据里面
【C】(笔试题)指针与数组,指针