当前位置:网站首页>Buuctf question brushing notes - [geek challenge 2019] easysql 1
Buuctf question brushing notes - [geek challenge 2019] easysql 1
2022-07-06 03:03:00 【Always a teenager】
Continue today BUUCTF The topic , Today's solution [ Geek challenge 2019]EasySQL 1.
One 、 Basic information of the topic
Let's go to the link , Open the web site , The results are shown below :
Two 、 Their thinking
As can be seen from the above figure , Our target site is a login page . Combined with the topic information , We can guess that the problem is solved as SQL Injection direction .
We simply try the user name with single quotation marks at the user name admin’, The results are shown below :
As can be seen from the above figure , This is a simple error report SQL Inject .
Next , We try to add a after the user name just now #, Try to filter the following content , The results are shown below :
3、 ... and 、 Get flag
It is easy to analyze from the above attempts , The topic is very simple , Basically no filtering , We try to use universal password , user name admin’ or 1=1#, Password optional , Click to log in , The results are shown below :
As can be seen from the above figure , We successfully got the title flag.
Originality is not easy. , Reprint please explain the source :https://blog.csdn.net/weixin_40228200
边栏推荐
- Yyds dry inventory comparison of several database storage engines
- 【 kubernets series】 a Literature Study on the Safe exposure Applications of kubernets Service
- How to read excel, PDF and JSON files in R language?
- Codeforces 5 questions par jour (1700 chacune) - jour 6
- What are the principles of software design (OCP)
- 继承day01
- OCR文字識別方法綜述
- My C language learning record (blue bridge) -- under the pointer
- 主数据管理(MDM)的成熟度
- Redis cluster deployment based on redis5
猜你喜欢
Linear regression and logistic regression
Codeworks 5 questions per day (1700 average) - day 6
Modeling specifications: naming conventions
淘宝焦点图布局实战
QT release exe software and modify exe application icon
深度解析链动2+1模式,颠覆传统卖货思维?
PMP每日一练 | 考试不迷路-7.5
How to accurately identify master data?
故障分析 | MySQL 耗尽主机内存一例分析
[Yunju entrepreneurial foundation notes] Chapter II entrepreneur test 20
随机推荐
codeforces每日5題(均1700)-第六天
MySQL advanced notes
JS events (add, delete) and delegates
【Kubernetes 系列】一文学会Kubernetes Service安全的暴露应用
Introduction to robotframework (I) brief introduction and use
[Yunju entrepreneurial foundation notes] Chapter II entrepreneur test 21
一个复制也能玩出花来
Referenceerror: primordials is not defined error resolution
建模规范:命名规范
Spherical lens and cylindrical lens
The difference between sizeof and strlen in C language
【若依(ruoyi)】ztree 自定义图标(iconSkin 属性)
[ruoyi] set theme style
华为、H3C、思科命令对比,思维导图形式从基础、交换、路由三大方向介绍【转自微信公众号网络技术联盟站】
C语言sizeof和strlen的区别
MySQL advanced notes
PMP practice once a day | don't get lost in the exam -7.5
Differences and usage scenarios between TCP and UDP
#PAT#day10
Game theory matlab