当前位置:网站首页>Buuctf question brushing notes - [geek challenge 2019] easysql 1
Buuctf question brushing notes - [geek challenge 2019] easysql 1
2022-07-06 03:03:00 【Always a teenager】
Continue today BUUCTF The topic , Today's solution [ Geek challenge 2019]EasySQL 1.
One 、 Basic information of the topic
Let's go to the link , Open the web site , The results are shown below :
Two 、 Their thinking
As can be seen from the above figure , Our target site is a login page . Combined with the topic information , We can guess that the problem is solved as SQL Injection direction .
We simply try the user name with single quotation marks at the user name admin’, The results are shown below :
As can be seen from the above figure , This is a simple error report SQL Inject .
Next , We try to add a after the user name just now #, Try to filter the following content , The results are shown below :
3、 ... and 、 Get flag
It is easy to analyze from the above attempts , The topic is very simple , Basically no filtering , We try to use universal password , user name admin’ or 1=1#, Password optional , Click to log in , The results are shown below :
As can be seen from the above figure , We successfully got the title flag.
Originality is not easy. , Reprint please explain the source :https://blog.csdn.net/weixin_40228200
边栏推荐
- C language - Blue Bridge Cup - promised score
- Selenium share
- Self made CA certificate and SSL certificate using OpenSSL
- 会员积分营销系统操作的时候怎样提升消费者的积极性?
- tcpdump: no suitable device found
- Who is the winner of PTA
- Communication between microservices
- [network security interview question] - how to penetrate the test file directory through
- OCR文字识别方法综述
- [ruoyi] set theme style
猜你喜欢
[Yunju entrepreneurial foundation notes] Chapter II entrepreneur test 20
Codeforces 5 questions par jour (1700 chacune) - jour 6
RobotFramework入门(一)简要介绍及使用
Game theory matlab
深度解析链动2+1模式,颠覆传统卖货思维?
IPv6 jobs
[unity3d] GUI control
Microservice registration and discovery
华为、H3C、思科命令对比,思维导图形式从基础、交换、路由三大方向介绍【转自微信公众号网络技术联盟站】
Reverse repackaging of wechat applet
随机推荐
tcpdump: no suitable device found
八道超经典指针面试题(三千字详解)
tcpdump: no suitable device found
这些不太会
Self made CA certificate and SSL certificate using OpenSSL
微服务注册与发现
Summary of Bible story reading
js 正则过滤和增加富文本中图片前缀
Zhang Lijun: penetrating uncertainty depends on four "invariants"
解决:AttributeError: ‘str‘ object has no attribute ‘decode‘
OCR文字識別方法綜述
【指针训练——八道题】
Atcoder beginer contest 233 (a~d) solution
【若依(ruoyi)】启用迷你导航栏
Classic interview question [gem pirate]
Gifcam v7.0 minimalist GIF animation recording tool Chinese single file version
Rust language -- iterators and closures
codeforces每日5题(均1700)-第六天
继承day01
Microservice registration and discovery