• sqli-lab(Stacked)


    (堆叠注入)
    Less-38:

    select * from table where id='1';
    ';insert into user values(20,'test','test')%23

    Less-39:
    select * from table where id=1;

    Less-40:
    select * from table where id=('1');

    Less-41:
    select * from table where id=1;

    Less-42:
    select * from table where username='admin' and password='admin';
    password处注入

    Less-43:
    select * from table where username=('admin') and password=('admin');

    Less-44:
    select * from table where username='admin' and password='admin';

    Less-45:
    select * from table where username=('admin') and password=('admin');


    (order by注入)
    Less-46:

    select * from table  order by 1;
    ?sort=rand(1)
    ?sort=1 and extractvalue()
    ?sort=1  procedure analyse(extractvalue(),1)
    ?sort=1 into outfile "path"

    Less-47:
    select * from table order by '1;
    ?sort=1' and extractvalue()%23

    Less-48:
    select *& from table order by 1;
    ?sort=if()

    Less-49:
    select * from table order by '1;


    (堆叠order by注入)
    Less-50:

    select *& from table order by 1;

    Less-51:
    select *& from table order by '1';

    Less-52:
    select *& from table order by 1;

    Less-53:
    select *& from table order by '1';

  • 相关阅读:
    JSON
    Iterator
    JSP内置对象和EL内置对象
    JavaBean简介
    Java关键字final、static使用总结
    static 语句块
    修改tomcat端口号的方法
    URL和URI的区别
    java.util.vector中的vector的详细用法
    java中Long 和long的区别
  • 原文地址:https://www.cnblogs.com/f1veseven/p/13414167.html
Copyright © 2020-2023  润新知