当前位置:网站首页>BUUCTF [极客大挑战 2019]EasySQL1
BUUCTF [极客大挑战 2019]EasySQL1
2022-04-23 06:32:00 【隔壁Cc】
首先打开靶机,显示是这样的页面
观察发现没有注册功能,看题目是EasySQL 判断应该是SQL注入类型(注入原理:通过把SQL命令插入到Web表单递交或输入域名或页面请求的查询字符串,最终达到欺骗服务器执行恶意的SQL命令)
F12查看源代码,发现是php类型
考虑到题目很简单:这里使用了php万能密码进行尝试: admin'or'1'='1
发现登录成功
大哥拿出你发财的小手zan个吧
版权声明
本文为[隔壁Cc]所创,转载请带上原文链接,感谢
https://blog.csdn.net/WINDY_PACE/article/details/121526297
边栏推荐
- Protobuf use
- 读书笔记
- Using lambda expression to solve the problem of C file name sorting (whether it is 100 or 11)
- MYSQL——第一章节(数据类型2)
- CTF-MISC学习之从开始到放弃
- 内网渗透系列:内网隧道之icmptunnel(jamesbarlow师傅的)
- Reptile learning notes, learning reptile, read this article is enough
- Houdini > rigid body, rigid body breaking RBD
- Personality charm of high paid it workers
- SAP tr manual import system operation manual
猜你喜欢
随机推荐
Unity gets the resources that a file depends on
Automatically fit single line text into the target rectangle
Intranet penetration series: pingtunnel of Intranet tunnel
Unity get real geographic map application terrain notes
Chapter V investment real estate
第四章 无形资产
About USB flash drive data prompt raw, need to format, data recovery notes
Post of experience in preparation for guarantee and research -- the 18th (2021) Central South planning department promoted the exemption to Zhejiang University Institute of Technology
一文了解系列,对web渗透的常见漏洞总结(持续更新)
一些靶场的学习记录:sqli-labs、upload-labs、XSS
Online Safe Trajectory Generation For Quadrotors Using Fast Marching Method and Bernstein Basis Poly
Essays (updated from time to time)
《内网安全攻防:渗透测试实战指南》读书笔记(七):跨域攻击分析及防御
SAP GUI安全性
SAP self created table log function is enabled
读书笔记
攻防世界MISC刷题1-50
关于unity获取真实地理地图转3D化的相关链接
Intranet penetration series: icmptunnel of Intranet tunnel (by master dhavalkapil)
Personality charm of high paid it workers