当前位置:网站首页>BUUCTF [极客大挑战 2019]EasySQL1
BUUCTF [极客大挑战 2019]EasySQL1
2022-04-23 06:32:00 【隔壁Cc】
首先打开靶机,显示是这样的页面
观察发现没有注册功能,看题目是EasySQL 判断应该是SQL注入类型(注入原理:通过把SQL命令插入到Web表单递交或输入域名或页面请求的查询字符串,最终达到欺骗服务器执行恶意的SQL命令)

F12查看源代码,发现是php类型

考虑到题目很简单:这里使用了php万能密码进行尝试: admin'or'1'='1


发现登录成功
大哥拿出你发财的小手zan个吧
版权声明
本文为[隔壁Cc]所创,转载请带上原文链接,感谢
https://blog.csdn.net/WINDY_PACE/article/details/121526297
边栏推荐
- Internal network security attack and defense: a practical guide to penetration testing (8): Authority maintenance analysis and defense
- 1+x云计算中级--脚本搭建读写分离
- Sto with billing cross company inventory dump return
- Houdini fluid > > particle fluid export to unity note
- RAID0和RAID5的创建和模拟RAID5工作原理
- 内网渗透系列:内网隧道之icmptunnel(jamesbarlow师傅的)
- C smoothprogressbar custom progress bar control
- VBA appelle SAP RFC pour réaliser la lecture et l'écriture des données
- Feign源码分析
- 内网渗透系列:内网隧道之pingtunnel
猜你喜欢
![[NLP notes] preliminary study on CRF principle](/img/8c/2717aeee2e75bdae97d2bacd362e53.png)
[NLP notes] preliminary study on CRF principle

SAP tr manual import system operation manual

Ctf-misc summary

Intranet penetration series: dnscat2 of Intranet tunnel

CTF attack and defense world brush questions 51-

Essays (updated from time to time)

Intranet penetration series: pingtunnel of Intranet tunnel

Export all SVG files in the specified path into pictures in PNG format (thumbnail or original size)

upload-labs 靶场练习

Protobuf use
随机推荐
SAP STO With Billing流程与配置
第四章 无形资产
Chapter IV intangible assets
内网渗透系列:内网隧道之icmptunnel(jamesbarlow师傅的)
从零开始完整学习机器学习和深度学习,包括理论和代码实现,主要用到scikit和MXNet,还有一些实践(kaggle上的)
C # control the camera, rotate and drag the observation script (similar to scenes observation mode)
SAP self created table log function is enabled
Internal network security attack and defense: a practical guide to penetration testing (IV): Authority improvement analysis and defense
Research on system and software security (2)
VBA calls SAP RFC to read & write data
Expression related to month, year and day in SVG
Redis事务实现乐观锁原理
Protobuf use
Feign源码分析
linux下mysql数据库备份与恢复(全量+增量)
Houdini>流体,刚体导出学习过程笔记
Intranet penetration series: icmptunnel of Intranet tunnel (by master dhavalkapil)
SAP自建表log功能开启
SAP TR手动导入系统操作手册
SAP GUI security