当前位置:网站首页>BUUCTF [极客大挑战 2019]EasySQL1
BUUCTF [极客大挑战 2019]EasySQL1
2022-04-23 06:32:00 【隔壁Cc】
首先打开靶机,显示是这样的页面
观察发现没有注册功能,看题目是EasySQL 判断应该是SQL注入类型(注入原理:通过把SQL命令插入到Web表单递交或输入域名或页面请求的查询字符串,最终达到欺骗服务器执行恶意的SQL命令)
F12查看源代码,发现是php类型
考虑到题目很简单:这里使用了php万能密码进行尝试: admin'or'1'='1
发现登录成功
大哥拿出你发财的小手zan个吧
版权声明
本文为[隔壁Cc]所创,转载请带上原文链接,感谢
https://blog.csdn.net/WINDY_PACE/article/details/121526297
边栏推荐
- Read and modify the JSON file under the resource folder
- sentinel集成nacos动态更新数据原理
- Zhuang understand's TA notes (VI) < fakeenvreflect & rust, rust effect >
- feign如何集成hystrix
- Common markdown grammar learning
- 内网渗透系列:内网隧道之icmp_tran
- upload-labs 靶场练习
- When using flash, the code ends automatically without an error, the connection cannot be maintained, and the URL cannot be accessed.
- Chapter IV intangible assets
- linux下mysql数据库备份与恢复(全量+增量)
猜你喜欢
SAP self created table log function is enabled
Intranet penetration series: icmptunnel of Intranet tunnel (Master James Barlow's)
Protobuf use
Teach-Repeat-Replan: A Complete and Robust System for Aggressive Flight in Complex Environments
upload-labs 靶场练习
[unity VFX] Introduction notes of VFX special effects - spark production
C problem of marking the position of polygons surrounded by multiple rectangles
linux下mysql数据库备份与恢复(全量+增量)
内网渗透系列:内网隧道之dns2tcp
BUUCTF MISC刷題
随机推荐
【编程实践/嵌入式比赛】嵌入式比赛学习记录(一):TCP服务器和web界面的建立
攻防世界MISC刷题1-50
Unity C single case mode learning review notes
VBA调用SAP RFC实现数据读取&写入
STO With Billing 跨公司库存转储退货
內網滲透系列:內網隧道之icmpsh
CTF-MISC总结
Online Safe Trajectory Generation For Quadrotors Using Fast Marching Method and Bernstein Basis Poly
Houdini>建筑道路可变,学习过程笔记
云计算赛项--2020年赛题基础部分[任务3]
The projection vector of a vector to a plane
Research on software security based on NLP (I)
Internal network security attack and defense: a practical guide to penetration testing (8): Authority maintenance analysis and defense
Redis--为什么字符串emstr的字符串长度是44字节上限?
linux下mysql数据库备份与恢复(全量+增量)
SAP tr manual import system operation manual
VBA appelle SAP RFC pour réaliser la lecture et l'écriture des données
Interview learning route
Ctf-misc learning from start to give up
内网渗透系列:内网隧道之icmp_tran