sqli-labs靶场(1)GET型
Contents
sqli-labs靶场精简记录1-10
Less-1 GET - Error based - Single quotes - String
基于错误的GET单引号字符型注入
vul
|
|
bypass
|
|
|
|
Less-2GET - Error based - Intiger based
基于错误的GET整型注入
vul
|
|
bypass
|
|
Less-3 GET - Error based - Single quotes with twist string
基于错误的GET单引号变形字符型注入
vul
|
|
bypass
|
|
Less-4 GET - Error based - Double Quotes - String
基于错误的GET双引号字符型注入
vul
|
|
bypass
|
|
Less-5 GET - Double Injection - Single Quotes - String
双注入GET单引号字符型注入
vul
|
|
payload
基于报错注入
|
|
基于时间盲注
sleep()函数
|
|
benchmark () 函数
|
|
script
|
|
xpath注入
|
|
payload
|
|
Less-6 GET - Double Injection - Double Quotes - String
双注入GET双引号字符型注入
vul
|
|
bypass
|
|
Less-7 GET - Dump into outfile - String
导出文件GET字符型注入
vul
|
|
bypass
|
|
但需要网站的绝对路径
|
|
利用 into outfile 导出文件
|
|
将数据库里面的信息导出到文件中
|
|
也可以写进webshell
|
|
Less-8 GET - Blind - Boolian Based - Single Quotes
布尔型单引号GET盲注
vul
|
|
bypass
|
|
Less-9 GET - Blind - Time based. - Single Quotes
基于时间的GET单引号盲注
bypass
|
|
Less-10 GET - Blind - Time based - double quotes
基于时间的双引号盲注
vul
|
|
bypass
|
|
盲注截取函数
mid()
|
|
substr () 与 substring ()
|
|
left()
|
|
编码函数
ord()
|
|
ascii()
|
|