sqli-labs靶场(6)堆叠注入
Contents
sqli-labs靶场精简记录38-45
Less-38 GET- Stacked Query Injection - String
基于错误 GET 单引号字符型堆叠注入
vul
|
|
因为存在mysqli_multi_query函数,该函数支持多条sql语句同时进行。
使用分号,来执行两条命令
插入新数据
|
|
Less-39 GET - Stacked Query Injection - Intiger
基于错误 GET 数字型堆叠注入
|
|
Less-40 GET - BLIND based - String - Stacked
基于布尔 GET 单引号小括号字符型盲注堆叠注入
bypass
|
|
关闭了报错,但是可以根据页面是否有内容来判断,语句是否正确
Less-41 GET - BLIND based - Intiger - Stacked
基于布尔 GET 数字型盲注堆叠注入
bypass
|
|
Less-42 - POST - Error based - String - Stacked
基于存储 POST 单引号字符型堆叠注入
|
|
post发包
|
|
less43 POST -Error based -String -Stacked with tiwst
POST型基于错误的堆叠变形字符型注入
bypass
|
|
Less-44 - POST - Error based - String - Stacked -Blind
基于存储 POST 单引号字符型盲注堆叠注入
bypass
|
|
less-45 POST - Error based - String - Stacked - Blind
基于存储 POST 单引号小括号字符型盲注堆叠注入
bypass
|
|