摘要: Lesson 11 POST -Error Based - Single Quotes (基于错误的POST型单引号字符型注入) (1)先输入admin和admin进行登录 sql语句为: SELECT username, password FROM users WHERE username='ad 阅读全文
posted @ 2020-03-17 22:47 zhaihuijie 阅读(154) 评论(0) 推荐(0) 编辑
摘要: Lesson 08 Blind -Boolian Based - Single Quotes (布尔型单引号GET盲注) (1)先进行探测 ?id=1 SELECT * FROM users WHERE id='1' LIMIT 0,1 (2)加上单引号,并注释掉 You are in...消失,说 阅读全文
posted @ 2020-03-17 22:16 zhaihuijie 阅读(124) 评论(0) 推荐(0) 编辑
摘要: Lesson 05 Double injection -Single quotes - string (双注入GET单引号字符型注入) bool型注入 (1)查看是否有注入 ?id=1 SELECT * FROM users WHERE id='1' LIMIT 0,1 当随便输入一个ID值时 没有 阅读全文
posted @ 2020-03-17 11:39 zhaihuijie 阅读(172) 评论(0) 推荐(0) 编辑