时间注入(盲注)##一.题目概述
页面回显只有You are in………..,无从下手,只能尝试时间注入,观察页面访问的时间
##二.Python脚本与sqlmap运用
sqlmap -u “http://a4676e5cb2bbf2db6a7365b7.http-ctf2.dasctf.com/Less-9/?id=1“ –technique=T –dbs –batch –time-sec=1 –threads=10 –dbms=mysql
##三.sql手动时间注入的方法
?id=1’ AND IF(LENGTH(databas
2026-09-25308 words2 mins
布尔注入(盲注)
##一.题目概述
在CTF2中,sqli-labs,less-8是一道考验布尔注入的题,如果条件正确会显示You are in………..,若条件为错不会有回显,凭借这个可以看出本题要盲注(二分法)
##二.方法(主要依靠脚本或者sqlmap)
在ASCII的基础上运用二分法提高效率(穷举效率慢)
脚本
爆库名
爆表名(select+group_concat(table_name)+from+information_schema.tables+where+table_schema=’security’+limit+0,1)
爆字段(select+group_concat(colum
2026-09-23203 words1 min
报错注入
报错注入##一.题目概述
在CTF2中,sqil-labs,less-5页面不会回显数据,只会在你注入成功时显示You are in …….,失败时什么都没有。这种关卡通常需要用到报错注入(不会回显数据)
##二.尝试与发现
固定输入?id=1,加上‘,?id=1’,发现报错,然后用–+注释掉后面的东西,即?id=1’+–+,恢复正常,报错注入前不需要先ORDER BY ,尝试报错注入
##三.尝试结果
##四.详细步骤
##五.若结果无法完全展示
可以用到substr
)
##小结
第一次学到报错注入,感觉有点难,但是很有意思!图片问题终于真正
2026-09-2375 words1 min
Hello World
Welcome to Hexo! This is your very first post. Check documentation for more info. If you get any problems when using Hexo, you can find the answer in troubleshooting or you can ask me on GitHub.
Quick StartCreate a new post1$ hexo new "My New Post"
More info: Writing
Run server1$ hexo ser