码迷,mamicode.com
首页 > Web开发 > 详细

Ethical Hacking - Web Penetration Testing(9)

时间:2020-02-09 18:41:43      阅读:84      评论:0      收藏:0      [点我收藏+]

标签:图片   blog   user   nbsp   try   from   format   ant   mic   

SQL INJECTION

Discovering SQLi in GET

Inject by browser URL.

技术图片

 

Selecting Data From Database

Change the number to a big one, then you can get a useful error message. And you can try different number to find the right column.

技术图片

Using “union select 1,2,3,4,5” to find the right column.

技术图片

Then replace it with the information we want to get. (database, user, version)

技术图片

Ethical Hacking - Web Penetration Testing(9)

标签:图片   blog   user   nbsp   try   from   format   ant   mic   

原文地址:https://www.cnblogs.com/keepmoving1113/p/12287747.html

(0)
(0)
   
举报
评论 一句话评论(0
登录后才能评论!
© 2014 mamicode.com 版权所有  联系我们:gaon5@hotmail.com
迷上了代码!