基于Http Header的SQL注入的方法详解
é常HTTPæ¶æ¯åæ¬å®¢æ·æºåæå¡å¨ç请æ±æ¶æ¯åæå¡å¨å客æ·æºçååºæ¶æ¯ãè¿ä¸¤ç§ç±»åçæ¶æ¯ç±ä¸ä¸ªèµ·å§è¡ï¼ä¸ä¸ªæèå¤ä¸ªå¤´åï¼ä¸ä¸ªåªæ¯å¤´åç»æç空è¡åå¯éçæ¶æ¯ä½ç»æãHTTPç头ååæ¬éç¨å¤´ï¼è¯·æ±å¤´ï¼ååºå¤´åå®ä½å¤´å个é¨åãæ¯ä¸ªå¤´åç±ä¸ä¸ªååï¼åå·ï¼:ï¼ååå¼ä¸é¨åç»æãååæ¯å¤§å°åæ å³çï¼åå¼åå¯ä»¥æ·»å ä»»ä½æ°éçç©ºæ ¼ç¬¦ï¼å¤´åå¯ä»¥è¢«æ©å±ä¸ºå¤è¡ï¼å¨æ¯è¡å¼å§å¤ï¼ä½¿ç¨è³å°ä¸ä¸ªç©ºæ ¼æå¶è¡¨ç¬¦ã
å¦ä¸å¾ï¼
GET / HTTP/1.1
Connection: Keep-Alive
Keep-Alive: 300
Accept:*/*
Host: host
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US;
rv:1.9.2.16) Gecko/20110319 Firefox/3.6.16 ( .NET CLR 3.5.30729; .NET4.0E)
Cookie: guest_id=v1%3A1328019064; pid=v1%3A1328839311134
å¦ä½æ§è¡ä¸ä¸ªHTTP头çSQL注å¥ï¼
ä¸è½½æ件cookie管çæ件
æå¼cookie管çå¨ï¼ç¶ååå»ç®æ ç½ç«
ç¼è¾ç®æ ç½ç«çcookieï¼æ¥éªè¯ç®æ ç½ç«æ¯å¦åå¨http头çSQL注å¥ï¼æ们ç¼è¾åélanguage_idçå段å容ï¼æ·»å åå¼å·’å·æ°é¡µé¢æ¥å¤æã
å·æ°é¡µé¢ï¼å¤ææ¯å¦åå¨SQL注å¥æ¼æ´
okï¼ä¸è½½æ件tamper-dataæ¥ä¿®æ¹è¯·æ±çæ°æ®å容ã
è¾å¥ä¸ä¸ªSQL注å¥è¯å¥
å¦ææ们è¾å¥order by 5– ï¼ä¼æ¥ä»¥ä¸é误ã
æ以å¯ä»¥å¤æå¾åºç¨æ·è¡¨å为4ï¼å使ç¨cookie管çå¨ï¼æ·»å 以ä¸ä»£ç å¨language_idå段éé¢ï¼
-1+UNION+ALL+SELECT+1,2,3,4
æèè¾å¥ä¸é¢çè¯å¥å¾å°æ°æ®åºç¨æ·æçæ¬ä¿¡æ¯çã
version()
user()
concat(database())
group_concat
ç¨SqlMap注å¥èµ·æ¥ä¼æ´ç®åï¼åç»ä¼å¸¦æ¥SqlMapçç¸å³æç« ï¼ï¼
ç¸å³é读ï¼
HTTPï¼HyperTextTransferProtocolï¼æ¯è¶ææ¬ä¼ è¾åè®®ç缩åï¼å®ç¨äºä¼ éWWWæ¹å¼çæ°æ®ï¼å³äºHTTPåè®®ç详ç»å容请åèRFC2616ãHTTPåè®®éç¨äºè¯·æ±/ååºæ¨¡åã客æ·ç«¯åæå¡å¨åéä¸ä¸ªè¯·æ±ï¼è¯·æ±å¤´åå«è¯·æ±çæ¹æ³ãURIãåè®®çæ¬ã以ååå«è¯·æ±ä¿®é¥°ç¬¦ã客æ·ä¿¡æ¯åå容ç类似äºMIMEçæ¶æ¯ç»æãæå¡å¨ä»¥ä¸ä¸ªç¶æè¡ä½ä¸ºååºï¼ç¸åºçå容åæ¬æ¶æ¯åè®®ççæ¬ï¼æåæèé误ç¼ç å ä¸åå«æå¡å¨ä¿¡æ¯ãå®ä½åä¿¡æ¯ä»¥åå¯è½çå®ä½å容ã
å¦ä¸å¾ï¼
GET / HTTP/1.1
Connection: Keep-Alive
Keep-Alive: 300
Accept:*/*
Host: host
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US;
rv:1.9.2.16) Gecko/20110319 Firefox/3.6.16 ( .NET CLR 3.5.30729; .NET4.0E)
Cookie: guest_id=v1%3A1328019064; pid=v1%3A1328839311134
å¦ä½æ§è¡ä¸ä¸ªHTTP头çSQL注å¥ï¼
ä¸è½½æ件cookie管çæ件
æå¼cookie管çå¨ï¼ç¶ååå»ç®æ ç½ç«
ç¼è¾ç®æ ç½ç«çcookieï¼æ¥éªè¯ç®æ ç½ç«æ¯å¦åå¨http头çSQL注å¥ï¼æ们ç¼è¾åélanguage_idçå段å容ï¼æ·»å åå¼å·’å·æ°é¡µé¢æ¥å¤æã
å·æ°é¡µé¢ï¼å¤ææ¯å¦åå¨SQL注å¥æ¼æ´
okï¼ä¸è½½æ件tamper-dataæ¥ä¿®æ¹è¯·æ±çæ°æ®å容ã
è¾å¥ä¸ä¸ªSQL注å¥è¯å¥
å¦ææ们è¾å¥order by 5– ï¼ä¼æ¥ä»¥ä¸é误ã
æ以å¯ä»¥å¤æå¾åºç¨æ·è¡¨å为4ï¼å使ç¨cookie管çå¨ï¼æ·»å 以ä¸ä»£ç å¨language_idå段éé¢ï¼
-1+UNION+ALL+SELECT+1,2,3,4
æèè¾å¥ä¸é¢çè¯å¥å¾å°æ°æ®åºç¨æ·æçæ¬ä¿¡æ¯çã
version()
user()
concat(database())
group_concat
ç¨SqlMap注å¥èµ·æ¥ä¼æ´ç®åï¼åç»ä¼å¸¦æ¥SqlMapçç¸å³æç« ï¼ï¼
ç¸å³é读ï¼
HTTPï¼HyperTextTransferProtocolï¼æ¯è¶ææ¬ä¼ è¾åè®®ç缩åï¼å®ç¨äºä¼ éWWWæ¹å¼çæ°æ®ï¼å³äºHTTPåè®®ç详ç»å容请åèRFC2616ãHTTPåè®®éç¨äºè¯·æ±/ååºæ¨¡åã客æ·ç«¯åæå¡å¨åéä¸ä¸ªè¯·æ±ï¼è¯·æ±å¤´åå«è¯·æ±çæ¹æ³ãURIãåè®®çæ¬ã以ååå«è¯·æ±ä¿®é¥°ç¬¦ã客æ·ä¿¡æ¯åå容ç类似äºMIMEçæ¶æ¯ç»æãæå¡å¨ä»¥ä¸ä¸ªç¶æè¡ä½ä¸ºååºï¼ç¸åºçå容åæ¬æ¶æ¯åè®®ççæ¬ï¼æåæèé误ç¼ç å ä¸åå«æå¡å¨ä¿¡æ¯ãå®ä½åä¿¡æ¯ä»¥åå¯è½çå®ä½å容ã
相关推荐
kentrl 2020-11-10
xiechao000 2020-05-18
咻咻ing 2020-07-04
wghou 2020-06-16
zkwgpp 2020-06-14
woniyu 2020-05-14
ysmh00 2020-05-14
0与的世界 2020-04-28
worldkun 2020-05-10
carolAnn 2020-04-20
zengni 2020-02-29
hygbuaa 2020-02-26
zhaolisha 2020-02-24
server { listen 80; server_name ××××.com; access_log /×××/×××/nginx/log/access.log; error_log /×××/×
咻咻ing 2020-02-02
JF0 2020-01-31
OwenJi 2020-01-17
webfullStack 2020-01-10