39

SQL注入之bWAPP之sqli_6.php-wx5a5f136bddbaa的博客

 6 years ago
source link: http://blog.51cto.com/13577444/2092108
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.
1、POST型注入就要先找到POST参数,在搜索框输入“1”后提交,按F12查看审查元素,找到“网络”,在点击POST项,接着点击右边的“参数”,查看POST的参数为“title”,如下图:2、开始构造,在hackbar的POST栏里输入“title=1'”,提交,返回的报错含有“%”,所以可以确定是搜索型注入。结果如下图:输入“title=1%'and'%'=&#

About Joyk


Aggregate valuable and interesting links.
Joyk means Joy of geeK