Administrator
发布于 2024-04-11 / 143 阅读
0
0

SQLI-LABS

A Platform To Learn SQLI Following Labs

访问地址(Saas):https://sqli.exp-9.com/

源代码:https://github.com/Audi-1/sqli-labs

SQLI-LABS is a platform to learn SQLI Following labs are covered for GET and POST scenarios:

Error Based Injections (Union Select)

String

Intiger

Error Based Injections (Double Injection Based)

BLIND Injections: 1.Boolian Based 2.Time Based

Update Query Injection.

Insert Query Injections.

Header Injections. 1.Referer based. 2.UserAgent based. 3.Cookie based.

Second Order Injections

Bypassing WAF

Bypassing Blacklist filters Stripping comments Stripping OR & AND Stripping SPACES and COMMENTS Stripping UNION & SELECT

Impidence mismatch

Bypass addslashes()

Bypassing mysql_real_escape_string. (under special conditions)

Stacked SQL injections.

Secondary channel extraction

更详细内容查看

独立博客 https://www.dataeast.cn/
CSDN博客 https://blog.csdn.net/siberiaWarpDrive
B站视频空间 https://space.bilibili.com/25871614?spm_id_from=333.1007.0.0
关注 “曲速引擎 Warp Drive” 微信公众号
公众号二维码


评论