
本题考点: sqlmaplog日志分析 flag格式: flag{xxx}
SQLMAP注入
打开日志发现大量注入流量,攻击者是通过SQLMAP进行注入的,全文url解码进行分析
找到关键注入语句:IF%28%28ORD%28MID%28%28SELECT%20IFNULL%28CAST%28KeyIsMe%20AS%20CHAR%29%2C0x20%29%20FROM%20example.__key__%20ORDER%20BY%20ID%20LIMIT%200%2C
本题考点: sqlmaplog日志分析 flag格式: flag{xxx}
打开日志发现大量注入流量,攻击者是通过SQLMAP进行注入的,全文url解码进行分析
找到关键注入语句:IF%28%28ORD%28MID%28%28SELECT%20IFNULL%28CAST%28KeyIsMe%20AS%20CHAR%29%2C0x20%29%20FROM%20example.__key__%20ORDER%20BY%20ID%20LIMIT%200%2C