SQL injection-WAF bypass

Principle-White Box Scenario

Insert picture description here

Principle-black box scenario

Insert picture description here
Insert picture description here

Fuzz bypassing WAF (using Bup)

Insert picture description here

sqlmap bypass waf

Insert picture description here

sqlmap Tamper script

Insert picture description here
Insert picture description here
The 28th level of sqli-labs-master is
written:
Insert picture description here

sqlmap -u "http://192.168.239.146/sqli-labs-master/Less-28/?id=1" --flush-session --tamper=sqlmap28.py   

Guess you like

Origin blog.csdn.net/weixin_42478365/article/details/114588523