SQL injection combat —— 3. Bypass the general anti-injection system and continue to inject

Target address: http://219.153.49.228:43960/news.asp?id=1


Obviously, the anti-injection system is used here, so let's do a simple test



Now that the record is made, let's take a look at its record file


So I thought about constructing an ASP sentence to write into


If the result fails, then perform a simple encryption on the one-sentence Trojan:


Successful execution, then use the kitchen knife to connect!



After that, you can view the directory in the directory according to the prompt Key, and finally find it in the root directory of the C drive:



key为:mozhefd5a44d93bdc8ba75e24c3dc600

Guess you like

Origin http://43.154.161.224:23101/article/api/json?id=325693733&siteId=291194637