设为首页 加入收藏

TOP

一道CTF题引发的思考-MySQL的几个特性(续)(二)
2017-10-13 10:43:53 】 浏览:4945
Tags:一道 CTF 引发 思考 -MySQL 特性
--------------+
| 'AbC' regexp binary '^a'  |
+--------------------------+
| 0             |
+--------------------------+
1 row in set

mysql> select 'AbC' regexp binary '^A';
+--------------------------+
| 'AbC' regexp binary '^A'   |
+--------------------------+
| 1              |
+--------------------------+


在选择表或者是通过数据库函数如user(),database()等获取数据的测试情况:

  • 在查询表中字段数据时,无论是否进行编码 ,大小写都是不强匹配

mysql> select * from test where user like 'A%';
+---------+-------+---------------------------------------+
| user_id   | user   | password                |
+---------+-------+---------------------------------------+
| 1     | admin | 5f4dcc3b5aa765d61d8327deb882cf99|
| 2     | ADMIN| 5f4dcc3b5aa765d61d8327deb882cf99|
+---------+-------+---------------------------------------+
2 rows in set

mysql> select * from test where user like char(65,37) ;
+---------+-------+---------------------------------------+
| user_id   | user   | password                |
+---------+-------+---------------------------------------+
| 1     | admin | 5f4dcc3b5aa765d61d8327deb882cf99|
| 2     | ADMIN| 5f4dcc3b5aa765d61d8327deb882cf99|
+---------+-------+---------------------------------------+
2 rows in set

mysql> select * from test where user regexp '^A';
+---------+-------+---------------------------------------+
| user_id   | user   | password                |
+---------+-------+---------------------------------------+
| 1     | admin | 5f4dcc3b5aa765d61d8327deb882cf99|
| 2     | ADMIN| 5f4dcc3b5aa765d61d8327deb882cf99|
+---------+-------+---------------------------------------+
2 rows in set

mysql> select * from test where user regexp 0x5E61;
+---------+-------+---------------------------------------+
| user_id   | user   | password                |
+---------+-------+---------------------------------------+
| 1     | admin | 5f4dcc3b5aa765d61d8327deb882cf99|
| 2     | ADMIN| 5f4dcc3b5aa765d61d8327deb882cf99|
+---------+-------+---------------------------------------+
2 rows in set

mysql> select * from test where user regexp binary 0x5E41;
+---------+-------+----------------------------------------------+
| user_id   | user    | password                   |
+---------+-------+----------------------------------------------+
| 2      | ADMIN | 5f4dcc3b5aa765d61d8327deb882cf99    |
+---------+-------+----------------------------------------------+
1 row in set


0x02 测试结论

  MYSQL大小写不进行强匹配的。要想匹配大小写可以使用binary,或者使用http://www.cnblogs.com/Z3roTo0ne/p/6883132.html中的两次16进制编码的方式。进行大小写强匹配。

0x03 另外的一种方式

使用10进制和16进制混合也可以达到区分大小写的效果,因为大小写的16进制是不一样的。

mysql> select conv(hex(substr((user()),1,8)),16,10);
+---------------------------------------+
| conv(hex(substr((user()),1,8)),16,10) |
+---------------------------------------+
| 8245931987826405219        |
+---------------------------------------+
1 row in set

mysql> select unhex(conv((8245931987826405219),10,16));
+----------------------------------------------------+
| unhex(conv((8245931987826405219),10,16))       |
+----------------------------------------------------+
| root@loc                       |
+----------------------------------------------------+
1 row in set

首页 上一页 1 2 下一页 尾页 2/2/2
】【打印繁体】【投稿】【收藏】 【推荐】【举报】【评论】 【关闭】 【返回顶部
上一篇大数据,只看这个就够了 下一篇MongoDB学习笔记(一)

最新文章

热门文章

Hot 文章

Python

C 语言

C++基础

大数据基础

linux编程基础

C/C++面试题目