Manual para participantes CTF
Introduction to the Web . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1 1.1 Significant “Information Gathering” . . . . . . . . . . . . . . . . . . . . . 1 1.1.1 The Importance of Information Gathering . . . . . . . . . . 1 1.1.2 Classification of Information Collection . . . . . . . . . . . . 2 1.2 SQL Injection in CTF . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10 1.2.1 SQL Injection Basics . . . . . . . . . . . . . . . . . . . . . . . . . 10 1.2.2 Injection Points . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 25 1.2.3 Injection and Defense . . . . . . . . . . . . . . . . . . . . . . . . . 31 1.2.4 Impacts of Injection . . . . . . . . . . . . . . . . . . . . . . . . . . 37 1.2.5 SQL Injection Summary . . . . . . . . . . . . . . . . . . . . . . . 38 1.3 Arbitrary File Read Vulnerability . . . . . . . . . . . . . . . . . . . . . . . 38 1.3.1 Common Trigger Points for File ...