1.利用burpsuite爆破 抓包 ctrl+I將包復(fù)制到intruder模塊忘晤,因?yàn)橐獙assword參數(shù)進(jìn)行爆破捏顺,所以在password參數(shù)的內(nèi)容兩邊加$ 選中Payloads跃闹,載入字典次乓,點(diǎn)擊Start attack進(jìn)行爆破 2.手工sql注入 username:admin'or'1'='1 -username: admin'#