【发布时间】:2015-02-20 05:04:24
【问题描述】:
过去,当我看到有人试图弄乱输入变量时 - 我只是阻止了他们的 IP……但似乎他们只是使用不同的 IP 并重试。因此,我设置了陷阱以在有人尝试时提醒我,并尝试找出他们试图获取的内容,以便我可以修复任何可能的漏洞。
我尝试过,他们将 var 更改为:
-999.9 / *!30000 UNION ALL SELECT 0x31303235343830303536,0x31303235343830303536,0x31303235343830303536,0x31303235343830303536,0x31303235343830303536,0x31303235343830303536,0x31303235343830303536,0x31303235343830303536,0x31303235343830303536,0x31303235343830303536,0x31303235343830303536,0x31303235343830303536,0x31303235343830303536,0x31303235343830303536,0x31303235343830303536,0x31303235343830303536,0x31303235343830303536,0x31303235343830303536,0x31303235343830303536, 0x31303235343830303536,0x31303235343830303536,0x31303235343830303536,0x31303235343830303536,0x31303235343830303536,0x31303235343830303536,0x31303235343830303536,0x31303235343830303536,0x31303235343830303536,0x31303235343830303536,0x31303235343830303536 * / -
我希望有人能帮忙解释一下这是什么意思?
【问题讨论】:
-
快速搜索
0x31303235343830303536会在这家精品店中获得多个结果。标记为重复。
标签: mysql sql-injection