Get the App
SLTechnology News&Howtos  ›  Network Security  › 

5 SQL Injection of DVWA series (Blind)

Shulou Source: shulou.com Published: 2022-06-01 07:07:01 10月02日 Update

The so-called blind note means that when we enter some special characters, the page does not display an error prompt, so we can only judge by whether the page is displayed properly.

Set DVWA Security to low, and then select SQL Injection (Blind) to view the source code of the page. You can find that unlike before, the mysql_numrows () function is preceded by an extra @ symbol, followed by a comment indicating that the @ symbol suppresses the error message.

As a matter of fact, blind injection does not have much effect on *. We can still display all the data by typing "or 1 # 1 #". The whole process is basically the same as before.

Tags: Symbols pages input different special consistent information functions characters that is data comments source code web pages procedures errors influences prompts choices Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Linux NVidia Shulou Information Xiaomi macOS