5 SQL Injection of DVWA series (Blind)
The so-called blind note means that when we enter some special characters, the page does not display an error prompt, so we can only judge by whether the page is displayed properly.
Set DVWA Security to low, and then select SQL Injection (Blind) to view the source code of the page. You can find that unlike before, the mysql_numrows () function is preceded by an extra @ symbol, followed by a comment indicating that the @ symbol suppresses the error message.
As a matter of fact, blind injection does not have much effect on *. We can still display all the data by typing "or 1 # 1 #". The whole process is basically the same as before.