Get the App
SLTechnology News&Howtos  ›  Database  › 

Sql injects piecemeal knowledge

Shulou Source: shulou.com Published: 2022-06-01 12:19:59 10月04日 Update

1. Order by explains:

In order by language, the query results can be sorted by adding the field name after the SQL statement. But he has a special usage, that is, the way to add numbers instead of field names. When you add a number, it indicates that it is sorted by the fields of the table. Valid only if the number is less than the number of fields. So through this condition, you can determine how many fields exist in a table. For example, if order by 10 returns normal and the order by 11 page returns an error, there are 10 fields in the database.

2 、 union select 1,2,3,4,5,6,7,8,9,10,11 from

First of all, explain the meaning of the next few numbers in select. 1Jing 2Jing 3Jing 4. The numbers here are purely made up of numbers, which are the same as the number of fields in the table in front of the union keyword, otherwise they can not be spliced into a table. During sql injection, the query results will be displayed after replacing the corresponding location with the data you want. The last line of the figure is as follows:

3. Common functions

There are many injection functions in mysql, such as user () database () version () to view the user name of the current database connection. The database name and the version of mysql, for example, return 367, so you replace 367 with user () database () version (), that is, union select 1, 2, user (), 4, 5, loadfile (), version (), 9, 10, 11, so that the absolute path of the user name can be revealed on the page.

Tags: Fields numbers data databases functions times users user names results pages sorting query interpretation valid special one line that is location key keyword Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Redmi Huawei Shulou Tech Info MariaDB macOS