order by ordering injection

Principle: in a different way queries are arranged in a different order number, such as sorting by name, according to sorting mail and so on.
1. The use MySQL if statements, such as if (1 = 1, email, nikename) is 1 = 1and email or follow nikename sort.
step one
Step Two
2. encoded capture tag
Here Insert Picture Description
3. Since only for implanting and 1 = 1, so the injection position plus and 1 = 1 then poured marker
Step Four
4. remember to change the delay, a second, blind
Step Five

  • Note: There is a space between do not delete / Encode> and HTTP / 1.1.
    Disclaimer: The pictures from A Course
Published 13 original articles · won praise 0 · Views 442

Guess you like

Origin blog.csdn.net/m0_46230316/article/details/105294023