Master site SQL injection of the red/Black alliance and bypassing Baidu cloud Acceleration
Master site SQL injection of the red/Black alliance and bypassing Baidu cloud Acceleration
When I went to the Consortium for study, I started to search for 123. The returned content was irrelevant to 123. I searched 123qwe at the same time. The page reported an error and I was told by intuition that injection was tested repeatedly, search for pure numbers returns results, but is irrelevant to the number you search for. If you search for a string that starts with a number and contains a letter, an error is returned. If you search for a string that starts with a letter, the http://www.bkjia.com is returned.
Mask Region
* ***** Init & typeid = 1 & *****
Search 123qwe
Baidu cloud accelerated Filtering
Add * in the keyword to bypass Baidu cloud Acceleration
Obtain the database name. Try again instead of the root user.
Table
Field