'and(select 1 from(select count(*),concat((select concat(CHAR(52),CHAR(67),CHAR(117),CHAR(110),CHAR(78),CHAR(117),CHAR(106),CHAR(119),CHAR(101),CHAR(99),CHAR(78)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a)and'
我是电力企业的员工,第一次遇到这个网站。因为不懂,胡乱尝试了几种情景的拟合。结果总是出现这个提示,无法拟合。
现在搞不清这个网站存在的意义,是盈利还是公益?是开放式工具,开始测试性平台?也没个背景介绍和操作指南.......
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
i18n14svki)(objectClass=*
1
i18n14svki)(!(objectClass=*)
1
nyl10cslj4)(objectClass=*
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
response.Write(142723791007+124545643543)
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
{{1029*1991}}
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
InjectedHeader: injected_value
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
dec0yscanner
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
*)(objectClass=*
1
*)(!(objectClass=*)
1
*
1
1
1
1
1
InjectedHeader: injected_value
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1&ver
1
1|ver
1
1|id
1
1&id
1
1;id
1
phpinfo();
1
`set|set&set`
1
${@print(md5(dec0y))}
1
'set|set&set'
1
aWQ=
1
127.0.0.1|id||
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
dec0y<s1﹥s2ʺs3ʹscanner
1
1
1
1
1'
1
1' having 2=2--
1
1 having 2=2--
1
1";
1
'and(select 1 from(select count(*),concat((select concat(CHAR(52),CHAR(67),CHAR(117),CHAR(110),CHAR(78),CHAR(117),CHAR(106),CHAR(119),CHAR(101),CHAR(99),CHAR(78)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a)and'
1
1a
1
(select char(97)+char(110)+char(116)+char(105)+char(95)+char(100)+char(101)+char(99)+char(48)+char(121))
1
1'"
1
1
1
1
1
1
1
1
1
1
1
1
1
*)(objectClass=*
1
*)(!(objectClass=*)
1
*
1
1
1
1
1
1
1
1
1a'";|)12345'"\'\");|]* { <