MySQL注入Bypass技巧汇总

文章目录

1.通过文件名查表

mysql> show tables;
+--------------------+
| Tables_in_students |
+--------------------+
| class              |
+--------------------+
1 row in set (0.00 sec)

mysql> SELECT FILE FROM `sys`.`io_global_by_file_by_bytes` WHERE FILE REGEXP DATABASE();
+-----------------------------------+
| file                              |
+-----------------------------------+
| @@basedir/data/students/class.ibd |
+-----------------------------------+
上一篇:***基础——活动目录信息的获取2:Bypass AV


下一篇:分享一个SQL的bypass小案例