{"description":"Hello there, ('\u03c9')\u30ce SQL\u30a4\u30f3\u30b8\u30a7\u30af\u30b7\u30e7\u30f3\u306eUNION\u653b\u6483\u3067\u3001\u30af\u30a8\u30ea\u3067\u8fd4\u3055\u308c\u308b\u5217\u306e\u6570\u3092\u3002 \u30af\u30a8\u30ea\u306e\u7d50\u679c\u306f\u3001\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u306e\u5fdc\u7b54\u3067\u8fd4\u3055\u308c\u308b\u306e\u3067\u3002 \u30af\u30a8\u30ea\u3067\u8fd4\u3055\u308c\u308b\u5217\u306e\u6570\u304c\u308f\u304b\u3063\u3066\u3002 \u305d\u306e\u305f\u3081\u306b\u306f\u3001UNION\u3067null\u5024\u3092\u8ffd\u52a0\u3057\u3066\u3044\u3063\u3066\u3002 \u307e\u305a\u306f\u3001Pets\u30ab\u30c6\u30b4\u30ea\u3092\u9078\u629e\u3057\u3066\u3002 \u30a4\u30f3\u30bf\u30fc\u30bb\u30d7\u30c8\u3057\u3066\u30ea\u30d4\u30fc\u30bf\u3078\u3002 \u307e\u305a\u306f\u3001\u305d\u306e\u307e\u307eSend\u3057\u3066\u3002 GET\u30e1\u30bd\u30c3\u30c9\u306a\u306e\u3067\u3001\u30af\u30a8\u30ea\u3092\uff0b\u3067\u7d50\u5408\u3057\u3066\u8ffd\u52a0\u3057\u3066\u3001Send\u3057\u3066\u3002 GET /filter?category=Pets'+UNION+SELECT+NULL-- \u3082\u3046\u4e00\u3064\u3001NULL\u3092\u8ffd\u52a0\u3057\u3066\u30ec\u30b9\u30dd\u30f3\u30b9\u306e\u30b9\u30c6\u30fc\u30bf\u30b9\u3092\u78ba\u8a8d\u3057\u3066\u3002 GET /fi\u2026","height":"190","provider_name":"Hatena Blog","html":"<iframe src=\"https://hatenablog-parts.com/embed?url=https%3A%2F%2Fcysec148.hatenablog.com%2Fentry%2F2021%2F02%2F21%2F160008\" title=\"SQL injection UNION attack, determining the number of columns returned by the query\u3092\u3084\u3063\u3066\u307f\u305f - Shikata Ga Nai\" class=\"embed-card embed-blogcard\" scrolling=\"no\" frameborder=\"0\" style=\"display: block; width: 100%; height: 190px; max-width: 500px; margin: 10px 0px;\"></iframe>","published":"2021-02-21 16:00:08","author_url":"https://blog.hatena.ne.jp/ThisIsOne/","url":"https://cysec148.hatenablog.com/entry/2021/02/21/160008","blog_title":"Shikata Ga Nai","title":"SQL injection UNION attack, determining the number of columns returned by the query\u3092\u3084\u3063\u3066\u307f\u305f","blog_url":"https://cysec148.hatenablog.com/","image_url":"https://cdn-ak.f.st-hatena.com/images/fotolife/T/ThisIsOne/20210221/20210221135341.png","version":"1.0","categories":["PortSwigger"],"width":"100%","provider_url":"https://hatena.blog","type":"rich","author_name":"ThisIsOne"}