MySQL 5.1.58指纹识别:comment injection解析及返回值差异疑问
Let's break down your two questions clearly, since you're working with MySQL 5.1.58 and sqlmap's fingerprinting feature:
1. What is Comment Injection (for SQL fingerprinting)?
In MySQL, the /*! ... */ syntax is a version-specific conditional comment—it's a special type of comment that doesn't behave like standard /* ... */ comments. Here's how it works:
- The number immediately after
/*!(e.g.,50158) maps directly to a MySQL version number (remove the dots from5.1.58to get50158). - If the running MySQL version is greater than or equal to the version in the comment, the database treats the content inside the comment as valid SQL and executes it.
- If the version is lower, the content is ignored entirely, just like a regular comment.
In the context of sqlmap's fingerprinting, "comment injection" refers to using this MySQL-specific feature to probe the database version. By sending payloads with different version numbers in these comments and checking the output, sqlmap can narrow down exactly which version you're running—this is how it identified your 5.1.58 instance.
2. Why do the two payloads return 0 and 1 respectively?
The key here is understanding how MySQL interprets the version numbers in the conditional comments. Let's break each payload down:
First Payload
SELECT (CASE WHEN (9427=9427/*!50158 AND 7430=2815*/) THEN 1 ELSE 0 END)
- Your database version is 5.1.58, which matches the
50158in the comment. MySQL executes the content inside the comment. - The full condition becomes:
9427=9427 AND 7430=28159427=9427is true, but7430=2815is false. The combinedANDcondition evaluates to false.- The CASE statement returns 0 because the condition is false.
Second Payload
SELECT (CASE WHEN (9427=9427/*!50159 AND 7430=2815*/) THEN 1 ELSE 0 END)
50159corresponds to MySQL 5.1.59, which is higher than your 5.1.58 version. MySQL ignores the content inside the comment entirely.- The condition simplifies to just
9427=9427, which is true. - The CASE statement returns 1 because the condition is true.
That's the core reason for the different results—MySQL only executes the conditional comment content when the version number matches or exceeds the value in the comment.
内容的提问来源于stack exchange,提问作者ditch

