RE: Hack a website using SQL Injection - step by step guide 03-02-2014, 11:37 AM
#11
(02-21-2014, 06:24 PM)Ligeti Wrote: Thank you for sharing, it was interesting (and easy) to read
Question:
Why do you people - and I mean everyone who writes about SQLi - target the URL only (using the get method)? I don't remember seeing anything about the post method (using forms for example), am I right or did I miss something?
Thanks
The answer to that question is probably simplicity. But I do understand why you maybe are a little frustrated about that
But the thing is that, what you do in the GET request you do in the POST request as well. So it's identical approach except that you write the queries in the form field instead. In the end sql injection is the same no matter where you use it.I hope that maybe answered your question

@Ex094




![[+]](https://sinister.li/images/modern/collapse_collapsed.png)
![[Image: wvBFmA5.png]](http://i.imgur.com/wvBFmA5.png)