(09-19-2014, 09:59 PM)Reiko Wrote: In many cases you don't actually have to encode the table name, and you certainly don't need to do it this way. Hex is faster and smaller and uses less CPU on the server. Unless for some reason quotes are being escaped server-side you can just use table_name='fish';
https://dev.mysql.com/doc/refman/5.6/en/ Here, have a look at this. You might learn something... probably not.
Why post these things if you don't understand their use cases?
By the way, this is absolutely a jab at you. I didn't -rep you for pleasure. I -repped you because you are a poser.
Agreed. It always baffles me how people dive into topics such as "code injection" without learning much (or anything) about the code they're injecting or the systems involved in the process.
This isn't a new topic but maybe my opinion will help someone out... (I'm probably just nitpicking):
Quote:Basically, SQLi is the abuse and exploitation of a MySQL Database that most websites (and even some professional websites) run on/with.
I feel like quite a few people are confusing the concepts of SQL (the actual language standard) and a DBMS like MySQL, PostgreSQL or MS SQL Server. To put it simply, many of these DBMS are implementations of the SQL language alongside other features such as front-ends, security mechanisms, administration tools, etc., etc.
It's also worth noting that many of them (if not all of the popular ones) don't exactly adhere to the standard, which results in several syntactical differences (amongst others) between the systems. This is why, in my opinion, spending some time learning the SQL standard is important; even for code injection. Some of the syntax you presented may work fine on a server running MySQL, but what if someone wants to execute this on a server running MS SQL? They may have trouble applying these concepts when all they have done is memorize some syntax. That's why I believe tutorials like this should speak more on the concepts and less on the specifics such as syntax.
The Lesson: The general concepts of the language are usually very much the same across these different database systems. However, the specific differences between them can be very, very different (if that even makes sense).