![]() |
|
SQL Injection Tutorial - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: Hacking (https://sinister.li/Forum-Hacking) +--- Forum: Tutorials (https://sinister.li/Forum-Tutorials) +--- Thread: SQL Injection Tutorial (/Thread-SQL-Injection-Tutorial--43243) |
RE: SQL Injection Tutorial - bun_cuoi_lam - 12-23-2012 thank bro.this's very useful for me and veryone RE: SQL Injection Tutorial - Wiz_ - 01-21-2013 First off I would like to say this was a great tutorial. It really helped me a lot. I had just one problem when you added the database name in. It keeps giving me an error. I have triple checked I followed exactly what you had but I keep getting an error. If you could help me in any way it would be much appreciated. RE: SQL Injection Tutorial - LEGITimacy™ - 01-22-2013 Wish you would have done this one yourself :/ Anyways you should have atleast explained WAF bypassing. Sometimes the server will have a windows application firewall. This will sanitize some SQL commands such as UNION SELECT in most cases and you will have to bypass that and trick the server into no sanitizing it. You can do this by using whitespacing and many other methods like so: /**UNION**/+/**SELECT**/+1,2,3.. Might make a TUT for you guys on this later on. RE: SQL Injection Tutorial - noize - 01-24-2013 Really thanks for posting, man. so much useful. definitely the greatest SQLi tutorial i've found. very well detailed and much much comprehensible. keep this up.. RE: SQL Injection Tutorial - Redoctober - 02-26-2013 hey i got a problem because i think i'm not well experienced on that actully it's first time i'm trying to do that ..so the problem is when i arrive to the step to find the column name i wrote all table name in the place where in ur example u wrote ''You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '\"es_cms_users\"--' at line 1 '' ... i tried also to convert to hex n after same error ''You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '\"0x65735f656e5f636d735f64616e65\"--' at line 1'' where am i making it wrong please help ;=) thanks a lot for share
RE: SQL Injection Tutorial - cyber_d3face - 08-16-2013 Thanks for your post. I always have a need for good explanations for sqli as well as a good manual. HQ post RE: SQL Injection Tutorial - eng-spy - 09-07-2013 Thank you for this tutorial RE: SQL Injection Tutorial - EgyptGhost - 10-03-2013 (09-19-2012, 07:54 AM)Solixious Wrote: I've never used a software myself, but I've heard that Havij is a good software for SQLi.me too RE: SQL Injection Tutorial - EgyptGhost - 10-03-2013 (09-19-2012, 07:54 AM)Solixious Wrote: I've never used a software myself, but I've heard that Havij is a good software for SQLi.me too RE: SQL Injection Tutorial - EgyptGhost - 10-03-2013 (09-19-2012, 07:54 AM)Solixious Wrote: I've never used a software myself, but I've heard that Havij is a good software for SQLi.me too |