Login Register




The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


Hack a website using SQL Injection - step by step guide filter_list
Author
Message
RE: Hack a website using SQL Injection - step by step guide #11
(02-21-2014, 06:24 PM)Ligeti Wrote: Thank you for sharing, it was interesting (and easy) to read Smile

Question:

Why do you people - and I mean everyone who writes about SQLi - target the URL only (using the get method)? I don't remember seeing anything about the post method (using forms for example), am I right or did I miss something?

Thanks

The answer to that question is probably simplicity. But I do understand why you maybe are a little frustrated about that Smile But the thing is that, what you do in the GET request you do in the POST request as well. So it's identical approach except that you write the queries in the form field instead. In the end sql injection is the same no matter where you use it.

I hope that maybe answered your question Smile

@Ex094 Smile
"SQL Injection-a-holic"

Twitter | Security Sucks | My Blog

Reply





Messages In This Thread