Extended SQL injection with Overflow

Source: Internet
Author: User

When I read the magazine hack in the box, I saw an article about how to expand the SQL injection attack method with the overflow method. Therefore, I wrote a record under the blog mark. I have previously mentioned the XSS method with overflow: Overflow.

When using a common statement injection, you may encounter the following error. In this case, you can consider using overflow to implement SQL injection (tested on MySQL 5.0.92 ):



The following is the injection statement provided by the author. % is missing at the beginning of 28 in the third row:

 

 

At the end of the article, the author also provides some injection statements that bypass WAF, the method is relatively old, but sometimes you can look back when you need to inject, as a record:

 

 

From: riusksk's blog

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.