SQL Injection
A SQL injection attack consists of insertion or "injection" of a SQL query via the input data from the client to the application.
Entry point detection
Simple characters
'
%27
"
%22
#
%23
;
%3B
)
Wildcard (*)
' # required for XML contentMultiple Encoding
%%2727
%25%27Merging characters
Logic Testing
Weird characters
DBMS Identification
Authentication Bypass
Authentication Bypass (Raw MD5 SHA1)
Polyglot injection (multicontext)
Routed injection
Insert Statement - ON DUPLICATE KEY UPDATE
Information_schema.tables Alternative
Version Alternative
Last updated