A Comprehensive Approach For Testing For SQLI
A Comprehensive Approach For Testing For SQLI
A Comprehensive
Approach for Testing for
SQL Injection
Vulnerabilities
GOVERDHAN KUMAR
1
A Comprehensive Approach for Testing for SQL Injection Vulnerabilities GOVERDHAN KUMAR
Trust me, it really feels good when you see this the below
screenshot on your target application and why not? SQL
injection vulnerabilities generally are a valid P1 issues on
bug bounty programs.
2
A Comprehensive Approach for Testing for SQL Injection Vulnerabilities GOVERDHAN KUMAR
URL query
URL query
3
A Comprehensive Approach for Testing for SQL Injection Vulnerabilities GOVERDHAN KUMAR
POST body
POST body
Headers
Headers
Cookies
4
A Comprehensive Approach for Testing for SQL Injection Vulnerabilities GOVERDHAN KUMAR
Cookies
Example: user_id=1338-1
5
A Comprehensive Approach for Testing for SQL Injection Vulnerabilities GOVERDHAN KUMAR
Semicolon (;)
Examples:
Integer Parameter:
6
A Comprehensive Approach for Testing for SQL Injection Vulnerabilities GOVERDHAN KUMAR
Text Parameter:
Examples:
7
A Comprehensive Approach for Testing for SQL Injection Vulnerabilities GOVERDHAN KUMAR
Follow :
https://www.linkedin.com/in/goverdhankumar
https://github.com/wh04m1i
https://linktr.ee/g0v3rdh4n
https://instagram.com/who4m1i
Source : https://infosecwriteups.com/a-comprehensive-approach-for-testing-
for-sql-injection-vulnerabilities-23c8772ffba9