Up-to-date syndicated information on database & ERP privacy, security, audit and compliance
RSS icon Email icon Home icon
  • Fun ways to learn SQL injection

    Posted on June 30th, 2009 Team No comments

    50 ways to Inject your SQL

    I see your input’s not validated properly
    You have to check it at all tiers: 1, 2 and 3
    Give me a browser and quite soon you will agree. There must be
    50 ways to inject your SQL

    You see it really is my business to intrude
    The CTO wants to see this web app broke into
    Turn on my proxy and all doubt will be removed. There must be
    50 ways to inject your SQL
    50 ways to inject your SQL

    Try a quick hack, Jack
    Add a new row, Joe
    Try an insert, Kurt
    Change their SQL query

    Evade the regex, Rex
    Encode it all in hex
    Unbalance the quotes, Vinod
    And change the query

    Break the syntax, Max
    Use a backslash, Cash
    Try command shell, Mel,
    And change the query

    Use “one equals one,” son,
    Unhandled exception!
    Read the stack trace, ace
    and change the query

    He said our application is secure against your kind
    There are no simple vulnerabilities to find
    I said your coders write their code like they are blind, there must be
    50 ways to inject your SQL

    Leave a reply