InjEctiOn Result
InjEct!On Place
inject0r@7rs[~]#
SQLi Opt!ons
Test InjEctable
Show DB informaion
Make InjEction
[MySQL 5.x] Tables Search
Search for accounts tables in all DBs "may delay a while"
fetch tables from current database
Search for specified database,table, and/or column
  • Schema
  • Table
  • Column
[MS SQL Server] Fetch Tables
Brute Force Opt!ons
[MySQL 4.x] Tables/Columns Bruteforcing
Prefix to strengthen Attack *Just for experts!*
For tables     For columns
Ex: prefix_name
[MS Access/JET/SQL Server] Tables/Columns Bruteforcing
Admin CPanels Bruteforcing
Filetype "php the default"
Painful Attack Opt!ons
Fetch files
File path "passwd file is default"
InjEcting malicious files
Directory path "available to write more than one path to each line"
Malicious code "eval code is default"
Ex: <? phpinfo() ?>
[SQL Server] Attack target Page
Table Column "for more columns use a comma"
Your Page! "phrases, malicious codes,..."