📙
AppSec
search
Ctrlk
  • Overview
  • Write Ups Compilations/Resources
  • Main Resources
  • Labs
  • Cross Site Request Forgery
    • Cross Site Request Forgery (CSRF)chevron-right
  • Missing Access Controls
    • Missing Access Controlschevron-right
  • LFI / Directory Traversal
    • Local File Inclusionchevron-right
  • XXE
    • XML External Entity (XXE)chevron-right
  • Injection
    • Command Injectionchevron-right
    • Server-Side Template Injectionchevron-right
    • SQL Injectionchevron-right
      • SQLI Write-ups
      • Source Code Examples
      • More Write-ups
      • Labs
      • Resources & Tools
  • SSRF
    • Server-Side Request Forgery (SSRF)chevron-right
  • Unvalidated Redirects and Forwards
    • Unvalidated Redirects and Forwardschevron-right
  • Verbose Error Messages and Stack Traces
    • Verbose Error Messages and Stack Traceschevron-right
gitbookPowered by GitBook
block-quoteOn this pagechevron-down
  1. Injectionchevron-right
  2. SQL Injection

Resources & Tools

hashtag
Resources

  • https://portswigger.net/web-security/sql-injection/blindarrow-up-right

  • https://owasp.org/www-community/attacks/Blind_SQL_Injectionarrow-up-right

  • https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.htmlarrow-up-right

  • See the OWASP code review guide Section A1 https://owasp.org/www-pdf-archive/OWASP_Code_Review_Guide_v2.pdfarrow-up-right

  • more Advanced SQL Injectionarrow-up-right - by NGS

  • Blind SQL Injection Automation Techniquesarrow-up-right - Black Hat Pdf

  • Blind Sql-Injection in MySQL Databasesarrow-up-right

  • Cgisecurity.com: What is Blind SQL Injection?arrow-up-right

  • Kevin Spett from SPI Dynamics:

    • http://www.net-security.org/dl/articles/Blind_SQLInjection.pdfarrow-up-right

    • http://www.imperva.com/resources/whitepapers.asp?t=ADCarrow-up-right

    • Advanced SQL Injectionarrow-up-right

  • https://dev.mysql.com/doc/refman/8.0/en/select.htmlarrow-up-right

hashtag
Tools

  • SQL Power Injectorarrow-up-right

  • Absinthe :: Automated Blind SQL Injectionarrow-up-right

  • SQLBrute - Multi Threaded Blind SQL Injection Bruteforcerarrow-up-right in Python

  • SQLiX - SQL Injection Scannerarrow-up-right in Perl

  • sqlmap, automatic SQL injection toolarrow-up-right in Python

  • bsqlbf, a blind SQL injection toolarrow-up-right in Perl

  • Burpsuite

hashtag

PreviousLabschevron-leftNextServer-Side Request Forgery (SSRF)chevron-right

Last updated 4 years ago

Was this helpful?

  • Resources
  • Tools

Was this helpful?