Is it possible to do order by and union injection in wheres gammer’s subquery?
They tested what is happening in each of the databases.
First of all, mssql was all right, and Oracle had syntax error.
I don't know why how they set the rules.
Maybe it is because there is no need for order by clause. (ex, where id = (select user_id from meter import = ' 0010030 ') This is probably because only one value is extracted and imported.
I have taken a note of the information I checked with SQL injection but it will not be very useful in the future.
'Security' 카테고리의 다른 글
DevOps toolchain notes. (0) | 2018.07.24 |
---|---|
What is Devops? (0) | 2018.07.23 |
Error trigger function note (0) | 2018.07.21 |
Consideration on duplication parameters. (0) | 2018.07.20 |
Consideration on namming rules. (0) | 2018.07.19 |