sql dop table while selecting

21. January 2007

this will drop the members table after selecting

 

SELECT * FROM members; DROP members--


Author: Aamir Hasan     औथोर: आमिर हसन       أثر أمير حسن .

ALL, SQL 2005 & 2008, SQL Injection

Paging Records Using SQL Server

2. January 2007



SELECT * FROM (SELECT ROW_NUMBER() OVER (ORDER BY id DESC)
AS Row, * FROM table1)
AS RowNumbers
WHERE Row >= 1 AND Row <= 5

SELECT * FROM (SELECT ROW_NUMBER() OVER (ORDER BY id DESC)
AS Row, * FROM table1)
AS RowNumbers
WHERE Row >= 6 AND Row <= 11

CREATE PROCEDURE dbo.AamirHasan
@PageIndex INT,
@PageSize INT
AS

BEGIN

WITH LogEn AS (
SELECT ROW_NUMBER() OVER (ORDER BY Date DESC)
AS Row, *
FROM members)

SELECT *
FROM LogEn
WHERE Row between

(@PageIndex - 1) * @PageSize + 1 and @PageIndex*@PageSize


END


Author: Aamir Hasan     औथोर: आमिर हसन       أثر أمير حسن .

ALL, SQL 2005 & 2008

Line Comments SQL Injection Attacks

1. January 2007
  • Username: admin'--
  • SELECT * FROM members WHERE username = 'admin'--' AND password = 'password'
    This is going to log you as admin user, password will ignore

Author: Aamir Hasan     औथोर: आमिर हसन       أثر أمير حسن .

ALL, SQL 2005 & 2008, SQL Injection

User Name: Guest

Your Ip: 38.107.191.112
Time: