• Unfortunately, we have experienced significant hard drive damage that requires urgent maintenance and rebuilding. The forum will be a state of read only until we install our new drives and rebuild all the configurations needed. Please follow our Facebook page for updates, we will be back up shortly! (The forum could go offline at any given time due to the nature of the failed drives whilst awaiting the upgrades.) When you see an Incapsula error, you know we are in the process of migration.

[Song] 50 ways to inject your SQL

Status
Not open for further replies.
Experienced Elementalist
Joined
Jan 6, 2009
Messages
261
Reaction score
88
Sing to "50 Ways to Leave Your Lover,"

50 ways to inject your SQL


I see your input's not validated properly
You have to check it at all tiers: 1, 2 and 3
Give me a browser and quite soon you will agree. There must be
50 ways to inject your SQL

You see it really is my business to intrude
The CTO wants to see this web app broke into
Turn on my proxy and all doubt will be removed. There must be
50 ways to inject your SQL
50 ways to inject your SQL

Try a quick hack, Jack
Add a new row, Joe
Try an insert, Kurt
Change their SQL query

Evade the regex, Rex
Encode it all in hex
Unbalance the quotes, Vinod
And change the query

Break the syntax, Max
Use a backslash, Cash
Try command shell, Mel,
And change the query

Use "one equals one," son,
Unhandled exception!
Read the stack trace, ace
and change the query

He said our application is secure against your kind
There are no simple vulnerabilities to find
I said your coders write their code like they are blind, there must be
50 ways to inject your SQL

He said our logs show unexpected funds were sent
Its probably time we started using Prepared-Statements
I said I'm glad you're seeing what I meant, there were
50 ways to inject your SQL
50 ways to inject your SQL

Break the syntax, Max
Use a backslash, Cash
Try command shell, Mel,
And change the query

Use "one equals one," son,
Unhandled exception!
Read the stack trace, ace
and change the query

Try a quick hack, Jack
Add a new row, Joe
Try an insert, Kurt
Change their SQL query

Evade the regex, Rex
Encode it all in hex
Unbalance the quotes, Vinod
And change the query
 
Super Mexican
Loyal Member
Joined
Jun 26, 2008
Messages
1,517
Reaction score
2
Wow lol.
If I knew about injection and SQL better it might be funnier.

Wasnt very funny to me though.
 
Mythic Archon
Joined
Feb 11, 2006
Messages
745
Reaction score
0
I am soo going to steal that and plaster that onto a poster. >3
 
Status
Not open for further replies.
Back
Top