Skip to content

Commit ea531a1

Browse files
committed
sql injection demo
1 parent dc9db2f commit ea531a1

5 files changed

Lines changed: 75 additions & 50 deletions

File tree

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,10 @@
1+
# author: greyshell
2+
# usage: mysql -u root -p < resource.sql
3+
# alternale usage for automation: mysql -u root --password=mypass < resource.sql
4+
5+
# sql injection: case02, clear the posts
6+
delete from vulnapp.tbl_post02 where user NOT LIKE 'asinha%';
7+
8+
# sql injection: case03, clear the posts
9+
delete from vulnapp.tbl_post03 where user LIKE 'anonymous-%';
10+
update vulnapp.tbl_post03 set age = 25, comment = 'Hello', city = 'San Jose' where user = 'admin';
Lines changed: 16 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,16 @@
1+
# author: greyshell
2+
# usage: mysql -u root -p < resource.sql
3+
# alternale usage for automation: mysql -u root --password=mypass < resource.sql
4+
5+
# drop all tables
6+
# sql injection: case01
7+
DROP TABLE vulnapp.tbl_post01
8+
9+
# sql injection: case02
10+
DROP TABLE vulnapp.tbl_post02
11+
DROP TABLE vulnapp.tbl_secret
12+
13+
# sql injection: case03
14+
DROP TABLE vulnapp.tbl_post03
15+
16+
DROP DATABASE vulnapp;
Lines changed: 48 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,48 @@
1+
# author: greyshell
2+
# usage: mysql -u root -p < resource.sql
3+
# alternale usage for automation: mysql -u root --password=mypass < resource.sql
4+
5+
# create database
6+
CREATE DATABASE vulnapp;
7+
8+
# sql injection: case01
9+
CREATE TABLE vulnapp.tbl_post01 (
10+
comment VARCHAR(30) NOT NULL,
11+
user VARCHAR(10) NOT NULL
12+
);
13+
14+
INSERT INTO vulnapp.tbl_post01 (comment, user) VALUES ('hola', 'pedro');
15+
INSERT INTO vulnapp.tbl_post01 (comment, user) VALUES ('hi', 'usman');
16+
INSERT INTO vulnapp.tbl_post01 (comment, user) VALUES ('ola', 'amol');
17+
18+
19+
# sql injection: case02
20+
CREATE TABLE vulnapp.tbl_post02 (
21+
comment VARCHAR(30) NOT NULL,
22+
pin INT NOT NULL,
23+
age INT NOT NULL,
24+
user VARCHAR(30) NOT NULL
25+
);
26+
27+
INSERT INTO vulnapp.tbl_post02 (comment, pin, age, user) VALUES ('hola', 100, 25, 'dhaval');
28+
29+
CREATE TABLE vulnapp.tbl_secret (
30+
user VARCHAR(30) NOT NULL,
31+
token INT NOT NULL,
32+
password VARCHAR(30) NOT NULL
33+
);
34+
35+
INSERT INTO vulnapp.tbl_secret (user, token, password) VALUES ('asinha', 777, 'blue@123');
36+
INSERT INTO vulnapp.tbl_secret (user, token, password) VALUES ('admin', 101, 'grey@321');
37+
38+
# sql injection: case03
39+
CREATE TABLE vulnapp.tbl_post03 (
40+
comment VARCHAR(30) NOT NULL,
41+
city VARCHAR(30) NOT NULL,
42+
age INT NOT NULL,
43+
user VARCHAR(30) NOT NULL,
44+
PRIMARY KEY (user)
45+
);
46+
47+
INSERT INTO vulnapp.tbl_post03 (comment, city, age, user) VALUES ('hello', 'mountain view', 25, 'dhaval');
48+
INSERT INTO vulnapp.tbl_post03 (comment, city, age, user) VALUES ('hi', 'santa clara', 19, 'admin');

‎web/sqli/db_setup.sql‎

Lines changed: 0 additions & 49 deletions
This file was deleted.

‎web/sqli/template/case02.html‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -17,7 +17,7 @@
1717
<body>
1818
<h2>SQL Injection</h2>
1919
<i>author: greyshell</i><br><br>
20-
Objective: extract admin's password and token <br><br>
20+
Objective: extract admin's token(INT) and password(VARCHAR) from a secret table<br><br>
2121
<form method="POST">
2222
Enter your comment:
2323
<label>

0 commit comments

Comments
 (0)