First Order SQL Injections
What are SQL Injections
Detection
Injection in different parts of the Query
- In UPDATE statements, within the updated values or the WHERE clause.
- In INSERT statements, within the inserted values.
- In SELECT statements, within the table or column name.
- In SELECT statements, within the ORDER BY clause.
UNION Attacks
- How many columns are being returned from the original query.
- Which columns returned from the original query are of a suitable data type to hold the results from the injected query.
First Step: Determining how many columns are being returned from the original query
- ORDER BY method A method involves injecting a series of ORDER BY clauses, and incrementing the number until an error occurs, that way we can know the number of columns returned by the original query.
- UNION SELECT method Following the same principle, we can inject UNION SELECT 1,2,3,4,5... as long as the page doesn't error. That would also give an idea on where the injection is reflected in the database. A better way to inject is to use UNION SELECT NULL,NULL,NULL... to make sure that the value types are compatible and the injection is working as it should.

