List of all the SQL Injection Strings
One of the major problems with SQL is its poor security issues surrounding is the login and url strings. This tutorial is not going to go into detail on why these string work as all these details have been given in my previous article Top 10 Tricks to exploit SQL Server Systems .
First SEARCH the following Keywords in Google or any Search Engine:
admin\login.asp
login.asp
with these two search string you will have plenty of targets to chose from…choose one that is Vulnerable
INJECTION STRINGS: How to use it?
This is the easiest part…very simple
On the login page just enter something like
user:admin (you dont even have to put this.)
pass:’ or 1=1–
or
user:’ or 1=1–
admin:’ or 1=1–
Some sites will have just a password so
password:’ or 1=1–
In fact I have compiled a combo list with strings like this to use on my chosen targets . There are plenty of strings in the list below. There are many other strings involving for instance UNION table access via reading the error pages table structure thus an attack with this method will reveal eventually admin U\P paths.
The one I am interested in are quick access to targets
PROGRAM
i tried several programs to use with these search strings and upto now only Ares has peformed well with quite a bit of success with a combo list formatted this way. Yesteday I loaded 40 eastern targets with 18 positive hits in a few minutes how long would it take to go through 40 sites cutting and pasting each string
combo example:
admin:’ or a=a–
admin:’ or 1=1–
And so on. You don’t have to be admin and still can do anything you want. The most important part is example:’ or 1=1– this is our basic injection string
Now the only trudge part is finding targets to exploit. So I tend to search say google for login.asp or whatever
inurl:login.asp
index of:/admin/login.asp
like this: index of login.asp
result:
http://www3.google.com/search?hl=en&ie=ISO…G=Google+Search
17,000 possible targets trying various searches spews out plent more
Now using proxy set in my browser I click through interesting targets. Seeing whats what on the site pages if interesting I then cut and paste URL as a possible target. After an hour or so you have a list of sites of potential targets like so
http://www.somesite.com/login.asp
http://www.another.com/admin/login.asp
and so on. In a couple of hours you can build up quite a list because I don’t select all results or spider for log in pages. I then save the list fire up Ares and enter
1) A Proxy list
2) My Target IP list
3) My Combo list
4) Start.
Now I dont want to go into problems with users using Ares..thing is i know it works for me…
Sit back and wait. Any target vulnerable will show up in the hits box. Now when it finds a target it will spew all the strings on that site as vulnerable. You have to go through each one on the site by cutting and pasting the string till you find the right one. But the thing is you know you CAN access the site. Really I need a program that will return the hit with a click on url and ignore false outputs. I am still looking for it. This will saves quite a bit of time going to each site and each string to find its not exploitable.
There you go you should have access to your vulnerable target by now
Another thing you can use the strings in the urls were user=? edit the url to the = part and paste ‘ or 1=1– so it becomes
user=’ or 1=1– just as quick as login process
There are lot of other variations of the Injection String which I cannot put on my blog because that is Illegal. If you are interested I can send it to you through Email. Just write in your email address in comment and I will send it to you as early as possible but you need to remain patient it may take 1 or 2 days.
As a result of a lot of requests for the list of SQL Injection String and due to lack of time on our behalf to respond to your Comments we have now decided to give the download link for the list of SQL Injection Strings. Now you just need to Subscribe to our RSS Feed via Email and get the Download link at the bottom of the Confirmation Email. Please don’t Forget to click on the Confirmation Link given in that Email.
Here is the form to Subscribe to our RSS feed via Email:
Happy Hunting
Popularity: 16% [?]
Enjoyed this article? Subscribe to Hacking Truths and get daily updates about new cool websites and programs in your email for free.


please send me the injection strings you are talking about i’m interested , thanks
edu@edugodinho.com – Combo List..
Me too, thanks.
please send me the combo list .
Hi friend i have read ur topic on SQL
plz mail to me the list
if possible then plz explain me brief idea about how to us bcoz i am new to this….
and on which sites i can use it !!
BYE………
Can you email me the list please.
I’d like to have it too!
Thx!
with respect, kindly send me the strings,i will be very thankful to you,
please send me conbo list
pri2sh@yahoo.com
plz send me cool tricKs of sql injection…
plz send me the tricks and injection strings. thanks
me too pls send me combo>.<thnks.?ASAp:)
send me something to crack te username and pass
send me the combo pls
pleae send me the way to hack phocomasy site using sql injection
Hey man thx for the list, it’ll definitely help me learn proper sql syntax
dear friend, i like to know about the sql injection strings can u send my a mail about it without fail thank you.
bye..
please, send me, if possible, the combo with de strings you said in the post to: infoinicio AT gmail.com
thanks!
i m interested in the post, please i m very glad if you send me the list to my mail afridikijan@gmail.com thnx
ok send me dear to afridikijan@gmail.com i m waiting
Send Free Messages To Mobile Phones…
Found your blog on yahoo – thanks for the article but i still don’t get it….
for sql injection i m using Paros – need to know more tools
hacking tools…
I can’t believe I missed this! I’m going to have to do some more reading me thinks….
i like to have a strings list also i am using sqlninja you can tell me where i put the strings i sqlninja? o some info about the best way to use it .
I would like to get the list too.
wsht4ever@gmail.com
Ey,
I would like to get the combolist, my e-mail is hansje1842@live.nl
i would be interested in this ‘combo list’ of sql injection strings. please send as soon as availabe. happy hacking!! ^_^
i would be interested in this ‘combo list’ of sql injection strings. please send as soon as availabe. happy hacking!! ^_^
– dont know if you need me to send email in the actual comment, but just in case its binaryhavoc@gmail.com
thanks
hi send me any documentation related to “Analysis of Sql Injection Prevention Methods”
and send the list of codes u have. urgent please
jackthbean -at- gmail -dot- com COMBO LIST
plz send me the combolist
itsfall [at] gmail [dot] com
thx very much!!
pls send my the combo list
and1990ff@yahoo.it
thz
phoenix011y@yahoo.com thx.
Would like to see list.
-Robert
pls meanttopwn@hotmail.co.uk thx
I would like to see too. decini@gmail.com
-R
x-factor_x@live.com – combo list please
thx
me too plz
combo list please
Hi, man! Please mail me the list. Thanks in advance!
please send the list of SQL injection and tell me how to mdetect vulnerability.
i want that list plz send me
email is bhaveekkool@gmail.com
idontlovesyou@hotmail.com
Combo List please
combo list
would like to see list
palmier56@gmail.com
I would like to see the combo list but also need your help in removing a page from a website because it is slandering someone close to me. Please tell me you can help me… Freed1114@yahoo.com
combo list pls. thnx ^^
Hy,
Can you send the list in my mail?
Thank´s
I have read ur article, its too interesting. please send me the injection strings which you didn’t post in ur blog. I’m interested in combo list, thx
Please send me the injection strings too; it would be very much appreciated.
Bonjour.
Cela serait très bein si vous pourriez me faire parvenir les cordes : metamorph-x@live.fr
Merci beaucoup.
good day…
ima noob and would like to see the combo list…please send….theoriginalwhiteboy@hotmail.com….thank u…
Can you please send me the combo list at tropez_jr@yahoo.com…
Thank you
Please send the list. THANKS
send to me here
this is pretty good wer one can increase his knowledge in the sense of prevention of his site
keym6@yahoo.com
can upls send me ur combo list of sql 101 injections and remote sql injections codes pls
pls send it to my email
robotkaba13@gmail.com
tnx
send it pls robotkaba13@gmail.com tnx
For me too, please tomuxaz at gmail.com
send me the combo please.. acoustic_player@live.com
Hi my dear friend,
Please can u send me the sql injections strings on my email
(jad_aizarani@hotmail.com)
Thank You Very much
and for your hard works that payed off…
Amazing
Hi just wanted to say thanks for your article i thaught it was superb. Please send me the strings you mentioned and keep up the good work.
Send me please … capunk85@gmail.com
PLEASE…..PLEASE…..
Please send me the list of sql injection strings. Thank you in advance.
plz send me ths tips n thanxxxxxxxx
Hey thank you, I would appreciate if you send to:
berti_5_1@hotmail.com
send me the combo list
pls send me combo list, auto26@inmail.sk
thanks,
Pls send me the combo list thx!!
please send me the list of the strings..thanks….my email is carlo_samanta@yahoo.com
Send me please
I have read ur article, its too interesting. please send me the injection strings. I’m interested in combo list, thx
Pls, I will like the list of all the injection strings so that i can hack my way out of Mobile operators database
Your the boss.ive been searching a couple of months about this sql injection tactics..please send me the sql injection codes to my email wyvern@ymail.com I highly appreciated for this.Thank you buddy..!
pls send…thnx
iangompers@yahoo.com Combo List Please
hi i will be glade if u pls reply at ur earliest
I have searched this topic for a month. I’m glad I found this website. Please, send me the combo list. thanks
hello,i’m so happy to discover dis post and thread.
pls send me d combo list.
my e-mail is doubleakins@yahoo.com
thanks.
pls u can also send me a brief tutorial on aw to go about it and give me a list of vulnerable site to toss around wit.
pls reply asap.
thanks!
Thanx for the info.
Plz mail me the combo list.
aabhaas.singhal@gmail.com
plz mail me the combo list
any tricks related to sql
[Original Post]
There are lot of other variations of the Injection String which I cannot put on my blog because that is Illegal. If you are interested I can send it to you through Email. Just write in your email address in comment and I will send it to you as early as possible but you need to remain patient it may take 1 or 2 days.
Please Send it to me on simplysanjeev@in.com as m securing my website on MySql.
Cheers
please send me the combo list; jfranklin77@yahoo.com…ty
thx a lot for the combolist!
Pls send me the combo list thx!!
atifbs@hotmail.com
fayizk1@yahoo.com – Combo List.
Please send the combo list. Thanks
atsutiet ludzu combo sarakstu uz kalviss_@tvnet.lv
hai iam very much intrested in hacking but idont know the path if you can please teach me the path plz send me a mail
thanking you
jackson kane
tlmgeox_13@yahoo.com – combo list
hi hacker i need those strings pls to hack any website
i need the combo list
yepp_its_faith@rocketmail.com
combo list plz
coolestme007@gmail.com
it wd be great if u cd send the list
HI, i beleave i have mosT of it, buT i’m not sure if i have all of iT, so kindly send me ThRough my email, it will Really help me gain more knowledge.
Cheers
Could u plz send me the string list?
The_prince_m@yahoo.com
Thanks..
Bonjour , j’aimerais avoir la liste plz
Please send the lists kueyiar@hotmail.com
wow nice topic dudes? Ur d man?interesting cn u send me the detail about sql injection string tnx_ jeff_sonic13@yahoo.com _kip on rockin!
hey dude send what you can. Im trying to get into one of those essays sites and dont really want to pay for a paper and would rather see the whole thing to assist me in building a stronger essay for my class. thx! cam_sim1@yahoo.com
combo list pls
send it to me please.
thanx in Advance
plz send me the list
pour la liste, merci malinois44@hotmail.fr
please send me the combo list too, thanks
Please email your list, thank you in advance!
pplease send me combo list thansk alot
hee stuur mij aub die lijst als je wilt
imad-007@live.nl
Please send me the combo list. Thank you.
Please send me the combo list to my email id……..thnx in advance
i like it..
,,thAnkz and i’ve seen this site cAn you please send me the c0mbo list at spabok14@yuurok.com thanks a l0t and keep hAcking,hAcK rulez!!
plz send me those combo list…thanks in advance
please send me the injection strings you are talking about i’m interested
Hi,
Please send me the injection strings list.
Thanks!
Rubie
hi,
please send me combo list.
thanx
hey just send me a combo list plz…n little bit tutorial abt website hacking…plz
Pls i need other variations of the Injection String…… THANXXXXXXXX
Please send me some variations
Please.
I Would Like to Recieve
Thanks
Please send me the Combo List
Hey there please send combo list on sql injection strings to:
scentedway@hotmail.com
thanks in advance
Please send me the strings.
Thanks.
captivatingpiece@hotmail.com
Hi please send me all scripts. Thanks
pls send me all the articles and combo list
thank you
plz send the string list which u r talking about.i am curious to know about it.thank you
micheal_balance@yahoo.com -> Send them to me, I know what u are talking about, but I don`t have the strings, please send.
send the list of sql injection strings to liatopia@hotmail.com please and thank you!
hi your tutorials are so good i want to have them in details please send me the combat list details
have a great day
see you later/
Hey if you could send me those that would be great.
Please send me the sql injection combo list. Thank you.
noblas.mel@gmail.com
It will be much appreciate if you can send me your latest combo list. Thank you..
Please send me the combo list to franknsteiner@gmail.com
Thank you!
Pls send me the combo list to boitario@gmail.com
plz send me combo list
superlogy@gmail.com
Please send me the combolist as well:
mm859170@gmail.com
Could you plz send me list of all strings, and the link to the program you use to scan the sites to c wot is vonruble or nt.
Cheers
pls mail me the combo list
i nid it plz skizzy5naira@yahoo.com
send me the combo list plz
sambitrath1989@gmail.com
plz send me the combo list
Please send me the combolist as well:
Please send me the sql injection strings i b really interested johnblister@gmail.com
content is very useful and i like have more details Please send me all details of sql injection to pandurangpable@yahoo.com
Hi may I please have da variations of the Injection String list. My e-mail: khule@hotmail.co.uk
Many thanks
mariuszpoziomka@wp.pl please send me a combo list Thanks
Please send me the list as well.
pls send me the combo list
hwy plz do send me
plz mail me the list.
And also some other useful stuff on hacking.
nairs999@gmail.com
Would you care to share some SQL strings with me as well? strictly for educational purposes of course…
letmehackyou@rocketmail.com
Thanks
please send me the combolistand pls explain better on how to use it
good one!!! mail me to sibten.sabuwala@gmail.com
please could you give me the list of strings you have,and combos as well please, many thanks
antony
Please Send list, thanks
Pls friend send me th combo list and also how can i get the Ares software. My email is stguccichima@gmail.com
Hi i would appreciate those strings thnx- dkwaterman@aol.com
Combo List please: lacfadio@gmail.com
please send me the combo list
Hi buddy great blog..
Send me the Combo List and info regarding the Latest Hacking Tools..
My ID is ashubhatt_1992@yahoo.com
Happy hacking….
list please? Rock On!
I need the combo list thanks
I need the combo list pls
thanks
fenat09@yahoo.com
The combo list of sql injection strings.
Hi Mate,
Great Stuff..
Can u please send me the combo list..
thnks..
killsecurity2009@gmail.com
nimoom@live.com please send me the combo list
Combo List..kilme@windowslive.com
Hey man… Pls send the COMBO LIST… thanx.
Hey man i need everything that you have your site is very much useful and fill with too many interesting things to learn, you’re wizzzzzzzz.
combo list please
kurtosis12@gmail.com
Dear,
Your site is very useful,100% usefull topics.Thanks alot for all these tips.If u dont mind,would u please sent me the other variations of the Injection String please(combo list).TC
please send me all hack tricks to my email id
plz send me too…
i need the combo list and strings pls. cyphs.exploits@gmail.com
please send me the combo list
i need the combo list and strings & all new information related with SQL injection pls.
My mail Id – bhuking@gmail.com
hallo
please send me the injection strings you are talking about i’m interested
……………..
to my e mail id
pankajkar.2007@gmail.com
i am waiting for ur reply
thanks
please send me the injection strings you are talking about i’m interested ,
cocacolaman93@hotmail.com just send me some variations of injection strings to that email.
Please send the Injection String to me..I hope u can send it to me as soon as posible..TQ..
Please send ‘u know what’ on 10.tanay@gmail.com
Hey man im interested in the list and the program witch u have said. My Email is patrickda3@hotmail.com I hope to hear from you.
pls send me any website and username and password that can show email and password pls am waiting for ur reply ASAP.
please combo list plmut77@hotmail.com thanks..
Send me list on my mail…Thanks !
Hi, can you send me the combo list via email? Thanks a lot!
can you send me them please, my email is blakek91@ymail.com
Hey bro i need the stuff
hello friend………
ur job was awsome. i dealt with yahoo or messenger hacks and so on using phising and trojans . i had not tried this sql injection . so i just want to try this. could u plzz send me these strings.. and is there any strings for rapidshare ,..?
amritsari_dude@yahoo.in this is my id plz send me that list.
i had a question that does it work on any site of my choice?
hi i have verious list you give me your combo list i can send my list bye
happy hacking
$ђдĐΘΨ Θƒ ĐΛЯҜЙξ$$
can you please mail me the combo list and string list…….
hey man!!
I want it!!
please sent it to my e-mail.
dudecrawling@yahoo.com
engenius@me.com send it to me please
combo list michaelkong16@gmail.com
plz send it me….. at kranthikumar.1245@gmail.com
combo list please
thanks,
me 2,i am looking forward to see the list , u have my email
plz send
Please send me the list.
You are having my id
Combo list please.
Awesome info, dood
Great article!
Please include me in the recipients of your combo list
[...] List of all the SQL Injection Strings [...]
sskamalavelan@gmail.com
I would like the secret "list"
i want a list too
sskamalavelan@gmail.com
pls send me too
hlwwwww dude i am intrested in sql injecting
plz send me combo list and other similar tutorials.
email address is aadi4aadeez@yahoo.com
Id like it as well. Thank you!
please send me the combo list. . .thanks! here’s my email : bruce_steven1880@yahoo.com
Please send me the injection strings too; it would be very much appreciated. And if you know anything else i can use for hacking emails,sites,and accounts please let me know
send me combo list dineshkaushik18@gmail.com
it looks good…can i have it,please…(combo list)
here’s my email
bobby_fz@operamail.com
thanks…
plz send me at bgohel9@yahoo.com
please send me the list of login/pass I want these info…
I wont be using it for the bad purpose. I know the ethics of hacking…
pls mail me the sql injection strings list
at
arpit07531@gmail.com
i also want to see the combo list. i have a subject about security in uni.hope it can help me much..
my email : muahaha_kui2@hotmail.com
Hi….
Please help me to hack gmail accounts. Thanks.
My id: linbladez@gmail.com
I like ur sql injection. pls mail me
send me the list please? Please tell me what to do if you can’t find admin\login.asp for a specific website?
email me at tonyrobertcook@msn.com
I want the combo list.
jessicaminervini@gmail.com
Thank you.
plz send me combo at :- knlpratap@gmail.com
thank
Can i get those combo list..send it to my email…interesting to have it..and if possible, please teach me about these matter.because i am the freshie for this one..Thank you
Hope to hear from you about the combo list and it is my pleasure if u send it to my email at hackingnerdsystem@gmail.com..Please teach me about how to use this combo a little bit because i am freshie for these things..Thanks folks
please send me the combo list. . .thanks! here’s my email :
adalenesilva@hotmail.com
hi dude…please send me the sql strings and tricks
pls send me d combo list.
my e-mail is banhnhantao@yahoo.com
thanks.
o hai :O
i’d love you forever if you sent me the other injection strings! thanks <3
alert(‘lol’)
please send me the strings too…….i’m interested…..williamsdipman@yahoo.com
I’d love to have that list please. Thanks in advance!
hiiiiiii plz send me combo list my email id is-
28.dheeraj@gmail.com
any body got this list please share
))))))
please send me
1.) sql injection strings and tricks,,
and also the
2.) combo list..thanks..
and also
3.) the procedure
thanks in advance
plz send me combo list my email id is- yomanabhi@gmail.com
pls Send me strings
plz…send me too..@. lost-shadows@live.com
plz send me the list
I need your combo list. Thanks a lot.
Can u please send me also …
Please send me the combo list to afosul@live.com or better still sell to me usa shop admin with at least 10 shopers per day.
hi, send me the combo pls, thanks
PLz send me that combo list if possible.
my email id is keval.desai@yahoo.com
Hi
Please send me the list of the sql scripts, want to look if they are different from what I use.
Thanks
Arun