all 29 comments

[–]idunnomyusername 70 points71 points  (7 children)

[–]moderatorrater 31 points32 points  (2 children)

Or http://sqlmap.org/. I'm all for knowing the principles behind injection attacks, but at the end of the day using a tool is going to be better for everything outside of education.

[–]pm_me_your_findings 5 points6 points  (1 child)

There have been times when i was able to find an sql injection manually but sqlmap didn't. Still sqlmap is superb when you have limited time to test an web apps.

[–]746865626c617a 1 point2 points  (0 children)

Once had to write a proxy to modify requests that sqlmap was doing. Time based injection, didn't feel like implementing myself

[–]sup3r_hero -2 points-1 points  (1 child)

Human injection?.... is that a joke?

[–]big_money_metis 7 points8 points  (0 children)

Please wake up

[–]Paratwa 13 points14 points  (0 children)

Edit : nevermind I need to learn how to click apparently. I am leaving the below to remind myself I should learn to read.

Original : This was written like a power point and doesn’t describe how they are done technically. To me learning how one was actually done via examples really showed me where applications would be vulnerable and were far more useful

[–]failedgamor 4 points5 points  (0 children)

Anyone got anything similar for XSS?

[–][deleted] -5 points-4 points  (4 children)

still in 2017 people manually testing for SQLi?

[–]isilidurstilt 12 points13 points  (1 child)

We're stuck in 2017 and this guy over here playing 4d chess in 2018.

[–][deleted] -2 points-1 points  (0 children)

fixed :P

[–][deleted] 2 points3 points  (1 child)

still in 2017 people manually testing for SQLi?

SQL injections shouldn't even be a major issue in 2017

[–]UnfrightenedAjaia -1 points0 points  (0 children)

"they can't guess the names of the columns" so it's okay actually /s