How To Hunt For Injection Vulnerabilities' OR 1='1
ID: a77b55d9-ba20-5289-ab47-4bbb114c2e34
STIX ID: report--a77b55d9-ba20-5289-ab47-4bbb114c2e34
Feed Name: HackerOne Blog
This blog post demonstrates SQL injection techniques against a vulnerable PHP/MySQL "Names API" example: it shows how supplying crafted id parameters (boolean conditions, UNION SELECT, and subqueries) can change query logic and exfiltrate a secret IP address, and discusses potential escalation to file writes, remote code execution, and JavaScript injection. The article is educational, aimed at testers and bug-bounty participants, and includes guidance and references for further exploitation techniques and responsible reporting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
