SQL注入fuzz字典

复制代码
length 
Length
+ handler like
LiKe
select
SeleCT
sleep
SLEEp database
DATABASe delete having or
oR
as
As
-~ BENCHMARK limit
LimIt left
Left
select
SELECT
insert
insERT
INSERT right #
--+ INFORMATION -- ; ! % + xor <> ( > < ) . ^ = AND
ANd BY
By CAST COLUMN
COlumn COUNT
Count CREATE END
case '1'='1 when admin' " length + REVERSE ascii
ASSIC
ASSic
select database left right union
UNIon
UNION
" & && || oorr / // //* */* /**/ anandd GROUP HAVING IF INTO JOIN LEAVE LEFT LEVEL sleep LIKE NAMES NEXT NULL OF ON | infromation_schema user OR ORDER ORD SCHEMA SELECT SET TABLE THEN UNION UPDATE USER USING VALUE VALUES WHEN WHERE ADD AND prepare set update delete drop inset CAST COLUMN CONCAT GROUP_CONCAT group_concat CREATE DATABASE DATABASES alter DELETE DROP floor rand() information_schema.tables TABLE_SCHEMA %df concat_ws() concat LIMIT ORD ON extractvalue order CAST() by ORDER OUTFILE RENAME REPLACE SCHEMA SELECT SET updatexml SHOW SQL TABLE THEN TRUE instr benchmark format bin substring ord UPDATE VALUES VARCHAR VERSION WHEN WHERE /* ` , users %0a
%0A %0b mid for BEFORE REGEXP RLIKE in sys schemma SEPARATOR XOR CURSOR FLOOR sys.schema_table_statistics_with_buffer INFILE count %0c from %0d %a0 = @ else
%27
%23
%22
%20

复制代码

配合burpsuite使用,已经算是比较全的了

posted @   链宁区块链安全服务  阅读(1818)  评论(0编辑  收藏  举报
编辑推荐:
· AI与.NET技术实操系列:基于图像分类模型对图像进行分类
· go语言实现终端里的倒计时
· 如何编写易于单元测试的代码
· 10年+ .NET Coder 心语,封装的思维:从隐藏、稳定开始理解其本质意义
· .NET Core 中如何实现缓存的预热?
阅读排行:
· 分享一个免费、快速、无限量使用的满血 DeepSeek R1 模型,支持深度思考和联网搜索!
· 基于 Docker 搭建 FRP 内网穿透开源项目(很简单哒)
· ollama系列01:轻松3步本地部署deepseek,普通电脑可用
· 25岁的心里话
· 按钮权限的设计及实现
点击右上角即可分享
微信分享提示