Collected research
SQLi filter evasion cheat sheet (MySQL)
A reference sheet distilled from three years of evading PHPIDS, presented at CONFidence 2.0. It collects MySQL syntax that survives filters: comment and whitespace variants, quoteless strings, backtick aliases, typecasting tricks, strings and integers built from gadgets such as pi(), version() and collation(), and rewrites that drop OR, UNION, LIMIT, WHERE and SELECT in turn.
Record
- Published by
- Reiners' Weblog
- Date
- Topic
- Injection
In the archive
Related sources
- SQL Injection Filter Evasion Whitepaper
Tags
This page is the archive's own catalogue record. The research is the work of Reiners' Weblog, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .