Collected research
Blind SQL Injection without an "in"
Blind SQL Injection without an “in”
A blind MySQL injection worked under a filter banning UNION SELECT, information_schema and any word containing in or or. Table names come from sys.x$schema_flattened_keys and sys.schema_table_statistics, row-vs-row comparison leaks data without knowing column names, and CONCAT with CAST(0 AS JSON) forces a case-sensitive byte comparison.
Record
- Document
- Blind SQL Injection without an “in”
- Researcher
- terjanq and @terjanq
- Published by
- Medium
- Date
- Topic
- Injection
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of terjanq and @terjanq, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .