Nick Galbreath
Nick Galbreath
hard to know what to do here since it's not clear what exactly clear akamai is using.. Keeping open in case other details come in.
@zimmerle can I transfer this repo to you or someone you can properly maintain it. @invd great work.
sorry, I don't really know what do here. I hope someone else can help with the python swig bindings!
Hello! thanks for writing it. I'd would love a test case before commenting further (and of course a Pull Request!).
- [x] `‘-sqlite_version() UNION SELECT password FROM users- --` - [x] `1337) INTO OUTFILE ‘xxx’--` - [x] `123);DROP TABLE users--` - [x] `) OR (SELECT password FROM users ...` These...
I'll take a look and see if I can find some quick wins here.
Going to revisit this... some are definitely doable.
These 3 are now detected correctly ``` id having (1 or 1) id having (1 or true) id having (true or 1) ```
Hello @attackercan Oh no problem.. I heard there was a talk at BH. Too bad we didn't meet up. A SQL Fuzzer? Fantastic! I've been waiting for someone to write...
https://twitter.com/NGalbreath/status/766294673837006848