Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
gskourou
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
3 ms
·
1.
▲
My SQLi adventure or: why you should make sure your WAF is configured properly
(astrocamel.com)
5 points
by
gskourou
5y ago
|
3 comments
2.
▲
by
gskourou
6y ago
amen
3.
▲
by
gskourou
6y ago
I have also seen backend application which strip out certain "bad" tags (i.e. <script>). I remember being able to perform an XSS attack by sending a payload that looked like: <sc<script>ript>alert(/XSS/
4.
▲
by
gskourou
6y ago
I am not sure if parametrized statements solve 100% of your SQLi problems, but I know they at least offer basic protection. I have to study them in order to give you a complete answer, but I found this https://stackoverflow.com&#
5.
▲
How I bypassed Cloudflare's SQL Injection filter
(astrocamel.com)
235 points
by
gskourou
6y ago
|
101 comments