✨
AppSec & Pentest
search
⌘Ctrlk
✨
AppSec & Pentest
  • AppSec Book
  • Intro
  • PII: Персональные данные
  • Поисковые движки
  • Построение модели угроз / анализ угроз
  • Платформы оркестрации, автоматизации пентеста
  • Audit and Compliance
  • Methodologies
  • peoples & blogs
  • Базы уязвимостей
  • Pentest IDE
  • Payloads & Wordlists
    • Генерация wordlists
    • Payloads
    • Расширения файлов, которые можно искать
    • Bypass Something
  • AppSec / WEB
    • Common
    • Automated WebApp Pentest
    • Server-Side Vulnerabilities
      • Broken Access Control
      • Bruteforce [credentials]
      • Business Logic Vuln
      • CSV-injection
      • DOS
      • DDOS
      • Dependency Confusion Attack
      • Deserialization
      • Host Header Injection
      • HTTP Smuggling
      • IDOR
      • JSON Hijacking
      • LFI
      • LFR
      • Open Redirect
      • OS Command Injection
      • Path Traversal
      • Phishing
      • Race Condition
      • Regular Expression
      • Reverse Shell
      • Searching
      • Session Fixation
      • SQLi
        • Description
        • Databases
          • HQL inj
          • DQL inj
          • postgres
          • Yandex ClickHouse
        • Exec Code
        • Tools
        • Papers
      • SSRF
      • SSTI/CSTI
      • Subdomain Takeover
      • Upload File
      • XML/SOAP injection/XXE
      • Web Cache Deception
      • Web Cache Poising
    • Client-Side Vulnerabilities
    • Technics
    • SSDLC
    • DevSecOps
    • Browser PWN
    • Вопросы
    • ЯП
    • Books & Papers
    • Tools
  • Technologies
    • WEB
    • Покупка SIM-карт и номеров
    • Banks & Payments
    • Программы лояльности
    • Digital Rights Management (DRM)
    • ELK — Elasticsearch, Logstash, Kibana
    • 1C
    • CI/CD
    • SCM
    • Honeypots
    • ChatGPT
  • Learning
    • Компетенции
    • Материалы SANS & Offensive Security
    • Просто норм материалы/gitbooks по пентесту вцелом...
    • Platforms & Playground Labs
    • Бумажная ИБ
  • Bug Bounty
    • Notes
    • Browser Plugins
    • Cheat Sheets
    • Платформы
    • Specific tools
  • Hardware/IoT
    • Tools
    • Training
    • Papers & Books
gitbookPowered by GitBook
block-quoteOn this pagechevron-down
  1. AppSec / WEBchevron-right
  2. Server-Side Vulnerabilitieschevron-right
  3. SQLichevron-right
  4. Databases

HQL inj

Про HQL inj https://habr.com/ru/company/parallels/blog/272589/arrow-up-right https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/hql-injection-exploitation-in-mysql/arrow-up-right

PreviousDatabaseschevron-leftNextDQL injchevron-right

Last updated 5 years ago