Advanced SQLi
Interacting with PostgreSQL
Decompiling Java Archives
Fernflower
mkdir <OutputDirectory>
java -jar Fernflower.jar <Application>.jar <OutputDirectory>
cd <OutputDirectory>
jar -xf <Application>.jarJD-GUI
Regex Patterns for Finding SQLi Vulnerabilities
SELECT|UPDATE|DELETE|INSERT|CREATE|ALTER|DROP
(WHERE|VALUES).*?'
(WHERE|VALUES).*" +
.*sql.*"
jdbcTemplateLive Debugging Java Applications
Enabling PostgreSQL Logging
Common Character Bypasses
Error-Based SQL Injection
Reading and Writing Files
Reading with COPY
Reading with Large Objects
Writing with COPY
Writing with Large Objects
Command Execution
RCE with COPY
RCE with Extensions
Defending Against SQL Injection
Last updated