96
JohanO
8y

About to order my personalized registration plate - no more toll fee's for me (I hope) :-)

Comments
  • 7
  • 0
    @ktopolski haha, did you get any comments from the 'authorities'?
  • 1
    @JohanO Was not my idea nor my car, but this picture became famous in Poland as perfect example of useful SQLi :D. I don't think it worked though :)
  • 1
    Someone please explain
  • 1
    @620hun you should read basics of sql injection
  • 0
    @620hun lookup SQL injection.
  • 0
    @boomi @xydac I'm familiar with the concept, but what does this actually do? I tried to Google it, but no luck.
  • 1
    @620hun I think it drops the table but all I know it makes it so the table entry will not be usefull
  • 0
    yeah, actually I wanted it to be 'AND 0;-- .. but one is limited to 8chars - hard to form a legal sql statement under those conditions ;-)

    Of course one could do ';-- but then everyone thinks its some kinda weird smiley...
  • 1
    @JohanO but "or 0" does nothing at all. "or 1" might get you somewhere.
  • 0
    @elazar I know. the point was that I didnt want my number to be 'inserted' so basically ';-- would do (regno would not be found) - I just added OR 0 for looks ;-)
  • 8
    guys itz just a rant not a GitHub issues page 😂😁😀
  • 4
    @elazar actually 'OR 1' is more interesting, then it would insert the first 'random' record it finds...or perhaps _all_ records ;-)

    Interesting scenario for them to debug when _all_ cars in sweden passed through the same toll booth at the exact same time ;-)
  • 3
    *finds $1500 fine in the post... for the first time in your life your truley upset someone used bound parameters :P
Add Comment