Bypassing SQL Filters
UNION Filters
Lets say we are testing a login form and it returns an error whenever we try to execute UNION SELECT. This suggest that there is a WAF filtering the queries so we would use Union instead.
You can also use [GROUP_CONCAT] instead of [concat] as it combines entire column in one result.
[union] filter is below:
Notice that the filter prohibits [“UNION”, “INFORMATION_SCHEMA”, and “union”] as characters hence if you modify on the [union] command a bit you can easily bypass it.
Last updated