From 4fd63060206ec9713736ed946e38a9b39f97790d Mon Sep 17 00:00:00 2001 From: Sachin Wagh <86011901+tigertigerboy07@users.noreply.github.com> Date: Tue, 15 Nov 2022 17:33:36 +0530 Subject: [PATCH 1/2] Update sqlserver.html Added String concatenation section for SQL Server --- dbmsIdentification/sqlserver.html | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/dbmsIdentification/sqlserver.html b/dbmsIdentification/sqlserver.html index ff0fa93..8f99e87 100644 --- a/dbmsIdentification/sqlserver.html +++ b/dbmsIdentification/sqlserver.html @@ -18,6 +18,10 @@

DBMS Identification

Default variable page.asp?id=sql'; SELECT @@SERVERNAME -- + + String concatenation + page.php?id='mssql'+'mssql' -- + Error messages
Note: Triggering DB errors through invalid syntax will sometimes return verbose error messages that include the DBMS name. page.asp?id=' From 9f9c17443a83776a16c5575b55960775fa530ef4 Mon Sep 17 00:00:00 2001 From: Sachin Wagh <86011901+tigertigerboy07@users.noreply.github.com> Date: Tue, 15 Nov 2022 17:56:21 +0530 Subject: [PATCH 2/2] Update sqlserver.html Added SQL Server functions --- dbmsIdentification/sqlserver.html | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/dbmsIdentification/sqlserver.html b/dbmsIdentification/sqlserver.html index 8f99e87..5bb7655 100644 --- a/dbmsIdentification/sqlserver.html +++ b/dbmsIdentification/sqlserver.html @@ -22,6 +22,12 @@

DBMS Identification

String concatenation page.php?id='mssql'+'mssql' -- + + Functions + @@rowcount --
+ SQUARE(1) --
+ @@pack_received -- + Error messages
Note: Triggering DB errors through invalid syntax will sometimes return verbose error messages that include the DBMS name. page.asp?id='