← Intel
Oct 5, 2026 · HackerOnStreet

How I found 5 Sql injection using 3 tools

HI No time for Hello! i was seeing in my office today i was working from home then i decide that i need to go office. i was working on one… How I found 5 Sql injection using 3 tools HI No time for Hello! i was seeing in my office

found sqlfound sql injectionfoundsqlinjectiontoolsnmapreasonscansqlmapattackbatter
How I found 5 Sql injection  using 3 tools

Quick overview

FieldDetail
Topicmuch
GuideHow I found 5 Sql injection using 3 tools
Tagsmuch, nmap, time, reason, scan, sql
LengthAbout 713 words
Practice ruleAuthorized labs only — stay ethical

HI No time for Hello! i was seeing in my office today i was working from home then i decide that i need to go office. i was working on one…


How I found 5 Sql injection using 3 tools

HI No time for Hello! i was seeing in my office today i was working from home then i decide that i need to go office. i was working on one issue then i think fro while lets make some mess.

The reason i write this artical i think its time to-tell you how can we go up with time i have been using my own scripts and tools since long time. some of the simple i provide you in previous lecture.

In this one I am not going to tell you show to in video reason there was alot of other things that i foud. using some automation testing tools. as you all know that teach You with basic level testing that is much much batter then others peapols who make you fool in YouTube Videos .

For this attack i use 3 tools for

  • Nmap
  • OSZAP (ZX Proxy )
  • SQLmap

OSZAP:

OSZAP has 2 major role in this Testing. i just just fro scanning how ever i use Zap in Window i will work batter. reason its work in batter way. may be You are good in other OS ..

For Scanning its was not much bad but i scan in deep with OSZAP with Ajax Spider including Attack mood

The page results were successfully manipulated using the boolean conditions [da1f9ce0bd5544c7cab987682f11f100cf0428d807d72b1cf40f4c5ff949c367" AND "1"="1" -- ] and [da1f9ce0bd5544c7cab987682f11f100cf0428d807d72b1cf40f4c5ff949c367" OR "1"="1" -- ]
The parameter value being modified was stripped from the HTML output for the purposes of the comparison
Data was NOT returned for the original parameter.
The vulnerability was detected by successfully retrieving more data than originally returned, by manipulating the parameter

After Scannign i get some more information that was a

da1f9ce0bd5544c7cab987682f11f100cf0428d807d72b1cf40f4c5ff949c367" AND "1"="1"

Nmap:

Nmap was the tool who allow me to find right Target for my Self . with this small command that look small has so much Power that can filter the list of IP. i was on target

When you scan with this Command with nmap Please before -iR ~ give the rang ip .

 nmap -v -iR .x.x.x.x..x.x 

In My Case i give the Rang That was Like nmap -v -iR 100 X.X.X..X.X.X. so how i know my target for sql injection. i was not ready for this bug i search for big origination IP List For example Microsoft is component who is using Someone eles host by 3ed Party

if you don't khow how example Yelp don't have its own Data Center . they are using OKla hosting who offer them data protection .

Sqlmap :

SqlMap is python based tool that allow you to scan issue in batter was. i will say that don't trust on sql injection more reason its slow in my case i have another Tool updated Version of SQL name Guhori.

$ python3 sqlmap.py -u "x.x.x..x.x.x..x.com/login" --batch --ra
nandom-agent --level=5 --risk=3 --dump --method POST --batch

i use this information with Sqlmap

da1f9ce0bd5544c7cab987682f11f100cf0428d807d72b1cf40f4c5ff949c367" AND "1"="1"

but attack a lot time for scanning and Testings

This is one of the reason that’s why I prefer to scan the largest level internet IP scanning system. But if you want to get a better result as a mention the bigger company that has a bigger client definitely has much much bigger security issues.

And here is a things started definitely if your issues are much bigger than that you need to find a better way in this case the website I scan it was a multi million dollar industry but there was not offering appointy but there was offering Hall of Fame and I was not interested the power it I decided to sell this bug 🪲.

To third party like I mention what I do with his all things if you don’t know what I do with these things you should check my previous article that will help you to understand how .I become a Redhat .

thank you so Much i will put video also and next video i will tell You in Live session

Frequently asked questions

What is this guide about much?

How I found 5 Sql injection using 3 tools explains practical, ethical notes on much. Use it as a structured walkthrough — then practice only in authorized labs.

Who is this much article for?

Readers who want clear, street-level guidance on much without hype. Beginners and intermediate practitioners both benefit.

How do I practice much safely?

Stay in scope: systems you own or have written permission to test. Keep notes, verify findings, and never attack live targets without authorization.