By using this site, you agree to our Privacy Policy and our Terms of Use. Close

ok, so for more detail.

Basically they put their SQL queries as a parameter in the HTML code.

Example: If you look at the address for this page it has "..../thread.php?id=23892". The id is the parameter and the value is after the =. However, ioi never let's you see what SQL queries he is actually running so you don't know the design of the database or how to immediately create usable SQL injections. On the OK site, it showed the entire sql query. Anyone with basic SQL knowledge could create their own queries and it would return the results. So a quick query to ALL_TABLES would return you a list of the table design. Then using that with ALL_TAB_COLS would allow you to build any query you want to gain any information that was available.