select a,b,null,null from table1 union select null,null,c,d from table2 union select null,null,null,null,e,f from table3.
Then in the second table I have select ..., null as opt from... I know that I could have an empty string with '' as opt however, I
Number of null-s on change between passed and failed queries is the one attacker looks for.
Union select null, null, null, null, null, null, null from information_schema.tables. for a small database containing three tables. this instruction is used in sql injection I tried it and it worked but I didn't really know how it...
Note: A NULL value is different from a zero value or a field that contains spaces. A field with a NULL value is one that has been left
Null values can be used as a condition in the WHERE and HAVING clauses. For example, a WHERE clause can specify a column that, for some rows, contains a null value. A basic comparison predicate using a column that contains null values does not select a row that has a null value for the column.
The null character (also null terminator or null byte) is a control character with the value zero. It is present in many character sets, including ISO/IEC 646 (or ASCII), the C0 control code, the Universal Coded Character Set (or Unicode), and EBCDIC.
NULL is special in SQL. NULL indicates that the data is unknown, inapplicable or even does not exist.
Nulls can appear in columns of any datatype that are not restricted by NOT NULL or PRIMARY KEY integrity constraints.