client9 / libinjection

SQL / SQLI tokenizer parser analyzer
Other
1k stars 274 forks source link

False positive with legitimate data #137

Open Jyotsna27 opened 6 years ago

Jyotsna27 commented 6 years ago

We are using Libinjection for false positive detection, and we see below legitimate data is considered as malicious by Libinjection. Can you please help me understand why it is considered as malicious. We are using || as a delimiter. 12345=12345||12345 12345||12345||12345 12345+12345||12345