client9 / libinjection

SQL / SQLI tokenizer parser analyzer
Other
1k stars 274 forks source link

False negative #148

Open dune73 opened 5 years ago

dune73 commented 5 years ago

The following payload is not detected by libinject (via ModSecurity 2.9.3).

a=SELECT-id-1.FROM`test`

(Based on tweet https://twitter.com/brutelogic/status/1189184204073885697)