> For the complete documentation index, see [llms.txt](https://meitoka.gitbook.io/stash/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://meitoka.gitbook.io/stash/learning/sqli/sqli-warning.md).

# SQLi warning

Using <mark style="color:red;">`OR 1=1`</mark> in SQL injections is **risky** and should rarely be used in real-world engagements. It loads all rows of the table, which may not bypass the login if only one row is expected. This can also cause database performance issues.

As an alternative, consider using <mark style="color:red;">`AND 1=1`</mark> with a valid input (such as a legitimate username) to test or confirm SQL injection vulnerabilities.

**Example:**

1. Detect a potential <mark style="color:red;">`Error message`</mark> after a failed login (doesn’t respect OWASP Guidelines).
2. Using the error to brute force the <mark style="color:red;">`username`</mark> field with Hydra
3. Get a legitimate username
4. Do a SQLi like: <mark style="color:red;">`user' AND '1'='1'-- -`</mark>
5. Bingo!!
