ORACLE SQL Injection Notes In ORACLE you can not just SELECT stuff you have to SELECT them from some table. For this purpose you can use special table called DUAL. i.e. SELECT 'dummydata' || 'x' FROM DUAL; You have to close comments if you used /* comment */ style comments Concatenation SELECT utl_raw.concat('x','y') FROM DUAL; SELECT 'x' || 'y' FROM DUAL; SELECT 'a' || 'b' FROM DUAL; SELECT use..