RE: XSS vs SQLi 09-29-2012, 06:43 PM
#11
XSS is easier, SQLi is more powerful. none of those are my faves though. I love arbitrary uploads and misconfigurations and when I'm bored I like to get oldschool and try to exploit software (not webapps obviously) with buffer overflows (that's pretty damn hard, but it's great for learning more in-depth stuff about how your computer's memory and processor work).