1. inurl -.com.my index.php id
  2. inurl -.com.my index.php id

Inurl -.com.my Index.php Id -

Never trust user input. If id is supposed to be a number, cast it to an integer:

$id = (int) $_GET['id'];

/index.php?id=123' WAITFOR DELAY '00:00:05'-- inurl -.com.my index.php id

Note: A cleaner, more effective version of this dork would be: inurl:index.php?id inurl:.com.my (to specifically hunt within Malaysian commercial sites). The inclusion of the minus sign suggests the user wants to avoid false positives or has a specific reconnaissance target. Never trust user input

If you are a website owner and you recognize your site in a search like inurl -.com.my index.php id, do not panic. Take immediate action. /index

bluenote by BBB