Vulnerability field guide
SQL Injection
SQL injection is still one of the most damaging web vulnerabilities. Here is how it actually works, what an attacker can do with it, and the one fix that reliably stops it.
8 articles 36 min total Overview to advanced techniques
SQL Injection techniques
7 focused deep-dives
- 02 Boolean-Based BlindBoolean-Based Blind SQL Injection: Extracting Data One Bit at a Time
- 03 Error-BasedError-Based SQL Injection: Turning Database Errors Into Data
- 04 Out-of-BandOut-of-Band SQL Injection: Confirming a Blind Flaw Through DNS
- 05 Second-OrderSecond-Order SQL Injection: When Stored Input Detonates Later
- 06 Stacked QueriesStacked Queries: Running Multiple Statements Through One Injection
- 07 Time-Based BlindTime-Based Blind SQL Injection: Reading a Database Through the Clock
- 08 UNION-BasedUNION-Based SQL Injection: Appending Your Own Result Set