From charlesreid1

No edit summary
Line 34: Line 34:
Lab 3: SQL injection UNION attack, determining the number of columns returned by the query
Lab 3: SQL injection UNION attack, determining the number of columns returned by the query
* https://portswigger.net/web-security/sql-injection/union-attacks/lab-determine-number-of-columns
* https://portswigger.net/web-security/sql-injection/union-attacks/lab-determine-number-of-columns
* https://www.youtube.com/watch?v=umXGHbEyW5I
* this page covers a ton of information: [[SQL Injection/UNION Attack]]
*
 
Lab 4: SQL injection UNION attack, finding a column containing text
* https://portswigger.net/web-security/sql-injection/union-attacks/lab-find-column-containing-text
* https://www.youtube.com/watch?v=SGBTC5D7DTs
 
Lab 5: SQL injection UNION attack, retrieving data from other tables
* https://portswigger.net/web-security/sql-injection/union-attacks/lab-retrieve-data-from-other-tables
* https://www.youtube.com/watch?v=6Dsj5SqR944
 
Lab 6: SQL injection UNION attack, retrieving multiple values in a single column
* https://portswigger.net/web-security/sql-injection/union-attacks/lab-retrieve-multiple-values-in-single-column
* https://www.youtube.com/watch?v=yRVYoqR9vrI

Revision as of 16:31, 21 May 2023

This page covers how to perform SQL injection attacks with Burp Suite.

Burp Suite Training

SQL Injection Labs

https://portswigger.net/web-security/sql-injection

Lab 1: SQL injection vulnerability in WHERE clause allowing retrieval of hidden data


Lab 2: SQL injection vulnerability allowing login bypass

SQL Injection UNION Attacks

https://portswigger.net/web-security/sql-injection/union-attacks

Lab 3: SQL injection UNION attack, determining the number of columns returned by the query

Lab 4: SQL injection UNION attack, finding a column containing text

Lab 5: SQL injection UNION attack, retrieving data from other tables

Lab 6: SQL injection UNION attack, retrieving multiple values in a single column