From charlesreid1

No edit summary
Line 48: Line 48:
* https://portswigger.net/web-security/sql-injection/union-attacks/lab-retrieve-multiple-values-in-single-column
* https://portswigger.net/web-security/sql-injection/union-attacks/lab-retrieve-multiple-values-in-single-column
* guide: https://www.youtube.com/watch?v=yRVYoqR9vrI
* guide: https://www.youtube.com/watch?v=yRVYoqR9vrI
==Examining the Database==
Lab 7: SQL injection attack, querying the database type and version on Oracle
* https://portswigger.net/web-security/sql-injection/examining-the-database/lab-querying-database-version-oracle
Lab 8: SQL injection attack, querying the database type and version on MySQL and Microsoft
* https://portswigger.net/web-security/sql-injection/examining-the-database/lab-querying-database-version-mysql-microsoft
Lab 9: SQL injection attack, listing the database contents on non-Oracle databases
* https://portswigger.net/web-security/sql-injection/examining-the-database/lab-listing-database-contents-non-oracle
Lab 10: SQL injection attack, listing the database contents on Oracle
* https://portswigger.net/web-security/sql-injection/examining-the-database/lab-listing-database-contents-oracle
==Blind SQL Injection==
https://portswigger.net/web-security/sql-injection/blind
==Cheat Sheet==
https://portswigger.net/web-security/sql-injection/cheat-sheet

Revision as of 16:55, 21 May 2023

This page covers how to perform SQL injection attacks with Burp Suite.

Burp Suite Training

SQL Injection Labs

https://portswigger.net/web-security/sql-injection

Lab 1: SQL injection vulnerability in WHERE clause allowing retrieval of hidden data


Lab 2: SQL injection vulnerability allowing login bypass

SQL Injection UNION Attacks

https://portswigger.net/web-security/sql-injection/union-attacks

Lab 3: SQL injection UNION attack, determining the number of columns returned by the query

Lab 4: SQL injection UNION attack, finding a column containing text

Lab 5: SQL injection UNION attack, retrieving data from other tables

Lab 6: SQL injection UNION attack, retrieving multiple values in a single column

Examining the Database

Lab 7: SQL injection attack, querying the database type and version on Oracle

Lab 8: SQL injection attack, querying the database type and version on MySQL and Microsoft

Lab 9: SQL injection attack, listing the database contents on non-Oracle databases

Lab 10: SQL injection attack, listing the database contents on Oracle

Blind SQL Injection

https://portswigger.net/web-security/sql-injection/blind



Cheat Sheet

https://portswigger.net/web-security/sql-injection/cheat-sheet