You are on page 1of 4

SQL

injection
Types of SQL Injection
• Error-Based SQL Injection
• Blind SQL Injection
• Second-Order SQL Injection
• Out-of-Band SQL Injection
Error based SQLi Queries:
SELECT * FROM users
WHERE
username = 'inputted_username’
AND
password = 'inputted_password';

SELECT * FROM users


WHERE
username = ‘-1 or '1'=‘1’ #’ AND password = 'inputted_password';
Blind SQLi Queries:

SELECT * FROM users


WHERE username = 'admin' AND '1' = '1';

SELECT * FROM users


WHERE username = 'admin' AND SLEEP(10);

You might also like