Kinda important to review
- SQLi cheat sheet: https://portswigger.net/web-security/sql-injection/cheat-sheet
- Remember to URL-encode everything
- Comment out whatever residue at the end
- Join the injected query with semicolon, or
UNION SELECT
Blind SQL injection with out-of-band data exfiltration | Practitioner
Blind SQL injection with time delays and information retrieval | Practitioner
Visible error-based SQL injection | Practitioner
Blind SQL injection with conditional errors | Practitioner
Also quite painful lab, careful with Oracle syntax
Blind SQL injection with conditional responses | Practitioner
Painfully long lab, Python bruteforce script included