SQL injection UNION attack, retrieving multiple values in a single column | Practitioner
Similar to this lab, our goal is to extract data from the table users, with username and password stored in plaintext.
First, we will need to find out how many columns does the “filter table” contain:
Again, there are two columns which is convenient for us as users also has two columns. What about the data types hold by those two columns?
Unfortunately, not all columns can hold string data which is kinda bad news for us. Though it does return a 500 which means it’s processing our injected query server-side. Let’s find out which of the two columns holds those strings:
So the silver lining is that one column can hold strings. However, users has two values to be fetched, meaning we will have to somehow combine two entries into one. This can be done by string concatenation, whereas username and password will be added together, separated by an unique symbol.
The syntax for string concatenation varies between database types, in this case for Oracle it’s as follow:
'foo'||'bar'
Knowing this, we can inject the following query:
