In this lab, we are tasked with finding the version of an Oracle database. The query syntax is as follow:

SELECT banner FROM v$version
SELECT version FROM v$instance

First, we will need to find out how many columns there are. One thing about Oracle is that every SELECT must use the FROM keyword and specify a valid table. Since we are probing for NULLs, we should query from the built-in table DUAL otherwise our injected query will return 500: We now know that there are two columns in the filter table, we can then use either query syntax above to probe for the Oracle version as follow: