Day 8 · Week 2

SQL injection

Complete TryHackMe SQL Injection Introduction and two PortSwigger SQL injection labs.

Challenges completed

THM SQL injection room

What I learned

  • Different types of SQL injection

    • In-Band

      • Error based
      • Union Based
    • Blind

      • Authentication
      • Boolean
      • Timed
    • Out of Band SQL Injection

  • Detecting when SQL Injection is possible

  • Remediation and Prevention tactics

Commands, tools, and techniques

  • ' OR 1=1; -- - Authentication bypass
  • 0 UNION SELECT 1,2,3 - for finding columns of tables

Problems and dead ends

Explain what did not work and why.

What I will revisit

  • More hands on practise with SQL injections with PortSwigger