Posts

Showing posts with the label Blind SQLI

Blind SQL Injection with Out-of-Band Data Exfiltration (Oracle XML + Burp Collaborator)

Image
Overview of the Lab This lab demonstrates a blind SQL injection vulnerability in an Oracle database environment where the application does not return any visible output, errors, or timing differences that can be used for inference. Traditional techniques such as UNION-based, error-based, and time-based SQL injection are not applicable because the application is fully blind. Instead, exploitation is achieved through out-of-band (OOB) data exfiltration using DNS resolution , combined with Oracle XML processing abuse , and validated using Burp Suite Collaborator . This makes the attack completely invisible at the application layer while still allowing full data extraction from the backend. The key idea is that the database is manipulated into making an external DNS request to an attacker-controlled domain. That DNS request contains sensitive data encoded inside it, allowing exfiltration even when no response is returned to the user. Understanding the Core Attack Concept Out-of-band SQL i...

Blind SQL injection with out-of-band interaction for oracle database

Image
Blind SQL Injection with Out-of-Band Interaction (Oracle Database) Lab Overview This lab demonstrates a blind SQL injection vulnerability in an Oracle database environment where the application does not return any visible database output, error messages, or timing differences that can reliably be used for inference. Instead, the vulnerability is confirmed through out-of-band (OOB) interaction using DNS lookup , triggered by SQL execution on the backend database. The attack is validated using Burp Suite Collaborator , which detects external DNS requests initiated by the database server. When the database resolves a domain controlled by the attacker, it provides definitive proof that SQL injection is present and that arbitrary SQL execution is possible. This technique is particularly important in real-world penetration testing scenarios where applications are heavily hardened, and traditional injection methods such as UNION-based, boolean-based, or time-based SQL injection are not v...

Blind SQL injection with time delays and information retrieval

Overview of the Lab This lab demonstrates a time-based blind SQL injection vulnerability in a PostgreSQL-backed web application , where no direct database output or error messages are returned to the user. Instead, information is extracted by observing response time differences caused by conditional database delays . The attacker leverages PostgreSQL’s pg_sleep() function to force the database to delay responses when specific conditions evaluate to TRUE. By measuring these delays, sensitive information such as usernames and passwords can be extracted incrementally. This type of vulnerability is especially important in real-world scenarios because: Applications often suppress errors completely No query output is reflected in responses Boolean-based inference may not be available Timing differences become the only observable signal Understanding Time-Based Blind SQL Injection in PostgreSQL In PostgreSQL, the function: pg_sleep(seconds) forces the database to pause ...

Blind SQL injection with conditional errors for oracle database.

Image
Blind SQL Injection with Conditional Errors (Oracle Database) Lab Overview This lab demonstrates a blind SQL injection vulnerability in an Oracle database environment , where data is not directly returned in HTTP responses. Instead, information is extracted by forcing conditional database errors , allowing the attacker to infer results based on whether the application generates an error or behaves normally. Unlike classic UNION-based SQL injection, this technique relies on Oracle-specific behavior , particularly the use of CASE , TO_CHAR , ROWNUM , and error generation through invalid arithmetic operations (such as division by zero). The exploitation flow consists of: Building boolean-based error logic Verifying database structure and table existence Extracting data using conditional errors Automating password extraction using Burp Suite Intruder This type of SQL injection is highly effective in Oracle systems because errors can be deliberately triggered to represent TRU...