Blind SQL Injection with Out-of-Band Data Exfiltration (Oracle XML + Burp Collaborator)
Overview of the Lab This lab demonstrates a blind SQL injection vulnerability in an Oracle database environment where the application does not return any visible output, errors, or timing differences that can be used for inference. Traditional techniques such as UNION-based, error-based, and time-based SQL injection are not applicable because the application is fully blind. Instead, exploitation is achieved through out-of-band (OOB) data exfiltration using DNS resolution , combined with Oracle XML processing abuse , and validated using Burp Suite Collaborator . This makes the attack completely invisible at the application layer while still allowing full data extraction from the backend. The key idea is that the database is manipulated into making an external DNS request to an attacker-controlled domain. That DNS request contains sensitive data encoded inside it, allowing exfiltration even when no response is returned to the user. Understanding the Core Attack Concept Out-of-band SQL i...