CompTIA CySA+ (CS0-003)Security OperationsHard

A security analyst is reviewing a custom web application's access logs and identifies the following requests from a single source IP (192.168.1.100): ``` GET /search?query=test%27%20AND%20substring(version(),1,1)=%275%27-- HTTP/1.1 GET /search?query=test%27%20AND%20substring(version(),1,1)=%278%27-- HTTP/1.1 GET /search?query=test%27%20AND%20substring(version(),1,1)=%27M%27-- HTTP/1.1 ``` No direct error messages or data are returned in the HTTP responses, but the response time for the first request is 200ms, the second is 500ms, and the third is 200ms. What type of SQL Injection attack is most likely being attempted?

  1. ATime-based Blind SQL Injection
  2. BIn-band SQL Injection
  3. CBoolean-based Blind SQL Injection
  4. DError-based SQL Injection
Show answer & explanation

Correct answer: C. Boolean-based Blind SQL Injection

The attacker is using `substring(version(),1,1)='X'` to test character by character. Since 'No direct error messages or data are returned' and the attacker is observing 'response time' for *different* queries to infer truth (e.g., if '8' is true, the response might be different from '5' or 'M' due to processing, not necessarily a time delay). The critical part is inferring truth from the *difference* in response, not a specific delay. In this case, the attacker is testing boolean conditions and observing differing responses, which is characteristic of Boolean-based Blind SQL Injection. If it were time-based, they would explicitly embed `SLEEP()` or `WAITFOR DELAY` and look for a *specific*, consistent delay.

Why the other options are wrong

  • A. Time-based blind SQLi explicitly uses functions like `SLEEP()` or `WAITFOR DELAY` to introduce measurable delays based on true/false conditions. While response times are observed, the queries themselves `substring(version(),1,1)='X'` are boolean conditions, and the varying times are likely due to backend processing differences for true/false conditions, rather than explicit time delays.
  • B. In-band SQLi would return direct data or errors in the response, which is explicitly stated as not happening.
  • D. Error-based SQLi relies on database error messages, which are stated as not being returned.

Blind SQL Injection

A type of SQL injection where the attacker cannot see the results of the malicious query directly on the web page, but can infer the database's response based on the application's behavior.

  • Includes Boolean-based and Time-based variants.
  • Boolean-based infers truth from content changes or subtle response differences.
  • Time-based infers truth from deliberate time delays.

Memory trick: Blind SQLi hides the output, you infer the truth.

More Security Operations questions