CompTIA PenTest+ (PT0-003)Vulnerability Discovery and AnalysisMedium

While testing a login form parameter with Burp Repeater, a tester notices that injecting `' AND SLEEP(5)-- -` causes a consistent five-second delay in the server response, while other injected payloads produce output identical to normal requests. The tester then runs SQLMap against the parameter to confirm and exploit the flaw. Which SQL injection technique is being leveraged?

  1. AUNION query-based
  2. BBoolean-based blind
  3. CError-based
  4. DTime-based blind
Show answer & explanation

Correct answer: D. Time-based blind

Time-based blind SQL injection is confirmed when injecting a time-delay function (like SLEEP()) causes a measurable response delay, with no visible difference in output otherwise. Boolean-based blind relies on true/false content differences, UNION-based requires combining result sets visibly, and error-based relies on database error messages being returned.

Why the other options are wrong

  • A. UNION-based requires visible combined query results, not timing differences.
  • B. Boolean-based blind relies on content changes (true/false), not delays.
  • C. Error-based injection relies on database error messages leaking data, not timing.

Time-Based Blind SQL Injection

A SQL injection technique where the attacker infers data by measuring response delays caused by time-delay functions, since no visible output difference occurs.

  • Uses functions like SLEEP() or WAITFOR DELAY
  • Useful when application suppresses errors and output
  • SQLMap automates detection and exploitation via --technique=T

Memory trick: No error, no visible change, just a pause — Time is Talking

More Vulnerability Discovery and Analysis questions