A penetration tester is performing a web application assessment. They identify a login form and attempt to bypass authentication. They submit the username `admin' AND 1=SLEEP(5)--` and a random password. The server takes approximately 5 seconds longer to respond than with a normal, invalid login attempt. Which type of SQL Injection is the tester likely exploiting?
- ATime-Based Blind SQL Injection
- BError-Based SQL Injection
- CStacked Queries SQL Injection
- DUnion-Based SQL Injection
Show answer & explanationAnswer & explanation
Correct answer: A. Time-Based Blind SQL Injection
The key indicator here is the `SLEEP(5)` function and the observed 5-second delay in the server's response. This behavior is characteristic of Time-Based Blind SQL Injection, where the attacker infers information about the database by observing delays in the application's response, rather than direct error messages or union-based data retrieval.
Why the other options are wrong
- B. Error-Based SQL Injection relies on the database returning verbose error messages that contain information about the database structure or data.
- C. Stacked Queries SQL Injection allows an attacker to execute multiple SQL statements in a single query, but it doesn't rely on time delays for information retrieval.
- D. Union-Based SQL Injection involves using the `UNION` operator to combine the results of a malicious query with the original query, directly returning data.
Time-Based Blind SQL Injection
A type of SQL Injection where an attacker infers information about the database by sending SQL queries that cause the database to delay its response for a specified amount of time (e.g., using `SLEEP()` or `WAITFOR DELAY`). This is used when direct output or error messages are unavailable.
- Relies on observable time delays in server responses.
- Used when no direct output or error messages are returned.
- Infers database information character by character or boolean by boolean.
- Often uses functions like `SLEEP()` or `WAITFOR DELAY`.
Memory trick: SQLi: Union combines, Error reveals, Time delays, Stacked commands.