CompTIA PenTest+ (PT0-003)Attacks and ExploitsHard

A penetration tester is performing a web application assessment. They identify a login form and attempt to bypass authentication. They submit the username `admin' AND 1=SLEEP(5)--` and a random password. The server takes approximately 5 seconds longer to respond than with a normal, invalid login attempt. Which type of SQL Injection is the tester likely exploiting?

  1. ATime-Based Blind SQL Injection
  2. BError-Based SQL Injection
  3. CStacked Queries SQL Injection
  4. DUnion-Based SQL Injection
Show answer & explanation

Correct answer: A. Time-Based Blind SQL Injection

The key indicator here is the `SLEEP(5)` function and the observed 5-second delay in the server's response. This behavior is characteristic of Time-Based Blind SQL Injection, where the attacker infers information about the database by observing delays in the application's response, rather than direct error messages or union-based data retrieval.

Why the other options are wrong

  • B. Error-Based SQL Injection relies on the database returning verbose error messages that contain information about the database structure or data.
  • C. Stacked Queries SQL Injection allows an attacker to execute multiple SQL statements in a single query, but it doesn't rely on time delays for information retrieval.
  • D. Union-Based SQL Injection involves using the `UNION` operator to combine the results of a malicious query with the original query, directly returning data.

Time-Based Blind SQL Injection

A type of SQL Injection where an attacker infers information about the database by sending SQL queries that cause the database to delay its response for a specified amount of time (e.g., using `SLEEP()` or `WAITFOR DELAY`). This is used when direct output or error messages are unavailable.

  • Relies on observable time delays in server responses.
  • Used when no direct output or error messages are returned.
  • Infers database information character by character or boolean by boolean.
  • Often uses functions like `SLEEP()` or `WAITFOR DELAY`.

Memory trick: SQLi: Union combines, Error reveals, Time delays, Stacked commands.

More Attacks and Exploits questions