CompTIA PenTest+ (PT0-003)Attacks and ExploitsMedium
A tester is assessing a login form and submits the username field value: admin' AND SLEEP(5)-- -. The application returns no error and displays the normal login failure page, but the response consistently takes about 5 seconds longer to load than a baseline request. Which SQL injection technique is being used?
- ATime-based blind SQL injection
- BBoolean-based blind SQL injection
- CError-based SQL injection
- DUnion-based SQL injection
Show answer & explanationAnswer & explanation
Correct answer: A. Time-based blind SQL injection
Because there is no visible error or data difference in the response body, but the server's response delay directly corresponds to the injected SLEEP() function, this is time-based blind SQL injection, which infers true/false conditions from timing rather than content.
Why the other options are wrong
- B. Boolean-based blind injection distinguishes true/false by differences in page content, not timing.
- C. Error-based injection relies on database error messages leaking information, which is absent here.
- D. Union-based injection appends a UNION SELECT to pull data directly into the visible response.
Time-Based Blind SQL Injection
A blind SQLi technique that infers database information by observing response time delays caused by conditional time-delay functions like SLEEP() or WAITFOR DELAY.
- Used when no errors or content differences are visible
- Common payloads: SLEEP(), BENCHMARK(), WAITFOR DELAY
- Slower and noisier than error-based or union-based techniques
Memory trick: Time-based = the database takes a nap to answer your question