CompTIA PenTest+ (PT0-003)Attacks and ExploitsMedium

A penetration tester is performing a web application assessment. They encounter a login form and want to test for SQL injection. They enter the username `admin' -- ` and a random password. The application returns an error message: 'Incorrect username or password.' The tester then tries `admin' OR 1=1 -- ` and a random password. This time, the application successfully logs in the tester as an administrator. Which type of SQL injection did the tester successfully perform?

  1. ATime-based Blind SQL Injection
  2. BBoolean-based Blind SQL Injection
  3. CUnion-based SQL Injection
  4. DError-based SQL Injection
Show answer & explanation

Correct answer: B. Boolean-based Blind SQL Injection

The tester used a `OR 1=1` condition, which always evaluates to true, to bypass the authentication logic. The success or failure of the login attempt directly indicates whether the injected condition was processed, making it a Boolean-based blind SQL injection.

Why the other options are wrong

  • A. Time-based blind SQL injection relies on delays in server responses to infer data, which is not described here.
  • C. Union-based SQL injection uses the `UNION` operator to combine the results of two `SELECT` statements, which was not used.
  • D. Error-based SQL injection relies on database error messages to extract information, and while an initial error was seen, the successful login did not rely on extracting data from errors.

Boolean-based Blind SQL Injection

A type of SQL injection where the attacker sends SQL queries that force the application to return a different result depending on whether a true or false condition is met, without directly returning database errors or data.

  • Relies on observable changes in application behavior (e.g., page content, login success).
  • Typically uses logical operators like `AND` or `OR` with a true/false condition.
  • Often used when error messages or direct data retrieval are suppressed.

Memory trick: Blind injections guess, union joins, and errors expose.

More Attacks and Exploits questions