The Payloads So far, we will try to focus on mssql (using waitfor delay command to introduce time delay) and MySQL Server (using benchmark function to generate long CPU activities).
The Payloads So far, we will try to focus on mssql (using waitfor delay command to introduce time delay) and MySQL Server (using benchmark function to generate long CPU activities).

SQL injection entry points, because there are so many ways to write an SQL statement, we will not be able to provide an exhaustive list of payloads for each kind of SQL command and injection issue.

Burp Suite example, this is a short example of a blind SQL injection detection with Burp Suite.

Introduction, burp suite is local proxy software (man-in-the-middle application) helping a penetration tester to perform deep analysis and security checks of the http conversation, between a browser and a web application.

First, we send a recorded http request to the Intruder module and set up the position where the payload will have to be injected (in red).

And then we start the attack (see Intruder menu).

For each injection, we will: use", double", parenthesis or blank characters to close everything written before the injected payload.

When it will be finished, the responses will be displayed in a table format.

In order to find SQL injection issues behind specific parameters of a page, we will simply use some usual time-base consuming SQL statements such as waitfor delay (for MS-SQL) and benchmark (for MySQL and sort the http responses.
