ALL PASS, NO FAIL!

CEH v13 Module 15: SQL Injection

SQL injection (SQLi) is one of the most critical web application vulnerabilities. This module covers UNION-based, blind, boolean-based, and time-based SQL injection techniques. Learn how to use sqlmap for automated exploitation, bypass WAFs, and implement prevention through parameterized queries.

The CEHStudy app carries 14 flashcards for Module 15 across 3 sections — learn the type tree cold (in-band: error-based and union; blind: boolean and time; out-of-band); every payload question resolves by naming which class the technique belongs to.

Key Topics Covered

Important Terms & Concepts

UNION-based SQLi: Uses the UNION operator to combine results from the original query with an attacker-injected SELECT statement. Requires same number of columns in both queries.
Blind SQL Injection: No data is returned in the response. Attacker infers data by observing true/false responses or time delays. Slower but works when error messages are disabled.
Boolean-based Blind SQLi: Injects conditions that evaluate to TRUE or FALSE, observing differences in HTTP response content to infer data character by character.
Time-based Blind SQLi: Uses database-specific time functions (SLEEP(5) in MySQL, WAITFOR DELAY '00:00:05' in MSSQL) to infer data based on response timing.
sqlmap: Open-source tool that automates SQL injection detection and exploitation. Supports UNION, blind, time-based, error-based, out-of-band techniques. Can take full database control.
WAF Bypass: Techniques to evade Web Application Firewalls: encoding (%27 for single quote), double encoding, comment injection (--, #), character set manipulation, and chunk size attacks.

How to Study This Module

Frequently Asked Questions

What is SQL injection?
Inserting malicious SQL code into input fields to manipulate backend database queries. Can lead to data theft, authentication bypass, and full database compromise.

What are the types of SQL injection attacks?
In-band (UNION-based, error-based), Blind (boolean-based, time-based), and Out-of-band. In-band is easiest — attacker uses same channel for attack and results. Blind is slower but works when errors are hidden.

Related Modules

What is SQL Injection in Ethical Hacking?

SQL Injection (SQLi) is the most critical and most commonly exploited web application vulnerability — a standalone module on the CEH v13 exam. SQLi occurs when an app concatenates unsanitized user input into SQL queries, letting an attacker manipulate the query's logic and execute arbitrary database commands. Unlike other injection flaws, it targets the relational database engine itself — MySQL, Microsoft SQL Server, PostgreSQL, Oracle, SQLite. Impact ranges from unauthorized data access (reading all tables) to complete database compromise (modifying/deleting data, executing OS commands via xp_cmdshell on MSSQL). Module 15 topics account for approximately 12% of CEH v13 exam questions.

Key Concepts in SQL Injection

Common Exam Mistakes in Module 15

Guessing UNION column counts by trial and error: a UNION SELECT fails unless column counts match — the disciplined step is ORDER BY n until the error flips, then NULL padding. Stems showing ' UNION SELECT username, password FROM users-- are in-band: the data returns in the same visible response.
Calling every no-output injection time-based: blind splits two ways — boolean, where responses differ for ' AND 1=1 versus ' AND 1=2 and leak one character at a time, and time-based, where an induced delay (MySQL SLEEP(5), SQL Server WAITFOR DELAY '0:0:5', PostgreSQL pg_sleep(5)) is the only channel. What you observe — page content or latency — picks the flavor.
Stopping the defense list at input validation: the stack starts with parameterized queries (prepared statements) separating code from data; stored procedures, least-privilege DB accounts, WAF rules, ORM frameworks, and suppressing raw database errors all belong in the same answer. Validation alone is not the strongest primary defense.

Tools Used in SQL Injection

Tools the CEH v13 exam references for SQL injection testing:

Worked Example: Login Bypass to OS Shell, Class by Class

On a login form, admin'-- in the username field comments out the password check — the same tautology logic as ' OR 1=1-- — and the app signs the tester in as administrator: first-order, in-band injection. Escalating, ' ORDER BY 3-- stops erroring while ORDER BY 4 errors, so the query has three columns; ' UNION SELECT username, password FROM users-- then dumps credentials inside the same visible response.

The twist: a second endpoint renders nothing, so the channel becomes latency — SLEEP(5) fires only when the injected condition is true, the signature of time-based blind. The database engine sets the post-exploitation ceiling: xp_cmdshell on SQL Server runs OS commands (often disabled by default); prepared statements from day one would have collapsed the chain, since injected SQL becomes inert data.

How to Study SQL Injection for the CEH v13 Exam

To study Module 15 for the CEH v13 exam:

  1. Memorize the SQLi hierarchy: In-band (UNION-based, Error-based) → data returned in the same channel; Blind (Boolean, Time-based) → data inferred from response differences or timing; Out-of-Band → exfiltrated via DNS/HTTP callbacks. Exam stems classify scenarios and pick the technique for the constraints (e.g., "errors are suppressed, but responses differ" = boolean-based blind)
  2. Hands-on: set up DVWA (Damn Vulnerable Web Application) with local MySQL. Practice error-based (invalid SQL forcing errors that reveal table structure), UNION-based (column counting, information_schema), and boolean blind (character-by-character iteration). For each, document the payload, what the response reveals, and the sqlmap command that automates it — this maps directly to scenario questions asking for the right technique
  3. Memorize database-specific functions: MySQL — SLEEP(), BENCHMARK(), information_schema, LOAD_FILE(), INTO OUTFILE; MSSQL — WAITFOR DELAY, sysobjects, xp_cmdshell, OPENROWSET; PostgreSQL — pg_sleep(), information_schema, COPY TO PROGRAM; Oracle — UTL_HTTP.request(), all_tab_columns. Stems may name a database and ask which function handles time-based blind or exfiltration
  4. Review related modules: Module 14 (Web Application Hacking) for the OWASP A03 (Injection) context and how SQLi fits into web application attack chains, and Module 13 (Web Server Hacking) for server-level misconfigurations (verbose errors, excessive database permissions) that increase SQLi success

Frequently Asked Questions About SQL Injection

How do you identify a potentially vulnerable parameter for SQL injection?

(1) Single quote test — append a single quote ('). An error referencing SQL syntax, a database query, or "unterminated string literal" means input is concatenated into SQL without sanitization; (2) Boolean test — append ' AND 1=1 vs ' AND 1=2; different responses (page length, content) mean the parameter affects query logic; (3) Time-based test — append ' AND SLEEP(5)-- or '; WAITFOR DELAY '00:00:05'--; a ~5-second delay confirms SQLi even without visible errors; (4) URL encoding — an error that disappears with %27 (URL-encoded quote) but returns when decoded server-side means the input is processed in SQL context; (5) Parameter position — numeric parameters that should be integers (e.g., ?id=1) are commonly vulnerable because type validation is skipped. A single quote is the fastest first check — confirmation requires demonstrating data manipulation or auth bypass, not just an error.

What WAF bypass techniques work against SQL injection filters?

(1) URL encoding — %27 for the quote, double-encoded %2527 if the WAF decodes only once; (2) Inline comments — MySQL syntax /*!...*/ breaks up keywords: UN/**/ION SEL/**/ECT; (3) Case variation — some WAFs are case-sensitive: SeLeCt, UnIoN, sLeEp(); (4) Alternative syntax — information_schema instead of SHOW TABLES, 0x41 (hex) instead of 'A'; (5) Chunked transfer encoding — split the payload across HTTP chunks so no chunk holds the full pattern; (6) HTTP parameter pollution — duplicate the parameter (?id=1&id=1 UNION SELECT...) to confuse WAF parsing while the app uses one value; (7) Character set manipulation — GBK/UTF-8 multi-byte characters whose trailing byte escapes a string context. No single bypass guarantees success — it depends on the specific WAF's rules and encoding behavior. Parameterized queries remain the reliable defense, making all bypasses irrelevant.

Related CEH v13 Modules

Related Glossary Terms