Web Apps Intermediate

SQL Injection

From a single quote to a full database dump: UNION attacks, blind boolean and time-based extraction, and how parameterised queries end the whole class.

Porter Mohr 5 lessons

About this class

What you'll learn

SQL injection (SQLi) lets an attacker interfere with the queries an application makes to its database. This class covers detection, in-band (UNION) extraction, both flavours of blind injection, injection outside the WHERE clause, and prevention.

How the attacks are structured

Every lesson follows the same rhythm: form a hypothesis about the query, send a payload that would confirm it, and read the result from the response — whether that result is data, a boolean, or a time delay.

Practice

Pair the lessons with the SQL injection labs: UNION-based data extraction and blind SQL injection with time delays.

On this page

Price

0.0120 BTC

≈ $780.00

Sign In to Enrol

At a glance

Category
Web Apps
Difficulty
Intermediate
Lessons
5 · 2 free
Total time
1h 36m
Students
0 enrolled
Tutor
Porter Mohr
Published
Sep 2026