Web Apps
Intermediate
SQL Injection
From a single quote to a full database dump: UNION attacks, blind boolean and time-based extraction, and how parameterised queries end the whole class.
Porter Mohr
5 lessons
About this class
What you'll learn
SQL injection (SQLi) lets an attacker interfere with the queries an application
makes to its database. This class covers detection, in-band (UNION) extraction,
both flavours of blind injection, injection outside the WHERE clause, and
prevention.
How the attacks are structured
Every lesson follows the same rhythm: form a hypothesis about the query, send a payload that would confirm it, and read the result from the response — whether that result is data, a boolean, or a time delay.
Practice
Pair the lessons with the SQL injection labs: UNION-based data extraction and blind SQL injection with time delays.
Curriculum
On this page
Price
0.0120 BTC≈ $780.00
At a glance
- Category
- Web Apps
- Difficulty
- Intermediate
- Lessons
- 5 · 2 free
- Total time
- 1h 36m
- Students
- 0 enrolled
- Tutor
- Porter Mohr
- Published
- Sep 2026