# Blind SQL Injection Techniques: Boolean-Based and Time-Based Methods

> Master blind SQL injection techniques. Learn boolean-based and time-based methods to infer and extract data when direct results are hidden. Enhance your security skills today.

- Repository: [Swissky/PayloadsAllTheThings](https://github.com/swisskyrepo/PayloadsAllTheThings)
- Tags: tutorial
- Published: 2026-03-01

---

**Blind SQL injection techniques extract data by inferring true/false conditions from application behavior when direct query results are not visible, using boolean-based responses or time delays to leak information bit by bit.**

Blind SQL injection occurs when an application is vulnerable to SQL injection but does not return the results of the injected query directly. Attackers must rely on **boolean-based** or **time-based** inference techniques to extract data from the database. The [PayloadsAllTheThings](https://github.com/swisskyrepo/PayloadsAllTheThings) repository provides a comprehensive collection of working payloads for these blind SQL injection techniques across multiple database management systems.

## Understanding Boolean-Based Blind SQL Injection

Boolean-based blind SQL injection forces the application to evaluate a conditional statement and react differently based on the result. The attacker sends two requests: one where the condition is true and one where it is false. By observing which request yields a valid response—such as a different page layout, HTTP status code, or error message—the attacker infers the truth value of the condition.

### Boolean-Based Detection Methodology

According to the `SQL Injection/README.md` and `Methodology and Resources/Methodology and enumeration.md` files in the PayloadsAllTheThings repository, the core workflow follows these steps:

1. **Identify a vulnerable parameter** (GET/POST, HTTP header, cookie, etc.) that interacts with the database.
2. **Inject a conditional expression** that appends a boolean check, such as `AND (SELECT 1 FROM users WHERE username='admin')`.
3. **Send a true version** (`… AND 1=1`) and a **false version** (`… AND 1=2`) of the payload.
4. **Compare the responses** to confirm the application behaves differently based on the condition.
5. **Use binary search** to extract data bit-by-bit by enumerating ASCII values or substring matches.

### MySQL Boolean-Based Payloads

The `SQL Injection/MySQL Injection.md` file contains specific payloads for extracting data through boolean inference. Consider a scenario where the attacker tests the first character of a password:

```http
GET /search.php?q=1' AND (SELECT SUBSTRING(password,1,1) FROM users WHERE username='admin')='a'-- HTTP/1.1
Host: vulnerable.example.com

```

If the character is `'a'`, the application returns the normal search results page. If the attacker changes the character to `'b'` and receives an error page or different content length, they confirm the character is not `'b'`. Repeating this process for each position reconstructs the entire password.

### MSSQL Boolean-Based Implementation

For Microsoft SQL Server, the `SQL Injection/MSSQL Injection.md` file demonstrates similar substring enumeration:

```http
GET /search.aspx?q=1' AND (SELECT SUBSTRING(password,1,1) FROM dbo.Users WHERE username='admin')='a'-- HTTP/1.1
Host: vulnerable.example.com

```

The attacker monitors for differences in HTTP response codes or page content to determine when the substring condition evaluates to true.

## Time-Based Blind SQL Injection Techniques

When the application’s response is indistinguishable regardless of boolean outcome—meaning the page looks identical whether the condition is true or false—attackers resort to **time-based** blind SQL injection. Here, the injected condition triggers a deliberate delay (e.g., `SLEEP(5)`) if true, while the query returns instantly if false. The attacker measures response time to infer the condition’s truth value.

### Time-Based Detection Workflow

According to the PayloadsAllTheThings methodology, the time-based approach follows this structured process:

1. **Locate the vulnerable input vector** that processes user-supplied data in SQL queries.
2. **Append a conditional `IF` statement** that calls a database-specific sleep function when the condition evaluates to true.
3. **Record the response time** for each request. A noticeable delay (e.g., 5-10 seconds) indicates the condition is true; a fast reply indicates false.
4. **Enumerate data character-by-character** using binary search or sequential testing, similar to boolean-based methods, but driven entirely by timing differentials.

### PostgreSQL Time-Based Payloads

The `SQL Injection/PostgreSQL Injection.md` file provides specific syntax for time-based extraction using `pg_sleep()`:

```http
GET /product?id=1; SELECT CASE WHEN (SUBSTRING(password,1,1)='a') THEN pg_sleep(5) ELSE pg_sleep(0) END-- HTTP/1.1
Host: vulnerable.example.com

```

If the first character of the password is `'a'`, the database pauses for 5 seconds before responding. If the character differs, the response returns immediately. By iterating through the ASCII range and measuring round-trip times, the attacker reconstructs the secret value without ever seeing the actual database output.

### Oracle Time-Based Methods

For Oracle databases, the `SQL Injection/OracleSQL Injection.md` file contains payloads utilizing `DBMS_LOCK.SLEEP()` or heavy time-consuming queries when sleep functions are unavailable. The methodology remains identical: inject a conditional delay, measure response time, and infer data based on the timing differential.

### MSSQL Time-Based Implementation

Microsoft SQL Server implements time-based blind SQL injection using the `WAITFOR DELAY` command, documented in `SQL Injection/MSSQL Injection.md`:

```http
GET /search.aspx?q=1; IF (SELECT SUBSTRING(password,1,1) FROM dbo.Users WHERE username='admin')='a' WAITFOR DELAY '00:00:05'-- HTTP/1.1
Host: vulnerable.example.com

```

The `WAITFOR DELAY '00:00:05'` statement pauses execution for 5 seconds only if the substring condition matches, allowing the attacker to confirm character values through response timing analysis.

## Automating Blind SQL Injection Detection

Manual enumeration of blind SQL injection vulnerabilities is time-consuming and error-prone. The `SQL Injection/SQLmap.md` file in the PayloadsAllTheThings repository provides guidance on automating both boolean-based and time-based detection using **sqlmap**.

Sqlmap automatically detects blind injection points by sending boolean payloads that compare page content hashes or by measuring response times when time-delay payloads are injected. It implements binary search algorithms to optimize data extraction, significantly reducing the number of requests required compared to linear character enumeration.

## Defensive Measures Against Blind SQL Injection

Both boolean-based and time-based blind SQL injection techniques rely on unsanitized interpolation of user input into SQL statements. Effective mitigations include:

- **Parameterized queries and prepared statements** – Eliminate the injection surface by separating code from data, as implemented in modern database driver libraries.
- **ORMs and query builders** – Automatically escape values and abstract raw SQL construction.
- **Input validation** – Whitelist allowed characters (e.g., numeric IDs only) and reject suspicious patterns.
- **Database-level hardening** – Disable `SLEEP` functions where possible, limit query timeouts, and restrict database user privileges to prevent unauthorized data extraction even if injection occurs.

The repository’s `Methodology and Resources/Methodology and enumeration.md` file contains a comprehensive SQL Injection checklist that covers testing for both boolean-based and time-based blind techniques, serving as a valuable resource for security auditors.

## Summary

- **Blind SQL injection** extracts data when applications do not return query results directly, requiring inference from application behavior.
- **Boolean-based blind SQLi** relies on differential responses (true vs. false page states) to leak information character-by-character.
- **Time-based blind SQLi** uses database sleep functions (`SLEEP()`, `pg_sleep()`, `WAITFOR DELAY`) to create measurable delays when conditions are true.
- The **PayloadsAllTheThings** repository provides database-specific payloads in files like `SQL Injection/MySQL Injection.md`, `SQL Injection/PostgreSQL Injection.md`, and `SQL Injection/MSSQL Injection.md`.
- **Sqlmap** automates both techniques, implementing binary search to optimize extraction speed.
- Prevention requires **parameterized queries**, input validation, and database privilege restrictions.

## Frequently Asked Questions

### What is the difference between boolean-based and time-based blind SQL injection?

Boolean-based blind SQL injection requires the application to return visibly different responses (such as distinct page content, HTTP status codes, or error messages) when a SQL condition evaluates to true versus false. Time-based blind SQL injection works even when the page appears identical in both cases; instead, it relies on database delay functions like `SLEEP()` or `WAITFOR DELAY` to make the application pause for several seconds when the condition is true, allowing the attacker to infer data through response timing analysis.

### How do attackers extract data using blind SQL injection techniques?

Attackers extract data through iterative character-by-character enumeration using binary search or linear testing. For each position in a target string (such as a password hash), the attacker injects a condition checking if the ASCII value or substring matches a specific value. By observing the boolean response or measuring the time delay, they confirm whether the guess was correct. Repeating this process for every character position reconstructs the complete secret value without ever seeing the actual database query output.

### Which databases support time-based blind SQL injection payloads?

All major relational database management systems support time-based blind SQL injection through vendor-specific delay functions. MySQL uses `SLEEP(seconds)` and `BENCHMARK()`, PostgreSQL uses `pg_sleep(seconds)`, Microsoft SQL Server uses `WAITFOR DELAY 'time'`, and Oracle uses `DBMS_LOCK.SLEEP()` or computationally expensive queries when sleep functions are unavailable. The `SQL Injection/` directory in PayloadsAllTheThings contains specific syntax examples for each platform in dedicated files like `MySQL Injection.md`, `PostgreSQL Injection.md`, `MSSQL Injection.md`, and `OracleSQL Injection.md`.

### Can WAFs effectively block boolean-based blind SQL injection attacks?

Web Application Firewalls (WAFs) can block many common boolean-based blind SQL injection payloads by detecting SQL keywords, comparison operators, and substring functions in HTTP parameters. However, determined attackers often bypass these filters through encoding techniques, case variation, comment injection, and alternative syntax specific to different database engines. Effective protection requires defense-in-depth: parameterized queries at the application layer, strict input validation, database privilege restrictions, and behavioral analysis to detect anomalous query patterns rather than relying solely on signature-based WAF rules.