Blind SQL Injection Techniques: Boolean-Based and Time-Based Methods
Blind SQL injection techniques extract data by inferring true/false conditions from application behavior when direct query results are not visible, using boolean-based responses or time delays to leak information bit by bit.
Blind SQL injection occurs when an application is vulnerable to SQL injection but does not return the results of the injected query directly. Attackers must rely on boolean-based or time-based inference techniques to extract data from the database. The PayloadsAllTheThings repository provides a comprehensive collection of working payloads for these blind SQL injection techniques across multiple database management systems.
Understanding Boolean-Based Blind SQL Injection
Boolean-based blind SQL injection forces the application to evaluate a conditional statement and react differently based on the result. The attacker sends two requests: one where the condition is true and one where it is false. By observing which request yields a valid response—such as a different page layout, HTTP status code, or error message—the attacker infers the truth value of the condition.
Boolean-Based Detection Methodology
According to the SQL Injection/README.md and Methodology and Resources/Methodology and enumeration.md files in the PayloadsAllTheThings repository, the core workflow follows these steps:
- Identify a vulnerable parameter (GET/POST, HTTP header, cookie, etc.) that interacts with the database.
- Inject a conditional expression that appends a boolean check, such as
AND (SELECT 1 FROM users WHERE username='admin'). - Send a true version (
… AND 1=1) and a false version (… AND 1=2) of the payload. - Compare the responses to confirm the application behaves differently based on the condition.
- Use binary search to extract data bit-by-bit by enumerating ASCII values or substring matches.
MySQL Boolean-Based Payloads
The SQL Injection/MySQL Injection.md file contains specific payloads for extracting data through boolean inference. Consider a scenario where the attacker tests the first character of a password:
GET /search.php?q=1' AND (SELECT SUBSTRING(password,1,1) FROM users WHERE username='admin')='a'-- HTTP/1.1
Host: vulnerable.example.com
If the character is 'a', the application returns the normal search results page. If the attacker changes the character to 'b' and receives an error page or different content length, they confirm the character is not 'b'. Repeating this process for each position reconstructs the entire password.
MSSQL Boolean-Based Implementation
For Microsoft SQL Server, the SQL Injection/MSSQL Injection.md file demonstrates similar substring enumeration:
GET /search.aspx?q=1' AND (SELECT SUBSTRING(password,1,1) FROM dbo.Users WHERE username='admin')='a'-- HTTP/1.1
Host: vulnerable.example.com
The attacker monitors for differences in HTTP response codes or page content to determine when the substring condition evaluates to true.
Time-Based Blind SQL Injection Techniques
When the application’s response is indistinguishable regardless of boolean outcome—meaning the page looks identical whether the condition is true or false—attackers resort to time-based blind SQL injection. Here, the injected condition triggers a deliberate delay (e.g., SLEEP(5)) if true, while the query returns instantly if false. The attacker measures response time to infer the condition’s truth value.
Time-Based Detection Workflow
According to the PayloadsAllTheThings methodology, the time-based approach follows this structured process:
- Locate the vulnerable input vector that processes user-supplied data in SQL queries.
- Append a conditional
IFstatement that calls a database-specific sleep function when the condition evaluates to true. - Record the response time for each request. A noticeable delay (e.g., 5-10 seconds) indicates the condition is true; a fast reply indicates false.
- Enumerate data character-by-character using binary search or sequential testing, similar to boolean-based methods, but driven entirely by timing differentials.
PostgreSQL Time-Based Payloads
The SQL Injection/PostgreSQL Injection.md file provides specific syntax for time-based extraction using pg_sleep():
GET /product?id=1; SELECT CASE WHEN (SUBSTRING(password,1,1)='a') THEN pg_sleep(5) ELSE pg_sleep(0) END-- HTTP/1.1
Host: vulnerable.example.com
If the first character of the password is 'a', the database pauses for 5 seconds before responding. If the character differs, the response returns immediately. By iterating through the ASCII range and measuring round-trip times, the attacker reconstructs the secret value without ever seeing the actual database output.
Oracle Time-Based Methods
For Oracle databases, the SQL Injection/OracleSQL Injection.md file contains payloads utilizing DBMS_LOCK.SLEEP() or heavy time-consuming queries when sleep functions are unavailable. The methodology remains identical: inject a conditional delay, measure response time, and infer data based on the timing differential.
MSSQL Time-Based Implementation
Microsoft SQL Server implements time-based blind SQL injection using the WAITFOR DELAY command, documented in SQL Injection/MSSQL Injection.md:
GET /search.aspx?q=1; IF (SELECT SUBSTRING(password,1,1) FROM dbo.Users WHERE username='admin')='a' WAITFOR DELAY '00:00:05'-- HTTP/1.1
Host: vulnerable.example.com
The WAITFOR DELAY '00:00:05' statement pauses execution for 5 seconds only if the substring condition matches, allowing the attacker to confirm character values through response timing analysis.
Automating Blind SQL Injection Detection
Manual enumeration of blind SQL injection vulnerabilities is time-consuming and error-prone. The SQL Injection/SQLmap.md file in the PayloadsAllTheThings repository provides guidance on automating both boolean-based and time-based detection using sqlmap.
Sqlmap automatically detects blind injection points by sending boolean payloads that compare page content hashes or by measuring response times when time-delay payloads are injected. It implements binary search algorithms to optimize data extraction, significantly reducing the number of requests required compared to linear character enumeration.
Defensive Measures Against Blind SQL Injection
Both boolean-based and time-based blind SQL injection techniques rely on unsanitized interpolation of user input into SQL statements. Effective mitigations include:
- Parameterized queries and prepared statements – Eliminate the injection surface by separating code from data, as implemented in modern database driver libraries.
- ORMs and query builders – Automatically escape values and abstract raw SQL construction.
- Input validation – Whitelist allowed characters (e.g., numeric IDs only) and reject suspicious patterns.
- Database-level hardening – Disable
SLEEPfunctions where possible, limit query timeouts, and restrict database user privileges to prevent unauthorized data extraction even if injection occurs.
The repository’s Methodology and Resources/Methodology and enumeration.md file contains a comprehensive SQL Injection checklist that covers testing for both boolean-based and time-based blind techniques, serving as a valuable resource for security auditors.
Summary
- Blind SQL injection extracts data when applications do not return query results directly, requiring inference from application behavior.
- Boolean-based blind SQLi relies on differential responses (true vs. false page states) to leak information character-by-character.
- Time-based blind SQLi uses database sleep functions (
SLEEP(),pg_sleep(),WAITFOR DELAY) to create measurable delays when conditions are true. - The PayloadsAllTheThings repository provides database-specific payloads in files like
SQL Injection/MySQL Injection.md,SQL Injection/PostgreSQL Injection.md, andSQL Injection/MSSQL Injection.md. - Sqlmap automates both techniques, implementing binary search to optimize extraction speed.
- Prevention requires parameterized queries, input validation, and database privilege restrictions.
Frequently Asked Questions
What is the difference between boolean-based and time-based blind SQL injection?
Boolean-based blind SQL injection requires the application to return visibly different responses (such as distinct page content, HTTP status codes, or error messages) when a SQL condition evaluates to true versus false. Time-based blind SQL injection works even when the page appears identical in both cases; instead, it relies on database delay functions like SLEEP() or WAITFOR DELAY to make the application pause for several seconds when the condition is true, allowing the attacker to infer data through response timing analysis.
How do attackers extract data using blind SQL injection techniques?
Attackers extract data through iterative character-by-character enumeration using binary search or linear testing. For each position in a target string (such as a password hash), the attacker injects a condition checking if the ASCII value or substring matches a specific value. By observing the boolean response or measuring the time delay, they confirm whether the guess was correct. Repeating this process for every character position reconstructs the complete secret value without ever seeing the actual database query output.
Which databases support time-based blind SQL injection payloads?
All major relational database management systems support time-based blind SQL injection through vendor-specific delay functions. MySQL uses SLEEP(seconds) and BENCHMARK(), PostgreSQL uses pg_sleep(seconds), Microsoft SQL Server uses WAITFOR DELAY 'time', and Oracle uses DBMS_LOCK.SLEEP() or computationally expensive queries when sleep functions are unavailable. The SQL Injection/ directory in PayloadsAllTheThings contains specific syntax examples for each platform in dedicated files like MySQL Injection.md, PostgreSQL Injection.md, MSSQL Injection.md, and OracleSQL Injection.md.
Can WAFs effectively block boolean-based blind SQL injection attacks?
Web Application Firewalls (WAFs) can block many common boolean-based blind SQL injection payloads by detecting SQL keywords, comparison operators, and substring functions in HTTP parameters. However, determined attackers often bypass these filters through encoding techniques, case variation, comment injection, and alternative syntax specific to different database engines. Effective protection requires defense-in-depth: parameterized queries at the application layer, strict input validation, database privilege restrictions, and behavioral analysis to detect anomalous query patterns rather than relying solely on signature-based WAF rules.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →