Skip to content
ScopefileGet the app

Technique fileSQL injection

SQL injection types: in-band, blind and out-of-band

CEH groups SQL injection types into three families by one thing: how the result gets back to the attacker. In-band injection returns it inside the application's own response, blind (inferential) injection returns no data at all, only indirect clues, and out-of-band injection uses a separate channel the database server opens itself. Learn that split, the evidence each family leaves and the control it maps to, and Module 15, SQL Injection becomes a sorting exercise.

Exam
312-50
Domain
5 · Web apps
Targets
8

Six terms, defined by what leaks and why

In-band SQL injection
The family where the injected query's output reaches the attacker inside the page the application already serves. It depends on input joined into the SQL text and a page that displays what the database returns.
Error-based
An in-band variant: diagnostic detail from the database, such as table names or data fragments, is passed through to the user. The extra weakness is verbose error handling.
UNION-based
An in-band variant that merges a second result set into the legitimate one, so rows from unrelated tables appear on an ordinary page.
Boolean-based blind
An inferential variant. Nothing from the database is displayed, and the page content differs depending on whether a hidden condition is true or false. The flaw is unchanged; only the output is hidden.
Time-based blind
The inferential variant for pages that look identical either way, where the response time is the only thing that varies.
Out-of-band
The database server itself carries the data out over a separate network channel, such as DNS or HTTP. It relies on database features that can make network calls and on a database host with open egress.

The control stack, bottom up

Only the bottom layer removes the cause; every layer above it limits damage or raises an alert
Six stacked layers of SQL injection defense: parameterized queries at the base, then allow-list validation, least-privilege database accounts, generic error handling, egress filtering on database hosts, and WAF plus database activity monitoring at the top.WAF + DB monitoringdetects, compensatesDB egress filteringcloses out-of-bandGeneric error pagesstarves error-basedLeast-privilege accountcaps reachAllow-list validationrejects bad inputParameterized queriesremoves the cause

From the analyst's evidence to the class

What each SQL injection family looks like in logs and alerts, and the control matched to it
ClassWhat a defender observesControl that answers it
Error-basedDatabase exception text in pages, or a burst of syntax errors in the application log from one client.Parameterized queries first; generic error pages with details logged server-side only.
UNION-basedOversized responses, and database monitoring flagging reads of tables that feature never touches.Parameterized queries; a least-privilege account that cannot read those tables at all.
Boolean-based blindLong runs of near-identical requests to one parameter, with response lengths in two recurring values.Parameterized queries; rate limiting and WAF anomaly scoring raise the alert.
Time-based blindLatency that climbs for one parameter only, matched by unexplained database wait events.Parameterized queries; query timeouts and slow-query alerting surface it.
Out-of-bandOutbound DNS or HTTP traffic from the database tier, which a database server should almost never generate.Egress filtering and DNS monitoring for database hosts; disable network-capable database features; parameterized queries.

The symptom names the class, and the class names the control. Where the WAF sits relative to the database tier is covered in the IDS, IPS and firewall comparison.

Name the family from the evidence

Sort each target by where its result surfaced: inside the page, in behavior or timing alone, or over a separate channel.

Answered 0/8Hits 0

T-01

Which type of SQL injection attack involves sending incorrect SQL commands to a database to force it to reveal useful system information through error messages?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ATautology injection makes a condition always true, for example to bypass a login check, rather than relying on error messages.
  2. BUnion query injection appends a second SELECT to return extra data in normal output, not through error messages.
  3. CBlind injection is used when errors and output are hidden, inferring data from true or false behavior or timing.
  4. DCorrect: error-based injection deliberately triggers database errors whose verbose messages leak structure or data, which generic error pages prevent.
T-02

In the context of SQL injection, which type of attack involves leveraging error messages to gather information from the database?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ABlind injection gives the attacker no visible errors or data, so it relies on inferring answers rather than reading database error messages.
  2. BOut-of-band injection moves data through a separate channel such as DNS or HTTP requests from the database server, not through error output on the page.
  3. CCorrect: error-based injection is a form of in-band SQL injection, because the same web response that carries the attack also returns the revealing database errors.
  4. DInferential injection is another name for blind injection, where results are deduced from true/false behavior or timing, not read from error messages.
T-03

Which of the following is a common method to test for blind SQL injection vulnerabilities?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: time-based testing adds a conditional delay and watches response time, revealing injection even when the page content never changes.
  2. BResponse headers rarely reveal whether input reaches a database query, so they are not a standard blind injection test.
  3. CPage source shows client-side markup and does not reveal backend query behavior when output is suppressed.
  4. DPacket captures show traffic but do not by themselves test whether user input changes a database query.
T-04

An analyst reviews a Python script sending SQL payloads with logical operators. The script infers database content solely by comparing HTTP 200 and HTTP 500 server responses. Which technique is this?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AUNION-based injection pulls data directly into the response, whereas this script only observes status codes.
  2. BCorrect: boolean-based blind injection asks true or false questions and infers data from consistent differences in responses, here 200 versus 500.
  3. CTime-based blind injection measures response delays, not differences in status codes.
  4. DError-based injection reads data from verbose error text, whereas here only the status code is compared.
T-05

You are performing a blind SQL injection attack. Which of the following best describes this type of attack?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AWhere the attacker sits, locally or remotely, does not define blind injection; the defining trait is that query results are never shown directly.
  2. BCorrect: in blind SQL injection the application shows no data or errors, so the attacker infers results from differences in page content or response timing.
  3. CRemote delivery describes almost every web attack and says nothing about how blind injection obtains its answers from the database.
  4. DUsing the same channel to send the attack and receive results describes in-band injection, such as error-based or union-based, not the blind category.
T-06

Which of the following is NOT a common type of SQL attack?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AUnion-based injection is a common SQL injection type that appends a second query to return extra data.
  2. BCorrect: a rainbow table attack cracks password hashes with precomputed chains and has nothing to do with injecting SQL.
  3. CError-based injection is a standard type that extracts information from database error messages.
  4. DBlind injection is a standard type that infers data from application behavior or timing.
T-07

Your cybersecurity team is tasked with mitigating SQL injection vulnerabilities. What should you implement to protect against these attacks?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: parameterized queries keep user input as data separate from SQL code, which prevents injection at its root.
  2. BRegular penetration testing helps find injection flaws but does not itself prevent them.
  3. CEncrypting stored data protects confidentiality at rest but does not stop injected queries from running.
  4. DA network firewall controls connections but does not inspect application queries to stop malicious SQL.
T-08

In an authorized test, a form is injectable, but the page never shows query results or database errors, and response times are too unstable to infer anything. Data is confirmed only when the database server itself contacts an external domain the tester controls. Which SQL injection category is this?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AUnion-based injection is in-band: results come back in the application's own page, which the stem says never shows query output.
  2. BError-based injection relies on database error messages returned to the page, and the stem states that no errors are ever displayed.
  3. CTime-based blind injection infers data from response delays, but the stem says timing is too unstable to draw any conclusion from it.
  4. DCorrect: out-of-band injection makes the database send data over a separate channel, such as DNS or HTTP, when in-band and inferential methods fail.

Where this file pays, and what to drop

Module 15 shares Domain 5, Web Application Hacking, with web servers and web applications; the domain carries 14% of the exam under blueprint v5.0 (checked Oct 11, 2026), and the blueprint lists SQL injection types as a named Module 15 topic. The v13 course outline names error-based, union and blind injection, the same terms used here.

High yield

  • The three families and their five variants, defined by where the result surfaces.
  • One defender's clue per variant, from the table above.
  • Parameterized queries as the primary defense, with egress filtering as the extra control for out-of-band.

Second-order injection is about timing: stored input turns dangerous when a later query reuses it, through any of the three families. Blind here describes what the response hides; it is unrelated to a blind or black-box engagement, where the tester starts without inside information. Input that reaches a browser or a shell instead of a database belongs to other files: the XSS, CSRF and SSRF comparison and the web application module.

Skip-list

Database-specific function names, tool switches and encoding catalogs. You can miss all of them and still collect the classification points.

Questions about the three families

Is blind SQL injection less serious than in-band?

No. Root cause and fix are identical. Blind extraction is slower and noisier in your logs, so it is easier to spot; once it works, the damage is the same.

Why bother with least privilege if every query is parameterized?

Defense in depth. One missed query, or a stored procedure that builds dynamic SQL inside, reopens the hole, and a database account limited to the tables its feature needs caps what that one mistake exposes.

Is second-order injection a fourth family?

No. It describes when stored input fires, in a later query, and the data can then come back in-band, blind or out-of-band. Learn the three families first and treat second-order as a timing label.

Sources