Which type of SQL injection attack involves sending incorrect SQL commands to a database to force it to reveal useful system information through error messages?
Make the call. Every option has a note waiting here.
Notes on all 4 options
- ATautology injection makes a condition always true, for example to bypass a login check, rather than relying on error messages.
- BUnion query injection appends a second SELECT to return extra data in normal output, not through error messages.
- CBlind injection is used when errors and output are hidden, inferring data from true or false behavior or timing.
- DCorrect: error-based injection deliberately triggers database errors whose verbose messages leak structure or data, which generic error pages prevent.