A scenario either gives a symptom and asks for a class, or gives a weakness and asks for a control. Decide which kind it is first.
Clues and what they point to
- Database error text in a user-facing page: an in-band exposure, and also an error-handling failure that needs its own fix.
- Response time that tracks one parameter: time-based blind. Nothing is displayed, so the timing is the leak.
- A database server reaching the internet: out-of-band. Pair it with egress filtering for database hosts and DNS monitoring.
- Bad data surfacing far from where it entered: second-order. The fix is binding parameters in every query, including those that read the application's own stored data.
Evasion, from the defender's chair
The blueprint lists evasion techniques as a Module 15 topic. The point is why signature matching is fragile: the same query logic can be written many ways, so a filter that looks for exact strings misses variants. The defensive answers are to normalize input before inspection, keep WAF signatures current and, above all, bind parameters, so that slipping past a filter changes nothing.
One flaw, several interpreters
Every injection flaw is untrusted input reaching an interpreter. What changes is the interpreter. In SQL injection, the database runs it. In cross-site scripting, the victim's browser runs it, which is why the XSS, CSRF and SSRF comparison sits next to this file. Command injection reaches the operating system shell, and LDAP, XPath and NoSQL injection reach their own query engines. Settle the interpreter question before you weigh the controls. The web application module covers the injection flaws that never touch a database.
Rules of engagement
Injection testing touches live data, so it needs written authorization that names the applications in scope.
Your skip-list
Function names for specific databases, tool switches and catalogs of filter-evasion encodings. They take hours to memorize and pay back little. Spend that time drilling until classifying a scenario and naming its control takes a few seconds.