The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Blind SQL injection with time delays and information retrieval

Robert | Last updated: Oct 21, 2022 03:23PM UTC

Hi, just hoping someone could help me understand something cus I'm a bit lost. In the lab on Blind SQL injection with time delays and information retrieval I was using the "||" string concatenation at the start of the SELECT+CASE+WHEN entry, but when attempting to use the intruder and the SUBSTRING keyword to enumerate the characters, the concatenation needs to change to ";" or rather "%3b" and I don't understand why it has to change or why "||" now doesn't work. Any explanation would be greatly appreciated. Thank you

Hannah, PortSwigger Agent | Last updated: Oct 24, 2022 01:28PM UTC