The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Lab: Blind SQL injection with conditional errors

phaneendra | Last updated: Jan 30, 2021 12:16PM UTC

Hi, While solving the lab which has a sql injection in tracking cookie I used the following payload TrackingId Cookie : 4gWGytzFyHUuumvW 4gWGytzFyHU'||case when((substr(select password from users where username='Administrator'),1,1)='a') then to_char(1/0) else 'uumvW' end-- 'a' is used as clusterbomb payload. I don't understand why the condition is always becoming true and throwing 500 internal error for all cases.

Uthman, PortSwigger Agent | Last updated: Feb 01, 2021 11:00AM UTC