The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Lab#SQL injection attack, querying the database type and version on MySQL and Microsoft

ds2000434 | Last updated: Nov 19, 2020 07:27PM UTC

Dear all, my question refers to https://portswigger.net/web-security/sql-injection/examining-the-database/lab-querying-database-version-mysql-microsoft. I already tried setting injectable parameter to following payloads without success: - ' UNION SELECT 'abc', 'def'--, - ' UNION SELECT @@version,NULL# (given solution) Any help is highly appreciated :)

Ben, PortSwigger Agent | Last updated: Nov 20, 2020 09:10AM UTC

Hi, Are you trying to enter these payloads via the address bar of your browser or through Burp?

ds2000434 | Last updated: Nov 20, 2020 12:53PM UTC

Hey, I tried it via burp now and it just worked out. Thanks =) Still confused where the difference is and why it was working on previous labs?

Ben, PortSwigger Agent | Last updated: Nov 23, 2020 02:14PM UTC