The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

SQLi lab - Blind SQL injection with conditional errors problem

DilemmaRabbit | Last updated: Aug 12, 2022 07:13AM UTC

Hello, I am tring to solve this lab. I notice that the solution using this pattern to check vulnerbility. TrackingId=xyz'||(SELECT '' FROM dual)||' I am confuse with concatenation symbol "||" ,why need to use concatenation symbol in my SQLi? And why can't I use space or other logical symbol (like AND or OR) to create a new SQL query?

Michelle, PortSwigger Agent | Last updated: Aug 12, 2022 10:18AM UTC