Join
Reading

SQL Injection: UNION, Blind Extraction, and the Tools That Automate It

PentestingHere Academy 23 Sep 2026

What it is

SQL injection happens whenever your input becomes part of a SQL query instead of a value inside one. The three labs in this topic show three different shapes of the same underlying bug, worth knowing apart because they need different techniques to exploit.

The labs here

  • PawMatch breed search UNION injection: the friendliest shape. Your input lands inside a query's WHERE clause, and the page prints the query's results back to you. Break out of the string with a quote, then UNION in your own SELECT to pull data from a completely different table.
  • CraftBrew Loyalty sort-order blind injection: your input lands in the ORDER BY clause instead, where UNION doesn't work (it's the wrong part of the query for a second result set), and the page never prints your extracted data or a raw error either. You get one true/false signal per request: a CASE expression that sorts normally when a guess is right, and throws an error when it's wrong. Extract the flag one character at a time from that.
  • Aegis Claims legacy API filter bypass: the query itself is injectable the normal way, but a filter blocks the literal word UNION before your input reaches it. The filter runs before a separate compatibility shim that strips comment markers like /* and */. Split the blocked word across an empty comment (UNI/**/ON) and the filter never sees the word it's looking for.