Reading
PentestingHere Academy
23 Sep 2026
What it is
SQL injection happens whenever your input becomes part of a SQL query instead of a value inside one. The three labs in this topic show three different shapes of the same underlying bug, worth knowing apart because they need different techniques to exploit.
The labs here
- PawMatch breed search UNION injection: the friendliest shape. Your input lands inside a query's WHERE clause, and the page prints the query's results back to you. Break out of the string with a quote, then UNION in your own SELECT to pull data from a completely different table.
- CraftBrew Loyalty sort-order blind injection: your input lands in the ORDER BY clause instead, where UNION doesn't work (it's the wrong part of the query for a second result set), and the page never prints your extracted data or a raw error either. You get one true/false signal per request: a CASE expression that sorts normally when a guess is right, and throws an error when it's wrong. Extract the flag one character at a time from that.
- Aegis Claims legacy API filter bypass: the query itself is injectable
the normal way, but a filter blocks the literal word UNION before your
input reaches it. The filter runs before a separate compatibility shim
that strips comment markers like
/*and*/. Split the blocked word across an empty comment (UNI/**/ON) and the filter never sees the word it's looking for.