WorksheetsPre-Final Exam in Computer Security
Total questions: 10
Worksheet time: 5mins
What is SQL Injection (SQLi)?
A method to protect databases from attacks
An injection attack where malicious SQL statements are executed
A method of encrypting database data
Which of the following is NOT a type of SQL Injection?
Error-based SQLi
Blind SQLi
UNION-based SQLi
Deaf SQLi
What does Error-Based SQLi rely on?
Network delay
Error messages from the database
Password brute-forcing
Which SQL operator is used in UNION-based SQLi?
JOIN
UNION
MERGE
What is the purpose of @@version in Error-Based SQLi?
To retrieve column names
To display the current version of the database
To delete tables
What should you do before displaying field values in Error-Based SQLi?
Check column order
Convert table name to hex
Log in as admin
In Blind SQLi, what does the following payload do? AND (length(database())) = 8--+**
Deletes the database
Checks if the database name is 8 characters long
Returns all database names
What is the purpose of ascii(substr(...)) in Blind SQLi?
Measures query length
Extracts characters one by one using ASCII values
Encrypts column names
What is the correct query to extract column names from a table using Blind SQLi?
SELECT * FROM columns;
SELECT column_name FROM table_name;
SELECT ascii(substr((SELECT column_name FROM information_schema.columns WHERE table_name = 'table'),1,1))--+
What does group_concat(column_name) do?
Sums up values in a column
Groups identical columns
Lists all column names in one string
