While testing a content-management site, you discover a parameter that lets you inject SQL. Because verbose error messages are suppressed and long responses are blocked by a WAF, you craft a payload that causes the database to resolve a custom sub-domain under attacker.com, embedding selected column data in the DNS request. Which type of SQL injection are you performing?
The attack leverages the fact that the database can initiate an outbound DNS lookup, sending exfiltrated data over that separate channel. Unlike error-based or UNION-based techniques, the results are not returned in the HTTP response. Nor does it rely on measurable time delays like time-based blind attacks. Instead, it uses one channel for injection (the web request) and a different channel for data retrieval (DNS), which is characteristic of an out-of-band SQL injection. Second-order SQL injection differs because it stores the malicious input first and executes it later in a separate context.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
How does Out-of-Band SQL Injection differ from other SQL injection types?
Open an interactive chat with Bash
What role does DNS play in Out-of-Band SQL Injection?
Open an interactive chat with Bash
What are the primary defenses against Out-of-Band SQL Injection?
Open an interactive chat with Bash
Certified Ethical Hacker (CEH)
Web Application Hacking
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .