Time-Based Blind SQL Injection using Heavy Queries - DEF CON

xp_cmdshell ‘ping –n 10 127.0.0.1’ application paused 10 seconds. Time-based techniques can be extended to any action performed by a stored procedure capable of generating a time delay or any other measurable action. In [6] SQL Injection tricks for MySQL are included with some examples based on benchmark ................
................