Uploaded July 2023 | Updated September 2026, 9 hours ago
In this video, Tib3rius completes the Visible Error-based SQL Injection lab from Portswigger Web Academy.
The lab completed was: portswigger.net/web-security/sql-injection/blind/lab-sql-injection-visible-error-based
Portion of my other video explaining how to identify database variants: youtube.com/watch?v=HDOm7ZmSjJw&t=555s
0:00 - Introduction
0:20 - Starting Lab: Visible error-based SQL injection
2:04 - Identifying the SQL injection in the cookie.
2:09 - Explaining how to identify database variants using concatenation.
4:45 - Explaining the concept of exploiting error-based SQL injection.
9:17 - Extracting the database version number via the error message.
10:42 - Attempting to extract the password from the users table, running into truncation issues.
11:49 - Defeating the truncation using shorthand casting syntax, removing the cookie value, and concatenating everything.
13:01 - Extracting the passwords from the table, solving the lab.
15:03 - Outro
Twitter: twitter.com/0xTib3rius
Twitch: twitch.tv/0xTib3rius
Courses: courses.tib3rius.com
Udemy: udemy.com/user/tib3rius
Discord: discord.com/invite/4qrvKMh
Threads: threads.net/@0xtib3rius
LinkedIn: linkedin.com/in/tib3rius
Facebook: facebook.com/0xTib3rius
InfoSec Exchange: https://infosec.exchange/@tib3rius
Bluesky: https://bsky.app/profile/tib3rius.bsky.social
In this video, Tib3rius completes the Visible Error-based SQL Injection lab from Portswigger Web Academy.
The lab completed was: portswigger.net/web-security/sql-injection/blind/lab-sql-injection-visible-error-based
Portion of my other video explaining how to identify database variants: youtube.com/watch?v=HDOm7ZmSjJw&t=555s
0:00 - Introduction
0:20 - Starting Lab: Visible error-based SQL injection
2:04 - Identifying the SQL injection in the cookie.
2:09 - Explaining how to identify database variants using concatenation.
4:45 - Explaining the concept of exploiting error-based SQL injection.
9:17 - Extracting the database version number via the error message.
10:42 - Attempting to extract the password from the users table, running into truncation issues.
11:49 - Defeating the truncation using shorthand casting syntax, removing the cookie value, and concatenating everything.
13:01 - Extracting the passwords from the table, solving the lab.
15:03 - Outro
Twitter: twitter.com/0xTib3rius
Twitch: twitch.tv/0xTib3rius
Courses: courses.tib3rius.com
Udemy: udemy.com/user/tib3rius
Discord: discord.com/invite/4qrvKMh
Threads: threads.net/@0xtib3rius
LinkedIn: linkedin.com/in/tib3rius
Facebook: facebook.com/0xTib3rius
InfoSec Exchange: https://infosec.exchange/@tib3rius
Bluesky: https://bsky.app/profile/tib3rius.bsky.social










