PortSwigger / BChecks

BChecks collection for Burp Suite Professional and Burp Suite Enterprise Edition
https://portswigger.net/burp/documentation/scanner/bchecks
GNU Lesser General Public License v3.0
588 stars 104 forks source link

How can I detect a time-based Sql injection #157

Closed f4ct0r closed 6 months ago

f4ct0r commented 6 months ago

Is there a way to detect time-based sql injection?

Michelle-PortSwigger commented 6 months ago

You can't currently use BChecks for time-based attacks, but we are already tracking this over at https://github.com/PortSwigger/BChecks/issues/32 and have added your vote for the feature :)