Application of Binary search in SQLI 06-18-2013, 12:59 PM
#1
![[Image: HChelpers_zps3210ab3a.png]](http://i1057.photobucket.com/albums/t387/MONETIZING/HChelpers_zps3210ab3a.png)
What is the binary search algorithm?
Quote:In computer science, a binary search or half-interval search algorithm finds the position of a specified value (the input "key") within a sorted array. In each step, the algorithm compares the input key value with the key value of the middle element of the array. If the keys match, then a matching element has been found so its index, or position, is returned. Otherwise, if the sought key is less than the middle element's key, then the algorithm repeats its action on the sub-array to the left of the middle element or, if the input key is greater, on the sub-array to the right. If the remaining array to be searched is reduced to zero, then the key cannot be found in the array and a special "Not found" indication is returned.Source: http://en.wikipedia.org/wiki/Binary_search_algorithm
How to utilize it?
I will be using a fictional SQL injection attack to explain this, so let's imagine we have found a vulnerable website http://www.domain.com/product.php?id=5. The id parameter is vulnerable to union injection and we're going to use order by to find out how many columns it has.
One method would be to start at 1 and count up, but this isn't very efficient if we're working with a lot of columns. This is when we utilize the binary search algorithm.
We start with a high number, in this case 100. If 100 fails we have determined that the correct number will be somewhere between 1 and 100
We will most likely now see an error like Unknown column '100' in 'order clause'
Code:
http://www.domain.com/product.php?id=5 order by 100Next we try 50. If we get the same error we now know it's also less than 50.
Code:
http://www.domain.com/product.php?id=5 order by 50Then we try with 25. Again we get the same error. So it's between 1 and 25 as well.
Code:
http://www.domain.com/product.php?id=5 order by 25We then try with 12, and the error is gone. No errors means that we are not exceeding the total column count. So now we know that it is equal to or higher than 12 and less than 25
Code:
http://www.domain.com/product.php?id=5 order by 12Since 12 is successful we reverse a little bit and we try 15. If this causes the error to return, the number is between 12 and 15
Code:
http://www.domain.com/product.php?id=5 order by 15When you are this close you can increase or decrease by one to find the answer
This might look difficult, but when you get the hang of it you will notice that this approach is far more efficient than increase or decrease by one.
Final words
I hope you found this tutorial helpful, and as always, if you have any comments or questions don't hesitate to reply. I will try to answer the best I can.




![[+]](https://sinister.li/images/modern/collapse_collapsed.png)
![[Image: OilyCostlyEwe.gif]](http://fat.gfycat.com/OilyCostlyEwe.gif)
![[Image: 2YpkRjy.png]](http://i.imgur.com/2YpkRjy.png)
