Full documentation of a TryHackMe SQL Injection lab, completed as part of the Zaio Institute of Technology cybersecurity bootcamp. Write-up includes methodology, findings, screenshots, and a GRC/POPIA compliance lens tying technical vulnerabilities to real-world regulatory impact.
- Authentication bypass via SQL injection
- Union-based SQLi
- Error-based SQLi
- Blind SQL Injection (Boolean and time-based)
- SQL injection prevention and remediation
Each task is mapped to its potential impact under POPIA (Protection of Personal Information Act), including data exposure risk, breach notification obligations, and the internal control failures an auditor would flag.
Full lab journal: MbanjwaNdumiso_SQLi_Journal.docx
- TryHackMe
- Web browser
- SQL injection payloads
Ndumiso Mbanjwa — Cybersecurity Bootcamp Student, Zaio Institute of Technology