Abstract
Bruce Sqli Tester is an open-source Cybersecurity & Ethical Hacking project. SQLi tester for Bruce firmware (LilyGO T-Embed CC1101): error/time/boolean-based SQL injection detection from the device. Authorized testing only. JS, picto UI. It is built using JavaScript, ESP32. Key capabilities include: Target menu from a file — pick a target directly from sqli_targets.txt (label + URL), or type one manually. No long typing on the device; 3 detection methods over a clean baseline request:; error-based — a DB error string appears that wasn't in the baseline. The complete source code is publicly available on GitHub under the MIT License, making it a useful reference for students building a Cybersecurity & Ethical Hacking mini project or final-year project.
1. Introduction
SQLi tester for Bruce firmware (LilyGO T-Embed CC1101): error/time/boolean-based SQL injection detection from the device. Authorized testing only. JS, picto UI.
2. Objective
SQLi tester for Bruce firmware (LilyGO T-Embed CC1101): error/time/boolean-based SQL injection detection from the device. Authorized testing only. JS, picto UI.
This project demonstrates how JavaScript, ESP32 can be applied to a real-world Cybersecurity & Ethical Hacking problem.
3. Key Features / Modules
- Target menu from a file — pick a target directly from sqli_targets.txt (label + URL), or type one manually. No long typing on the device.
- 3 detection methods over a clean baseline request:
- error-based — a DB error string appears that wasn't in the baseline
- time-based (blind) — a SLEEP()/WAITFOR payload makes the response ~3 s slower
- boolean-based — AND 1=1 vs AND 1=2 give clearly different responses
- Exact test URL in the report — every finding shows the precise (URL-encoded) request that triggered it, ready to reproduce in a browser or curl.
- Picto UI — animated scanning screen (magnifier + radar + progress + live hit counter), flicker-free scrollable report.
4. Technology Stack
5. System Requirements
General requirements for this technology stack — check the README for exact versions.
- Node.js (LTS) and npm
- A modern web browser
- VS Code or any code editor
- Git (to clone the repository)
6. Installation & Setup
git clone https://github.com/koua29/bruce-sqli-tester.git
cd bruce-sqli-tester- Copy SQL Injection.js and sqli_targets.txt onto the SD card (e.g. into /scripts, or the SD root for the targets file).
- On the device: JS Interpreter → select SQL Injection.js (or add it to your favorites with bruce-launcher).
- Rotate = move, click = select/scan, long-press (ESC) or click = back.
label | http://host/page.php?id=1Full setup instructions are in the project README.
7. Future Enhancements
Suggested extensions you can add to make this your own project.
- Add logging and alert notifications (email / Telegram)
- Write a threat model document for the tool
- Package it with Docker for safe lab testing
8. Viva / Review Questions
Common questions examiners ask for projects in this domain.
- Which threat or attack does this project defend against?
- What detection or protection technique is used and what are its limits?
- How are false positives and false negatives handled?
- Which cryptographic algorithms or security standards are involved?
- What legal and ethical rules apply when testing a tool like this?
9. Source Code & License
This project is developed by koua29 and published on GitHub under the MIT License. Please follow the license terms and credit the original author when you use or modify this code.
Want to build this as your internship project?
Work on a Cybersecurity & Ethical Hacking project like this with mentor guidance, weekly reviews and an internship certificate from Training Trains, Erode — online or offline.
Apply for Cybersecurity & Ethical Hacking Internship