Watch this video on YouTube
Determine the type of SQL injection: SELECT * FROM user WHERE name = 'x' AND userid IS NULL; --';