This post from Pauldotcom explains how to perform Blind SQL injection attacks against DVWA (Damn Vulnerable Web App) in order to extract the usernames and  password hashes from the database.