We are no longer faced with a new threats to our web applications from SQL injection attacks, and the number of attacks is steadily declining as users become more aware of the risks. Almost all web applications are still vulnerable to advanced SQL injection attacks. A regular expression based query structure in this paper describes a new method for transforming blind SQL injection into a more effective and faster technique than traditional blind SQL injection. When we understand the cause of an attack, we are able to find more effective treatment.