Detection is methodical: enumerate every parameter, send quote and boolean probes, and read the differences in responses and errors.
Every SQL injection is the same picture: text you type in the browser travels through the web app and becomes part of a command the database runs.