| name | exploiting-sql-injection-vulnerabilities |
| description | Use when identifying and exploiting SQL injection vulnerabilities in web applications during authorized penetration tests using manual techniques and automated tools like sqlmap. The tester detects injection points through error-based, union-based, blind boolean, and time-based blind techniques across all major database engines (MySQL, PostgreSQL, MSSQL, Oracle) to demonstrate data extraction, authentication bypass, and potential remote code execution. |
| domain | cybersecurity |
| tags | ["SQL-injection","sqlmap","database-security","OWASP-A03","injection-testing"] |
| subdomain | penetration-testing |
| version | 1.0.0 |
| author | oyi77 |
| license | Apache-2.0 |
| nist_csf | ["ID.RA-01","ID.RA-06","GV.OV-02","DE.AE-07"] |
Exploiting Sql Injection Vulnerabilities
Overview
Cybersecurity skill for exploiting sql injection vulnerabilities. Follows industry best practices and security standards.
When to Use
Trigger phrases:
-
"exploiting sql injection vulnerabilities"
-
"Identifies and exploits SQL injection vulnerabilities in web applications during"
-
Testing web application input parameters for SQL injection vulnerabilities during an authorized penetration test
-
Validating that parameterized queries and input sanitization are properly implemented across all database interactions
-
Demonstrating the business impact of a confirmed SQL injection vulnerability by extracting sensitive data
-
Verifying that WAF rules and input validation controls effectively block SQL injection payloads
-
Testing stored procedures, dynamic SQL, and ORM bypass scenarios in enterprise applications
Do not use against databases without written authorization, for extracting or exfiltrating actual customer data beyond what is needed for proof of concept, or against production databases where exploitation could corrupt data integrity.
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- Written authorization specifying the target application and permissible level of exploitation (detection only vs. full exploitation)
- Burp Suite Professional configured as an intercepting proxy to capture and modify HTTP requests
- sqlmap installed with current version for automated detection and exploitation
- Knowledge of the target database engine (MySQL, PostgreSQL, MSSQL, Oracle) or ability to fingerprint it
- Test accounts at various privilege levels to test injection in authenticated contexts
Workflow
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": ,
}
() -> :
{k: re.findall(v, text) k, v IOC_PATTERNS.items()}