SQL Injection¶
Injecting SQL through unvalidated input to read, modify, or bypass the logic of a database-backed application.
Why It Matters¶
SQL injection remains one of the highest-impact web vulnerabilities: it can expose entire databases, bypass authentication, and sometimes lead to code execution on the database server. It appears wherever user input reaches a query without parameterization.
Reference¶
Approach¶
- Discover: send crafted input and watch for errors or changed behavior
- Exploit: confirm and extract data through the injection
- Assess: determine what data and privileges the injection exposes
- Report: document the vulnerability, impact, and remediation
Types¶
| Type | Description |
|---|---|
| In-band (UNION) | Uses UNION SELECT to append attacker-chosen results to the response |
| In-band (Error-based) | Reads data from database error messages |
| Blind (Boolean) | Infers data from true/false differences in the response |
| Blind (Time-based) | Infers data from how long a query takes (SLEEP) |
Authentication Bypass¶
Classic example where input is concatenated into the query. Supplying ' OR 1=1;-- as the username makes the WHERE clause always true:
-- intended
SELECT * FROM users WHERE username='%u%' AND password='%p%' LIMIT 1;
-- injected username: ' OR 1=1;--
SELECT * FROM users WHERE username='' OR 1=1;-- ...
UNION Data Extraction¶
Enumerate tables, then columns, then data from information_schema:
0 UNION SELECT 1,2,group_concat(table_name) FROM information_schema.tables WHERE table_schema='app_db'
0 UNION SELECT 1,2,group_concat(column_name) FROM information_schema.columns WHERE table_name='staff_users'
0 UNION SELECT 1,2,group_concat(username,':',password) FROM staff_users
Remediation¶
- Parameterized queries (prepared statements): the primary fix; keeps data out of the query structure
- Input validation: allowlist expected formats
- Least privilege: the application's database account should have only the access it needs
- Escaping: a secondary control, not a substitute for parameterization
Tools¶
| Tool | Use |
|---|---|
| sqlmap | Automated detection and exploitation |
| Burp Suite / OWASP ZAP | Manual testing and scanning |
How I Use It¶
I test by hand first to understand the injection point and the database, then use sqlmap to extract at scale once I have confirmed and scoped it. In the report I pair each finding with the parameterized-query fix, since that is the remediation developers can act on directly.