Posts

Showing posts with the label SQLi

SQL injection attack, listing the database contents on Oracle

Image
SQL Injection Attack, Listing the Database Contents on Oracle This lab demonstrates a UNION-based SQL injection vulnerability in an application backed by an Oracle database. The objective is to identify how user input is incorporated into a dynamically constructed SQL query and progressively exploit it to enumerate database structure and extract sensitive data. Oracle behaves slightly differently from other database systems such as MySQL or PostgreSQL. For example, it uses the dual table for selecting literal values and follows specific constraints in UNION-based queries. Understanding these characteristics is important when performing SQL injection analysis in Oracle environments. The vulnerability in this lab arises from improper input handling, where user-supplied data is directly embedded into SQL queries without sanitization or parameterization. This allows an attacker to manipulate query structure and retrieve unauthorized data. Observed Payloads and Testing Methodology Th...

SQL injection attack, listing the database contents on non-Oracle databases

Image
     A typical SQL injection lab focused on “listing database contents” is designed to simulate how attackers move from a simple injection point to full database enumeration. In non-Oracle database systems such as MySQL, PostgreSQL, and Microsoft SQL Server, this process heavily relies on UNION-based SQL injection combined with metadata exploration . The key idea behind this type of lab is not simply to extract data, but to understand how relational databases expose internal structure through system catalogs. Once an attacker can manipulate a query using UNION, they can gradually reconstruct the database schema, identify tables, discover columns, and finally extract sensitive application data. In real-world applications, this becomes possible when user input is directly concatenated into SQL queries. Instead of being treated as data, the input becomes part of the executable query structure, allowing the attacker to influence how the database executes logic. UNION Inject...

SQL injection attack, querying the database type and version on MySQL and Microsoft

Understanding Database Fingerprinting in SQL Injection This lab focuses on using SQL injection to identify the backend database type and extract its version, specifically for MySQL and Microsoft SQL Server. The core idea is not just exploitation, but understanding how different database engines respond to manipulated queries. In real applications, a vulnerable query might look like: SELECT id, name, price FROM products WHERE id = '1' When user input is not properly sanitized, this becomes injectable, allowing an attacker to modify its structure and append additional SQL logic. The goal of this lab is to transform that input into a controlled SQL query that reveals system information, such as the database version. UNION-Based SQL Injection and Query Structure The main technique used is UNION-based SQL injection. UNION allows combining results from two SELECT statements: SELECT id, name FROM products UNION SELECT username, password FROM users In SQL injection, this becomes danger...

UNION-Based SQL Injection: Column Enumeration, Output Mapping, and Data Extraction Workflow

In a UNION-based SQL injection scenario, the first required step is determining the number of columns returned by the original SQL query. This requirement exists because relational database engines enforce strict structural validation before executing a UNION operation. When a query is parsed, the database first validates each SELECT statement independently, and only then attempts to merge result sets. At this stage, column count and data type compatibility are checked. If either condition fails, execution is halted before any data is returned. Because the attacker does not have access to the backend SQL statement, they must infer this structure indirectly through application responses. For instance, if the backend query is conceptually SELECT name, price, description FROM products WHERE category = 'x' , the attacker’s goal is to discover that three columns exist. This is done through iterative probing using UNION SELECT payloads with increasing column counts. A mismatch typica...

SQLi querying the database type and version on Oracle

Oracle SQL Injection: UNION-Based Data Extraction and Database Version Fingerprinting SQL injection is a critical vulnerability that arises when user input is embedded directly into SQL queries without proper sanitization or parameterization. In Oracle Database environments, this issue takes on unique characteristics due to the database’s strict syntax rules and its reliance on system-defined objects such as dual and dynamic performance views. This analysis focuses on a UNION-based SQL injection scenario in an Oracle backend, where the objective is to understand query structure and extract database version information from internal system metadata. The process demonstrates how attackers methodically infer query behavior and leverage Oracle-specific constructs to retrieve sensitive information such as version strings. Understanding Oracle-Specific Behavior Oracle databases differ significantly from other relational database systems in both structure and query execution rules. One of...