> For the complete documentation index, see [llms.txt](https://0xkourama.gitbook.io/blog/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://0xkourama.gitbook.io/blog/vulnerabilities-and-techniques/web-vulnerabilities/sql-injection-or-sqli.md).

# SQL Injection | SQLI

## Intro to SQL Injection <a href="#intro-to-sqli" id="intro-to-sqli"></a>

<figure><img src="https://3344169606-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjoHbOFRbwrmbD6PvIUkf%2Fuploads%2FbaHApoGA7Uy4aiPy6idy%2Fimage.png?alt=media&amp;token=7d6dea37-d8cf-4879-814f-ce31f07eeb58" alt=""><figcaption></figcaption></figure>

### 📚 What is **SQLI**? <a href="#what-is-sqli" id="what-is-sqli"></a>

(**SQLi**) attack exploits the **injection of SQL commands** into the **SQL queries** of a web application.

A successful **SQLi** attack lets **malicious hackers** **access** and **manipulate** a web application’s backend **database**.

To interact with **databases**, entities such as **systems operators**, **programmers**, **applications**, and **web applications** use the Structured Query Language (**SQL**).

You Can Know More About SQL [HERE](https://www.w3schools.com/sql/)

***

**SQL Like:**

![](https://i.imgur.com/BLT3hCD.png)

**SQL** is a powerful interpreted language used to **extract and manipulate data from a database.**

***

### 🤔 Why SQLI happen? <a href="#why-sqli-happen" id="why-sqli-happen"></a>

A web developer's **trust** in **users** and **missing** to put any **input validation** or **output encoding** prevent users from interacting with database queries

**Modern web frameworks** nowadays solved this problem with **predefined functions** that defend against sqli like **Laravel** framework based on **php**

**Example:**

![](https://i.imgur.com/Mo7Gvmp.png)

$id Parameter is vulnerable to sqli

![](https://i.imgur.com/xosrZuD.png)

try to provide the id parameter with the values payload above to achieve your sqli attack

***

### 🔎 Finding SQL Injection <a href="#finding-sql-injection" id="finding-sql-injection"></a>

The most straightforward way to find SQL injections within a web application is to probe its inputs with **characters that are known to cause the SQL query to be syntactically invalid** and thus forcing the web application to **return** an **error**.

Input parameters are carried through **GET** and **POST** requests,**HEADERS,** and **COOKIES**. So, we have to check all the channels where data is retrieved from the client.

***

### 🌀 What are the types of **SQLI**? <a href="#what-are-types-of-sqli" id="what-are-types-of-sqli"></a>

![](https://i.imgur.com/4caA7ow.png)

### <mark style="color:red;">**In-band SQL injections:**</mark>

leverage the **same channel** used to inject the SQL code (i.e., the pages generated by the web application).

#### <mark style="color:red;">**1. Error-Based SQL injection attack:**</mark>

The penetration tester tries to force the **DMBS** to **output an error message** and then uses that information to perform data exfiltration.

#### <mark style="color:red;">**2. Union-Based SQL injection attack:**</mark>

The ability of the user to **add another sql query** to the original query to make some sql operation to **retrieve data** like this:

### <mark style="color:red;">**Blind SQL injection:**</mark>

This does not reflect the results of the injection on the output. In this case, the penetration tester must find an inference method to exploit the vulnerability

#### <mark style="color:red;">**1. Blind Boolean-Based SQLI:**</mark>  Currently, most production websites do not display such errors. This happens both because of the usability of the application; it is useless to display errors to end users who cannot understand or fix them, and to achieve security through obscurity.

IF SQL Statement is **TRUE**  ✅  **Render page Well.**\
IF SQL Statement is **FALSE** ❌ **Render page Bad.**<br>

<mark style="color:red;">**2. Blind Time-Based SQLI**</mark>\
\
Time is used to infer a TRUE condition from a FALSE condition.

This SQL syntax is used:

```sql
%SQL condition% waitfor delay '0:0:5’
If condition true response will wait 5 seconds
```

***

### 🌀 What is the impact of a successful SQL injection attack? <a href="#what-is-the-impact-of-a-successful-sql-injection-attack" id="what-is-the-impact-of-a-successful-sql-injection-attack"></a>

A **successful** SQL injection attack can result in:

**unauthorized access to sensitive data such as**

1. **passwords**
2. **credit card details**
3. **personal user information.**

Many high-profile data breaches in recent years have been the result of SQL injection attacks, leading to reputational damage and regulatory fines. In **some cases**, an attacker can obtain a **persistent backdoor** into an organization’s systems, leading to a long-term compromise that can go unnoticed for an extended period.

***

### SQL injection examples <a href="#sql-injection-examples" id="sql-injection-examples"></a>

* [Retrieving hidden data](https://portswigger.net/web-security/sql-injection#retrieving-hidden-data), where you can modify an SQL query to return additional results.
* [Subverting application logic](https://portswigger.net/web-security/sql-injection#subverting-application-logic), where you can change a query to interfere with the application’s logic.
* [UNION attacks](https://portswigger.net/web-security/sql-injection/union-attacks), where you can retrieve data from different database tables.
* [Examining the database](https://portswigger.net/web-security/sql-injection/examining-the-database), where you can extract information about the version and structure of the database.
* [Blind SQL injection](https://portswigger.net/web-security/sql-injection/blind), where the results of a query you control are not returned in the application’s responses.

***

### 🐍 SQLMAP <a href="#sqlmap" id="sqlmap"></a>

**sqlmap** is an open-source penetration testing tool developed by Bernardo Damele Assumpcao Guimaraes and Miroslav Stampar that automates the process of detecting and exploiting SQL injection flaws and taking over database servers. It comes with a powerful detection engine, many niche features for the ultimate penetration tester, and a broad range of switches lasting from database fingerprinting, and fetching data from the database to accessing the underlying file system and executing commands on the operating system via out-of-band connections.

you can automation find many sqli with **SQLMAP**

![](https://i.imgur.com/hnHTLp2.png)

Automate using sqlmap

***

### 🔬 Labs <a href="#labs" id="labs"></a>

[**Portswigger**](https://portswigger.net/web-security/sql-injection)

[**OWASP Broken Web Applications Project**](https://sourceforge.net/projects/owaspbwa/)**:** \
Install this Machine and will have a lot of Labs like DVWA, BWAPP, Webgoat, etc

You can find my solution for portswigger [**HERE**](https://equatorial-soldier-1bb.notion.site/PortSwigger-Labs-473fe73ef69a4c07aebb7a48388daa38)

***

### 📕 Referance <a href="#referance" id="referance"></a>

[**Portswigger**](https://portswigger.net/web-security/sql-injection)

[**OWASP**](https://owasp.org/www-community/attacks/SQL_Injection)

[**PayloadsAllTheThings**](https://github.com/swisskyrepo/PayloadsAllTheThings)

[**hacktricks**](https://book.hacktricks.xyz/pentesting-web/sql-injection)

[**hackingarticles**](https://www.hackingarticles.in/beginner-guide-sql-injection-part-1/)
