LogoAwesome Skills
  • Search
  • Category
  • Tag
  • Blog
LogoAwesome Skills
LogoAwesome Skills

Discover Open-Source Agent Skills for AI Coding Assistants

Product

  • Search
  • Category
  • Tag
  • Blog

Resources

  • Claude Skill Docs
  • Antigravity Skills Docs

Tools

  • Claude Code
  • OpenCode
  • Cursor
  • Codex
  • Antigravity

Company

  • Privacy Policy
  • Terms of Service
  • Sitemap

©2026 Awesome Skills. All rights reserved.

Privacy PolicyTerms
Back to Skills

sqli-sql-injection

SQL injection playbook. Use when input reaches SQL queries, authentication logic, sorting, filtering, reporting, or DB-specific blind and out-of-band execution paths.

1,256stars173forksUpdated 7/1/2026
Security#offensive-security#security#penetration-testing#web-security#sql-injection

Security Assessment

Critical Risk(0/100)

Detected risks:

Persistence([SCENARIOS.md] crontab)
Remote Code Execution([SQLMAP_ADVANCED.md] exec(, [SQLMAP_ADVANCED.md] EXEC ()
Secret Exposure([SCENARIOS.md] password=, [SQLMAP_ADVANCED.md] token=, [SQLMAP_ADVANCED.md] password=)
Sensitive File Access([SCENARIOS.md] .env, [SQLMAP_ADVANCED.md] /etc/passwd)
Security Score0/100

About sqli-sql-injection

An expert-level SQL injection attack playbook for security testing, meant to be used when input reaches SQL queries, authentication logic, sorting, filtering, reporting, or database-specific blind and out-of-band execution paths. It assumes the fundamentals of UNION, error-based, and boolean-blind injection are already known and concentrates on advanced material: per-database exploitation, out-of-band exfiltration, second-order injection, parameterized-query bypass scenarios, filter evasion, and escalation toward the operating system. It routes to companion files for deeper material, using SCENARIOS.md for real-world CVE cases and framework-specific exploitation such as ThinkPHP5 array-key injection and a Django GIS Oracle case, and SQLMAP_ADVANCED.md for SQLMap tamper-script matrices, technique, risk, and level combinations, second-order and OS-level options, and GraphQL plus SQL injection. It also cross-references a ghost-bits-cast-attack skill for Java with Jackson backends where SQL keywords are WAF-blocked.

The quick-start guidance gives a first-pass payload family table keyed by situation such as a login or boolean branch, a numeric parameter, ORDER BY sorting, visible errors, no output, or heavy filtering, along with a small stable payload set and DBMS routing hints that map error strings to a likely database and a good next move. Detection emphasizes behavioral differences over errors, and stresses testing every parameter type including URL query, POST body, JSON fields, XML values, and HTTP headers such as X-Forwarded-For, User-Agent, Referer, and cookie values. Fingerprinting snippets cover version and user functions across MySQL, MSSQL, Oracle, and PostgreSQL, and UNION extraction covers column-count determination, type detection with NULLs, and database-specific string concatenation.

Blind sections detail boolean and time-based inference with per-database payloads such as WAITFOR DELAY, SLEEP, pg_sleep, and Oracle CASE or UTL_HTTP techniques, and a critical out-of-band exfiltration section covers MSSQL OpenRowSet over ports 80 or 443, Oracle UTL_HTTP, UTL_INADDR DNS exfiltration, UTL_SMTP and UTL_TCP, and MySQL DNS via LOAD_FILE with Windows UNC paths. It advises completing first-pass validation locally before loading additional payload skills when only a suspicious SQL sink has been confirmed. Given its content, it is an offensive security resource for penetration testing and authorized assessment work.

FAQ

Who is this playbook aimed at, and what does it assume?

It targets advanced SQL injection during security testing and assumes UNION, error-based, and boolean-blind fundamentals are already known, focusing instead on per-database exploitation, out-of-band exfiltration, second-order injection, filter evasion, and OS escalation.

How does it recommend detecting injection points?

It notes most SQLi is found by behavioral differences rather than errors, for example different responses to a single quote versus a doubled quote, arithmetic being evaluated, or boolean conditions changing results, and it says to test all parameter types including URL, POST, JSON, XML, and HTTP headers.

When should I use out-of-band exfiltration?

Use it when blind injection provides no time or boolean indicator, or when batch queries cannot return data inline; the guide covers MSSQL OpenRowSet, Oracle UTL_HTTP, UTL_INADDR, UTL_SMTP and UTL_TCP, and MySQL DNS via LOAD_FILE.

What are the companion files for?

SCENARIOS.md covers real-world CVE cases and framework-specific exploitation like ThinkPHP5 and Django GIS Oracle, while SQLMAP_ADVANCED.md covers SQLMap tamper scripts, technique, risk, and level options, second-order and OS-level exploitation, and GraphQL plus SQL injection.

How do I know which database I am dealing with?

DBMS routing hints map error strings to a likely database, for example a MySQL syntax error, Microsoft OLE DB Provider for MSSQL, a PG prefix for PostgreSQL, or an ORA- prefix for Oracle, and suggest a good next move for each.

All Files

3 files
SCENARIOS.md14.6 KB
View
SQLMAP_ADVANCED.md17.5 KB
View
SKILL.md15.0 KB
View

Install sqli-sql-injection

Download and extract the skill files to your .claude/skills/ directory.

Quick Setup:

  1. Copy the skill folder to .claude/skills/
  2. Claude will automatically detect and use the skill

Repository

yaklang/hack-skills

Related Skills

referral-program

2,132

agentmail-cli

22

codex

3,038

content-modeling

192