SQL injection playbook. Use when input reaches SQL queries, authentication logic, sorting, filtering, reporting, or DB-specific blind and out-of-band execution paths.
Detected risks:
An expert-level SQL injection attack playbook for security testing, meant to be used when input reaches SQL queries, authentication logic, sorting, filtering, reporting, or database-specific blind and out-of-band execution paths. It assumes the fundamentals of UNION, error-based, and boolean-blind injection are already known and concentrates on advanced material: per-database exploitation, out-of-band exfiltration, second-order injection, parameterized-query bypass scenarios, filter evasion, and escalation toward the operating system. It routes to companion files for deeper material, using SCENARIOS.md for real-world CVE cases and framework-specific exploitation such as ThinkPHP5 array-key injection and a Django GIS Oracle case, and SQLMAP_ADVANCED.md for SQLMap tamper-script matrices, technique, risk, and level combinations, second-order and OS-level options, and GraphQL plus SQL injection. It also cross-references a ghost-bits-cast-attack skill for Java with Jackson backends where SQL keywords are WAF-blocked.
The quick-start guidance gives a first-pass payload family table keyed by situation such as a login or boolean branch, a numeric parameter, ORDER BY sorting, visible errors, no output, or heavy filtering, along with a small stable payload set and DBMS routing hints that map error strings to a likely database and a good next move. Detection emphasizes behavioral differences over errors, and stresses testing every parameter type including URL query, POST body, JSON fields, XML values, and HTTP headers such as X-Forwarded-For, User-Agent, Referer, and cookie values. Fingerprinting snippets cover version and user functions across MySQL, MSSQL, Oracle, and PostgreSQL, and UNION extraction covers column-count determination, type detection with NULLs, and database-specific string concatenation.
Blind sections detail boolean and time-based inference with per-database payloads such as WAITFOR DELAY, SLEEP, pg_sleep, and Oracle CASE or UTL_HTTP techniques, and a critical out-of-band exfiltration section covers MSSQL OpenRowSet over ports 80 or 443, Oracle UTL_HTTP, UTL_INADDR DNS exfiltration, UTL_SMTP and UTL_TCP, and MySQL DNS via LOAD_FILE with Windows UNC paths. It advises completing first-pass validation locally before loading additional payload skills when only a suspicious SQL sink has been confirmed. Given its content, it is an offensive security resource for penetration testing and authorized assessment work.
It targets advanced SQL injection during security testing and assumes UNION, error-based, and boolean-blind fundamentals are already known, focusing instead on per-database exploitation, out-of-band exfiltration, second-order injection, filter evasion, and OS escalation.
It notes most SQLi is found by behavioral differences rather than errors, for example different responses to a single quote versus a doubled quote, arithmetic being evaluated, or boolean conditions changing results, and it says to test all parameter types including URL, POST, JSON, XML, and HTTP headers.
Use it when blind injection provides no time or boolean indicator, or when batch queries cannot return data inline; the guide covers MSSQL OpenRowSet, Oracle UTL_HTTP, UTL_INADDR, UTL_SMTP and UTL_TCP, and MySQL DNS via LOAD_FILE.
SCENARIOS.md covers real-world CVE cases and framework-specific exploitation like ThinkPHP5 and Django GIS Oracle, while SQLMAP_ADVANCED.md covers SQLMap tamper scripts, technique, risk, and level options, second-order and OS-level exploitation, and GraphQL plus SQL injection.
DBMS routing hints map error strings to a likely database, for example a MySQL syntax error, Microsoft OLE DB Provider for MSSQL, a PG prefix for PostgreSQL, or an ORA- prefix for Oracle, and suggest a good next move for each.
Quick Setup:
.claude/skills/Repository
yaklang/hack-skills