IBM Db2

IBM Db2 (the LUW edition on Linux, Unix, and Windows) has a distinctive dialect, and this page's payloads target it rather than Db2 for z/OS or Db2 for i, which differ.

Like Oracle, every SELECT needs a FROM, and the single-row pseudo-table is SYSIBM.SYSDUMMY1 (Db2's DUAL). There is no LIMIT; row limiting is FETCH FIRST n ROWS ONLY. Strings concatenate with || or CONCAT(), and comments are -- and /* */. Identity comes from the special registers CURRENT USER, SESSION_USER, SYSTEM_USER, CURRENT SCHEMA, and CURRENT SERVER.

The catalog lives in the SYSCAT views (SYSCAT.TABLES with TABSCHEMA/TABNAME, SYSCAT.COLUMNS with COLNAME, SYSCAT.DBAUTH for grants) and the older SYSIBM.SYSTABLES. Version and service level come from SYSIBMADM.ENV_INST_INFO and SYSIBMADM.ENV_SYS_INFO, not a version() function. Aggregation into one cell uses LISTAGG (Db2 9.7 and later) or XMLAGG.

Two limits shape technique choice. Db2 has no SLEEP/WAITFOR, so time-based inference relies on a deliberately heavy query, and its error messages rarely echo an arbitrary query result, so error-based is weak and boolean or time-based inference is the dependable blind channel. Stacked queries are generally unavailable through the standard CLI/JDBC drivers.

Techniques#

  • Enumeration: service level, special registers, and the SYSCAT catalog.
  • Authentication bypass: subvert a login built from the credential fields.
  • Union-based: append a UNION SELECT ... FROM SYSIBM.SYSDUMMY1.
  • Error-based: the narrow Db2 error surface and what it can leak.
  • Blind: infer data from boolean response differences.
  • Time-based: infer data with a heavy query, since Db2 has no SLEEP.
  • Privileges: read authorities and grants from SYSCAT.DBAUTH.
  • Command execution: external routines, and the limits of ADMIN_CMD.
  • DIOS: single-request dumps with XMLAGG/LISTAGG.
  • WAF bypass: CHR(), concatenation, and hex past filters.

References#

  • IBM Db2 SQL Reference: special registers, catalog views, built-in functions
  • OWASP Testing Guide: Testing for SQL Injection

Cookie Consent

We use cookies to enhance your experience. Learn more