Microsoft SQL Server runs the T-SQL dialect, and a successful injection against it is often high-impact because command execution, file access, and lateral movement to other servers are all reachable from SQL.
Comments are -- and /* */. Strings concatenate with + (and CONCAT() from 2012), and CHAR()/NCHAR() build strings without quotes. MSSQL commonly permits stacked queries: a ;-separated second statement usually runs, which makes EXEC, DDL, and configuration changes reachable from one injection. The catalog lives in the sys schema (sys.databases, sys.tables, sys.columns, sys.sql_logins) and in information_schema, and server metadata comes from @@version, SERVERPROPERTY(), DB_NAME(), and SYSTEM_USER.
Two dialect details shape payloads. There is no LIMIT; row limiting is TOP n or OFFSET ... FETCH (2012+), so blind and union payloads use TOP 1. And aggregation into one cell uses STRING_AGG() (2017+) or the FOR XML PATH('') trick on older versions, in place of MySQL's GROUP_CONCAT.
Impact depends on the login's server role. A member of sysadmin can enable and run xp_cmdshell, read and write files, and pivot through linked servers, so IS_SRVROLEMEMBER('sysadmin') is checked early.
Techniques#
- Enumeration: version, current context, and server role.
- Authentication bypass: subvert a login built from the credential fields.
- Union-based: append a
UNION SELECTwith matching types. - Error-based: leak values through conversion errors.
- Blind: infer data from boolean response differences.
- Time-based: infer data with
WAITFOR DELAY. - Stacked queries: run extra statements after a
;. - Privileges: read the login's server and database roles.
- Database credentials: dump login password hashes.
- File manipulation: read and write files with OPENROWSET and bcp.
- Out-of-band: exfiltrate and capture hashes over UNC with
xp_dirtree. - Command execution: run OS commands with
xp_cmdshellor OLE automation. - Trusted links: pivot to linked servers with
openqueryand RPC.
References#
- Microsoft SQL Server Documentation: system catalog views, functions, configuration
- OWASP Testing Guide: Testing for SQL Injection