MSSQL

Microsoft SQL Server runs the T-SQL dialect, and a successful injection against it is often high-impact because command execution, file access, and lateral movement to other servers are all reachable from SQL.

Comments are -- and /* */. Strings concatenate with + (and CONCAT() from 2012), and CHAR()/NCHAR() build strings without quotes. MSSQL commonly permits stacked queries: a ;-separated second statement usually runs, which makes EXEC, DDL, and configuration changes reachable from one injection. The catalog lives in the sys schema (sys.databases, sys.tables, sys.columns, sys.sql_logins) and in information_schema, and server metadata comes from @@version, SERVERPROPERTY(), DB_NAME(), and SYSTEM_USER.

Two dialect details shape payloads. There is no LIMIT; row limiting is TOP n or OFFSET ... FETCH (2012+), so blind and union payloads use TOP 1. And aggregation into one cell uses STRING_AGG() (2017+) or the FOR XML PATH('') trick on older versions, in place of MySQL's GROUP_CONCAT.

Impact depends on the login's server role. A member of sysadmin can enable and run xp_cmdshell, read and write files, and pivot through linked servers, so IS_SRVROLEMEMBER('sysadmin') is checked early.

Techniques#

References#

  • Microsoft SQL Server Documentation: system catalog views, functions, configuration
  • OWASP Testing Guide: Testing for SQL Injection

Cookie Consent

We use cookies to enhance your experience. Learn more