MySQL

MySQL (and the compatible MariaDB fork) is the database behind a large share of injectable web applications, so its dialect is worth knowing precisely. Several traits shape how injection plays out against it.

Comments are -- (the trailing space is required), #, and /* */. Versioned comments /*! ... */ execute their contents only on MySQL at or above an embedded version number, which doubles as a filter-evasion trick. String literals concatenate with CONCAT() rather than || (the || operator means logical OR unless PIPES_AS_CONCAT is set), and hex literals such as 0x7573657273 stand in for quoted strings when quotes are filtered.

Schema metadata lives in information_schema (databases in SCHEMATA, tables in TABLES, columns in COLUMNS), which is the backbone of blind and union extraction. database(), user(), and @@version identify the current context. Stacked queries are usually unavailable: the common PHP drivers (mysqli_query, PDO with emulation) send one statement per call, so techniques that depend on a second ;-separated statement rarely work here, unlike MSSQL or PostgreSQL.

File access is gated. LOAD_FILE() and SELECT ... INTO OUTFILE/DUMPFILE require the FILE privilege, and the secure_file_priv system variable restricts (or disables) the directories they can touch. These defaults decide whether file read, web-shell write, and UDF command execution are reachable.

Techniques#

  • Enumeration: fingerprint the engine, version, current context, and privileges.
  • Authentication bypass: subvert a login built from the credential fields.
  • Union-based: append a UNION SELECT to pull data into the visible response.
  • Error-based: force query output into a reflected error message.
  • Boolean blind: infer data one bit at a time from true/false response differences.
  • Time-based: infer data from conditional response delays.
  • Out-of-band: exfiltrate over DNS or SMB when no channel is reflected.
  • File read: read server files with LOAD_FILE().
  • Command execution: write web shells or load a UDF for OS commands.
  • WAF bypass: reach information_schema, version(), and keywords past filters.

References#

  • MySQL Reference Manual: information_schema tables and string functions
  • OWASP Testing Guide: Testing for SQL Injection

Cookie Consent

We use cookies to enhance your experience. Learn more