MySQL (and the compatible MariaDB fork) is the database behind a large share of injectable web applications, so its dialect is worth knowing precisely. Several traits shape how injection plays out against it.
Comments are -- (the trailing space is required), #, and /* */. Versioned comments /*! ... */ execute their contents only on MySQL at or above an embedded version number, which doubles as a filter-evasion trick. String literals concatenate with CONCAT() rather than || (the || operator means logical OR unless PIPES_AS_CONCAT is set), and hex literals such as 0x7573657273 stand in for quoted strings when quotes are filtered.
Schema metadata lives in information_schema (databases in SCHEMATA, tables in TABLES, columns in COLUMNS), which is the backbone of blind and union extraction. database(), user(), and @@version identify the current context. Stacked queries are usually unavailable: the common PHP drivers (mysqli_query, PDO with emulation) send one statement per call, so techniques that depend on a second ;-separated statement rarely work here, unlike MSSQL or PostgreSQL.
File access is gated. LOAD_FILE() and SELECT ... INTO OUTFILE/DUMPFILE require the FILE privilege, and the secure_file_priv system variable restricts (or disables) the directories they can touch. These defaults decide whether file read, web-shell write, and UDF command execution are reachable.
Techniques#
- Enumeration: fingerprint the engine, version, current context, and privileges.
- Authentication bypass: subvert a login built from the credential fields.
- Union-based: append a
UNION SELECTto pull data into the visible response. - Error-based: force query output into a reflected error message.
- Boolean blind: infer data one bit at a time from true/false response differences.
- Time-based: infer data from conditional response delays.
- Out-of-band: exfiltrate over DNS or SMB when no channel is reflected.
- File read: read server files with
LOAD_FILE(). - Command execution: write web shells or load a UDF for OS commands.
- WAF bypass: reach
information_schema,version(), and keywords past filters.
References#
- MySQL Reference Manual:
information_schematables and string functions - OWASP Testing Guide: Testing for SQL Injection