SELECT ... INTO DUMPFILE '/path/file' writes a single row to a file with no row or column formatting, so the bytes land exactly as selected. This is the binary-safe counterpart to INTO OUTFILE: OUTFILE adds terminators and escaping that would corrupt a binary, while DUMPFILE does not. Its main use is dropping a compiled artifact, most often the shared library for a command-execution UDF.
The content is supplied as a hex literal so arbitrary bytes survive transport, and the target is the server's plugin directory:
' UNION SELECT 0x7f454c46... INTO DUMPFILE '/usr/lib/mysql/plugin/lib_mysqludf_sys.so'--
Find the plugin directory first so the library lands where CREATE FUNCTION will look for it:
' UNION SELECT @@plugin_dir,NULL,NULL--
DUMPFILE writes only one row, so it cannot dump a multi-row result, and like OUTFILE it requires FILE privilege, a permissive secure_file_priv, a writable destination, and a non-existent target file. With the library in place, the UDF is registered and called as shown in the sys_exec page.
References#
- MySQL Reference Manual: SELECT INTO DUMPFILE,
plugin_dir,secure_file_priv - OWASP Testing Guide: Testing for SQL Injection