PostgreSQL has a rich dialect that changes several injection techniques compared with MySQL, and it tends to reward a successful injection with more power because its file and command primitives are built in.
Comments are -- and /* */. Strings concatenate with the standard || operator, and dollar-quoting ($$text$$ or $tag$text$tag$) provides a quote-free string literal that is useful for evading filters. Type handling is strict: UNION requires the column types on both sides to match or be explicitly cast, so NULL::text and value::text casts appear throughout union payloads.
Unlike the common MySQL drivers, PostgreSQL commonly allows stacked queries: a ;-separated second statement often executes, which opens CREATE, COPY, and DDL from a single injection. The catalog lives in both the SQL-standard information_schema and the native pg_catalog (pg_tables, pg_class, pg_namespace, pg_roles, pg_database), and pg_catalog is often reachable when information_schema is filtered.
Power depends on the role. A superuser can read files with pg_read_file(), write them with COPY ... TO, and run OS commands with COPY ... FROM PROGRAM. On version 11 and later a non-superuser reaches each primitive only through the matching predefined role: pg_read_server_files for reads, pg_write_server_files for COPY ... TO writes, and pg_execute_server_program for program execution. Checking current_setting('is_superuser') and these role memberships early decides which routes are open.
Techniques#
- Enumeration: fingerprint the version, current context, and role.
- Authentication bypass: subvert a login built from the credential fields.
- Union-based: append a
UNION SELECTwith matching casts. - Error-based: leak values through type-cast errors.
- Boolean blind: infer data from true/false response differences.
- Time-based: infer data from
pg_sleepdelays. - Stacked queries: run extra statements after a
;. - Privileges: read the role and its grants.
- File manipulation: read and write files with
pg_read_fileandCOPY. - Out-of-band: exfiltrate over DNS via
COPY ... PROGRAM. - Command execution: run OS commands through
COPY PROGRAMor an untrusted-language function. - WAF bypass:
CHR(), dollar-quoting, and catalog alternatives past filters.
References#
- PostgreSQL Documentation: system catalogs, functions, and COPY
- OWASP Testing Guide: Testing for SQL Injection