PostgreSQL

PostgreSQL has a rich dialect that changes several injection techniques compared with MySQL, and it tends to reward a successful injection with more power because its file and command primitives are built in.

Comments are -- and /* */. Strings concatenate with the standard || operator, and dollar-quoting ($$text$$ or $tag$text$tag$) provides a quote-free string literal that is useful for evading filters. Type handling is strict: UNION requires the column types on both sides to match or be explicitly cast, so NULL::text and value::text casts appear throughout union payloads.

Unlike the common MySQL drivers, PostgreSQL commonly allows stacked queries: a ;-separated second statement often executes, which opens CREATE, COPY, and DDL from a single injection. The catalog lives in both the SQL-standard information_schema and the native pg_catalog (pg_tables, pg_class, pg_namespace, pg_roles, pg_database), and pg_catalog is often reachable when information_schema is filtered.

Power depends on the role. A superuser can read files with pg_read_file(), write them with COPY ... TO, and run OS commands with COPY ... FROM PROGRAM. On version 11 and later a non-superuser reaches each primitive only through the matching predefined role: pg_read_server_files for reads, pg_write_server_files for COPY ... TO writes, and pg_execute_server_program for program execution. Checking current_setting('is_superuser') and these role memberships early decides which routes are open.

Techniques#

References#

  • PostgreSQL Documentation: system catalogs, functions, and COPY
  • OWASP Testing Guide: Testing for SQL Injection

Cookie Consent

We use cookies to enhance your experience. Learn more