← All concepts
SQL / command injection

Understanding SQL / command injection

What it is

Injection is untrusted input reaching an interpreter as code rather than as data. When a value you supply is concatenated into a SQL query or a shell command, characters that mean something to that interpreter let you change what it does — read tables you should not, or run commands the app never intended.

How you approach it

  1. Feed the input a character that is special to a query — a quote, a semicolon. Does the error, or the change in behaviour, tell you it reached the interpreter raw?
  2. Once you are in the syntax, you decide what runs. For SQL, a UNION or a boolean condition; for a shell, a separator and a second command.
  3. The flag lives in a table or a file the intended query never touches. Redirect the query to read it.

How it gets fixed

Input was concatenated into the interpreter instead of being passed as a bound parameter, so crafted syntax changed the statement itself. That let the query — or the command — reach data outside its intended scope, where the flag sat. The fix is parameterised queries and never building a command line from user input.

Practise it

Every lab in the SQL / command injection category drills exactly this. Start at Apprentice and work up.

Practise it

ApprenticeSQL / command injection

A quote that breaks the login query

Break out of a query or a shell command through unescaped input.

10 pts · 20 minStart →
ApprenticeSQL / command injection

The search filter that trusts your input

Break out of a query or a shell command through unescaped input.

10 pts · 20 minStart →
PractitionerSQL / command injection

UNION-selecting the users table

Break out of a query or a shell command through unescaped input.

25 pts · 45 minStart →
PractitionerSQL / command injection

Error-based extraction from a chatty endpoint

Break out of a query or a shell command through unescaped input.

25 pts · 45 minStart →
ExpertSQL / command injection

Boolean-blind, one bit at a time

Break out of a query or a shell command through unescaped input.

50 pts · 90 minStart →
ExpertSQL / command injection

Time-based extraction from a silent endpoint

Break out of a query or a shell command through unescaped input.

50 pts · 90 minStart →