BBQSQL
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
bbqsql is a blind SQL injection exploitation framework written in Python. It is designed to be database-agnostic and extremely customizable, making it useful when off-the-shelf tools fail.
BASIC USAGE#
bbqsql # Launch interactive menu
CONFIGURATION OPTIONS#
# HTTP Parameters: url # Target URL method # HTTP method (GET/POST) headers # HTTP headers (dict) cookies # HTTP cookies (dict) data # POST data files # File upload data # Injection Parameters: query # SQL query to execute technique # binary_search or frequency_search comparison_attr # content_length, status_code, text concurrency # Number of concurrent requests
INJECTION MARKERS#
# Use these markers in URL, data, cookies, or headers:
${injection} # Where the SQL injection goes
${char_test} # Character comparison marker
${sleep} # Time-based sleep marker
TECHNIQUES#
# binary_search (default) # - Uses binary search on character values # - Faster for most cases # - Works with boolean-based blind SQLi # frequency_search # - Uses character frequency analysis # - Better for certain character sets # - More efficient for predictable data
COMPARISON ATTRIBUTES#
# content_length # - Compare response sizes # - Good when true/false differ in page size # status_code # - Compare HTTP status codes # - Useful when different codes returned # text # - Compare response body text # - Most flexible but slowest
EXAMPLES#
# Boolean-based blind SQL injection:
# 1. Launch bbqsql
# 2. Set URL: http://target.com/page?id=1${injection}
# 3. Set technique: binary_search
# 4. Set comparison_attr: content_length
# 5. Set query: SELECT table_name FROM information_schema.tables
# 6. Run the attack
# Time-based blind SQL injection:
# 1. Set URL with ${sleep} marker
# 2. Configure time threshold
# 3. Set query to extract data
WORKFLOW#
# 1. Identify injection point manually # 2. Determine true/false response differences # 3. Configure bbqsql with correct markers # 4. Set appropriate comparison attribute # 5. Define SQL query to extract # 6. Run and collect results
NOTES#
- Python-based framework - Database agnostic (works with any DBMS) - Highly customizable for edge cases - Better than sqlmap for non-standard injections - Supports concurrent requests for speed - Interactive menu-driven configuration - Good for blind SQLi where sqlmap fails - Requires understanding of the injection point