← All cheat sheets

BBQSQL

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

bbqsql is a blind SQL injection exploitation framework written in
Python. It is designed to be database-agnostic and extremely
customizable, making it useful when off-the-shelf tools fail.

BASIC USAGE#

bbqsql                           # Launch interactive menu

CONFIGURATION OPTIONS#

# HTTP Parameters:
url                              # Target URL
method                           # HTTP method (GET/POST)
headers                          # HTTP headers (dict)
cookies                          # HTTP cookies (dict)
data                             # POST data
files                            # File upload data

# Injection Parameters:
query                            # SQL query to execute
technique                        # binary_search or frequency_search
comparison_attr                  # content_length, status_code, text
concurrency                      # Number of concurrent requests

INJECTION MARKERS#

# Use these markers in URL, data, cookies, or headers:
${injection}                     # Where the SQL injection goes
${char_test}                     # Character comparison marker
${sleep}                         # Time-based sleep marker

TECHNIQUES#

# binary_search (default)
# - Uses binary search on character values
# - Faster for most cases
# - Works with boolean-based blind SQLi

# frequency_search
# - Uses character frequency analysis
# - Better for certain character sets
# - More efficient for predictable data

COMPARISON ATTRIBUTES#

# content_length
# - Compare response sizes
# - Good when true/false differ in page size

# status_code
# - Compare HTTP status codes
# - Useful when different codes returned

# text
# - Compare response body text
# - Most flexible but slowest

EXAMPLES#

# Boolean-based blind SQL injection:
# 1. Launch bbqsql
# 2. Set URL: http://target.com/page?id=1${injection}
# 3. Set technique: binary_search
# 4. Set comparison_attr: content_length
# 5. Set query: SELECT table_name FROM information_schema.tables
# 6. Run the attack

# Time-based blind SQL injection:
# 1. Set URL with ${sleep} marker
# 2. Configure time threshold
# 3. Set query to extract data

WORKFLOW#

# 1. Identify injection point manually
# 2. Determine true/false response differences
# 3. Configure bbqsql with correct markers
# 4. Set appropriate comparison attribute
# 5. Define SQL query to extract
# 6. Run and collect results

NOTES#

- Python-based framework
- Database agnostic (works with any DBMS)
- Highly customizable for edge cases
- Better than sqlmap for non-standard injections
- Supports concurrent requests for speed
- Interactive menu-driven configuration
- Good for blind SQLi where sqlmap fails
- Requires understanding of the injection point