← All cheat sheets

JSQL

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

jSQL Injection is a lightweight Java application for automatic SQL
injection discovery and exploitation. It supports multiple database
types and injection strategies with a GUI interface.

LAUNCHING#

java -jar jsql-injection.jar     # Launch GUI
jsql                             # Launch (if installed)

SUPPORTED DATABASES#

# MySQL, PostgreSQL, SQLite, Oracle, SQL Server
# DB2, Informix, Sybase, H2, HSQLDB
# CockroachDB, Cubrid, Derby, Firebird
# Access, Ingres, MaxDB, Mckoi, Monetdb
# NuoDB, Vertica, Presto

INJECTION TYPES#

# Normal (UNION-based)
# - Fastest extraction method
# - Requires UNION SELECT capability

# Error-based
# - Uses database error messages
# - Works when errors are displayed

# Blind (Boolean-based)
# - Infers data from true/false responses
# - Works when no output is visible

# Time-based Blind
# - Uses response time differences
# - Slowest but most reliable

GUI INTERFACE#

# Address Bar:
# - Enter target URL with parameter
# - Example: http://target.com/page?id=1

# Tabs:
# Database   - Browse database structure
# Admin      - Search for admin pages
# File       - Read/write files on server
# Shell      - Web shell upload/command
# SQL Shell  - Execute SQL queries
# Brute      - Hash cracking

INJECTION MARKERS#

# Use * to mark injection point in URL:
http://target.com/page?id=1*
http://target.com/page?id=1*&other=test

# In POST data:
id=1*&submit=true

# In headers:
Cookie: session=abc123*
X-Forwarded-For: 127.0.0.1*

REQUEST OPTIONS#

# Method: GET, POST, PUT, DELETE, PATCH, HEAD
# Body type: URL-encoded, Multipart, JSON, SOAP
# Headers: Custom headers and cookies
# Authentication: Basic, Digest, NTLM, Kerberos

EXPLOITATION FEATURES#

# Database browsing:
# - List databases
# - List tables
# - List columns
# - Dump data

# File operations:
# - Read files from server (LOAD_FILE)
# - Write files to server (INTO OUTFILE)

# Shell:
# - Upload web shell
# - Execute OS commands

# Admin panel finder:
# - Brute force admin page URLs
# - Common admin paths tested

PROXY SUPPORT#

# Settings → Proxy
# - HTTP proxy
# - SOCKS proxy
# - Tor integration
# - Proxy authentication

TAMPERING#

# Built-in tamper scripts:
# - Base64 encoding
# - Hex encoding
# - Unicode encoding
# - Comment insertion
# - Case randomization
# - Space-to-comment

EXAMPLES#

# Basic GET injection:
# URL: http://target.com/news?id=1
# Click "Start" to auto-detect

# POST injection:
# URL: http://target.com/login
# Body: user=admin&pass=1*
# Method: POST

# Header injection:
# URL: http://target.com/page
# Header: X-Forwarded-For: 1*

NOTES#

- Java-based (cross-platform)
- GUI and CLI modes available
- Supports 30+ database types
- Automatic injection strategy detection
- Built-in hash cracker
- Tamper scripts for WAF bypass
- Actively maintained on GitHub
- Pair with Burp Suite for complex scenarios