JSQL
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
jSQL Injection is a lightweight Java application for automatic SQL injection discovery and exploitation. It supports multiple database types and injection strategies with a GUI interface.
LAUNCHING#
java -jar jsql-injection.jar # Launch GUI jsql # Launch (if installed)
SUPPORTED DATABASES#
# MySQL, PostgreSQL, SQLite, Oracle, SQL Server # DB2, Informix, Sybase, H2, HSQLDB # CockroachDB, Cubrid, Derby, Firebird # Access, Ingres, MaxDB, Mckoi, Monetdb # NuoDB, Vertica, Presto
INJECTION TYPES#
# Normal (UNION-based) # - Fastest extraction method # - Requires UNION SELECT capability # Error-based # - Uses database error messages # - Works when errors are displayed # Blind (Boolean-based) # - Infers data from true/false responses # - Works when no output is visible # Time-based Blind # - Uses response time differences # - Slowest but most reliable
GUI INTERFACE#
# Address Bar: # - Enter target URL with parameter # - Example: http://target.com/page?id=1 # Tabs: # Database - Browse database structure # Admin - Search for admin pages # File - Read/write files on server # Shell - Web shell upload/command # SQL Shell - Execute SQL queries # Brute - Hash cracking
INJECTION MARKERS#
# Use * to mark injection point in URL: http://target.com/page?id=1* http://target.com/page?id=1*&other=test # In POST data: id=1*&submit=true # In headers: Cookie: session=abc123* X-Forwarded-For: 127.0.0.1*
REQUEST OPTIONS#
# Method: GET, POST, PUT, DELETE, PATCH, HEAD # Body type: URL-encoded, Multipart, JSON, SOAP # Headers: Custom headers and cookies # Authentication: Basic, Digest, NTLM, Kerberos
EXPLOITATION FEATURES#
# Database browsing: # - List databases # - List tables # - List columns # - Dump data # File operations: # - Read files from server (LOAD_FILE) # - Write files to server (INTO OUTFILE) # Shell: # - Upload web shell # - Execute OS commands # Admin panel finder: # - Brute force admin page URLs # - Common admin paths tested
PROXY SUPPORT#
# Settings → Proxy # - HTTP proxy # - SOCKS proxy # - Tor integration # - Proxy authentication
TAMPERING#
# Built-in tamper scripts: # - Base64 encoding # - Hex encoding # - Unicode encoding # - Comment insertion # - Case randomization # - Space-to-comment
EXAMPLES#
# Basic GET injection: # URL: http://target.com/news?id=1 # Click "Start" to auto-detect # POST injection: # URL: http://target.com/login # Body: user=admin&pass=1* # Method: POST # Header injection: # URL: http://target.com/page # Header: X-Forwarded-For: 1*
NOTES#
- Java-based (cross-platform) - GUI and CLI modes available - Supports 30+ database types - Automatic injection strategy detection - Built-in hash cracker - Tamper scripts for WAF bypass - Actively maintained on GitHub - Pair with Burp Suite for complex scenarios