47 Gaining Access – SQL Injection
Dante Rocca and Mathew J. Heath Van Horn, PhD
This section will show students the basics of performing a simple SQL injection. Prior knowledge of SQL is not required since we are walking you through the attack in a “monkey see, monkey do” fashion. This chapter provides experience in exploiting SQL database vulnerabilities. However, extensive SQL knowledge is necessary to conduct this type of attack against non-prescribed targets.
Learning Objectives
- Learn the basics of SQL Injection
Prerequisites
Deliverables
- 4 Screenshots are needed to earn credit for this exercise:
- Successful SQL injection getting usernames and passwords
- Using usernames and passwords to SSH into the target system
- The addition of a new SUDO user as demonstrated by SSH into the target system
- Showing the copy of the target’s shadow file and passwd file in the local (Kali) Downloads folder
Resources
- Deepak Prasad – “DWVA SQL Injection Exploitation Explained (Step-by-Step)” – https://www.golinuxcloud.com/dvwa-sql-injection/
- Murari, G. “Exploiting the Vulnerabilities on Metasloit3 (sic) (Ubuntu) Machine Using Metasploit Framework and Methodologies“, Dec 2020, Concordia University of Edmonton
Contributors and Testers
- Raechel Ferguson, Cybersecurity Student, ERAU-Prescott
- Justin La Zare, Cybersecurity Student, ERAU-Prescott
- Jacob M. Christensen, Cybersecurity Student, ERAU-Prescott
Phase I – Injection basics – find a way in
A SQL injection attack involves running an unintended SQL query using an application’s client input fields. By using creativity within the constraints of the SQL syntax, attackers can access the SQL database, extract or modify information, adjust their inputs, and repeat until they gain access. Our first step is to find a place to insert SQL commands.
NOTE: Some IP addresses in the figures vary because the clarifying screenshots were added from different PCs when testing the lab. Your IPs will also vary.
- Start with the attack environment from Chapter 42 and get it up and running
- Find the IP address of the Metasploitable3-Linux VM using Nmap. In our example, we discovered the Metasploitable3-Linux VM using the this will be <IP_ADDRESS>
- We can see that MySQL is running on port 3306, likely supporting a website.
- Open Firefox on the Kali VM. Go to the address:
http://<IP_ADDRESS>
- Click on payroll_app.php
- Log in with the Username admin and the Password admin.
- We got in….sort of. We can see a table trying to display 4 fields, presumably from the MySQL database. We can work with that.
Phase II – SQL Injection
We want to try a few different SQL commands to see what happens. As a reminder, here are some SQL commands:
- ALL CAPS is used to differentiate between SQL commands and data. If a word is typed in ALL CAPS, you know that it is telling SQL to take an action.
- A delimiter separates commands in the way punctuation separates sentences within a paragraph.
- An apostrophe ( ‘ ) delineates the beginning a