SQL Injection: practice machines and key commands
SQL injection happens when user input is concatenated into a query, letting you change its logic. Test every parameter, header and cookie with a single quote, a comment sequence and boolean conditions, and watch for errors, timing differences or changed content. Depending on the result you can use UNION queries to read other tables, boolean or time based blind techniques, or stacked queries on some engines. Authentication bypasses and credential dumps are the common wins, and on MSSQL or MySQL with the right privileges you may reach file writes or command execution. sqlmap automates the work, but understand the manual payload first so you can fix it when filters or WAFs get in the way. Save the HTTP request to a file and let sqlmap reuse it. NoSQL variants use operators like $ne instead of quotes. The machines below feature injection as the foothold.
Key commands
Placeholders in braces, such as {TARGET_IP}, are values you fill in for your target.
SQLmap Automated Injection & Database Dump
Batch automated SQL injection extraction with risk and level escalation.
sqlmap -u "http://{TARGET_IP}/item.php?id=1" --batch --random-agent --level=3 --risk=2 --dbsSQLmap Target Saved HTTP Request File
Pass raw saved Burp Suite POST request file to extract DB tables.
sqlmap -r request.txt -p username --batch --current-db --dumpSQLmap Heavy Injection Probe (Risk 3 / Level 5)
High-potency SQL injection test checking all HTTP headers, cookies, and injection boundaries.
sqlmap -u "http://{TARGET_IP}/page?id=1" --batch --risk=3 --level=5 --threads=4 --dbs
Keep going
- Methodology: Phase 04: Foothold Execution & Initial Access
- Cheatsheet: Web & Directory Fuzzing
- Cheatsheet: Exploitation & Payloads
SQL Injection machines (25)
3 of these are machines I solved myself and are listed first within each difficulty. Machines are matched by their technique tags. 21 Linux, 4 Windows.
Very Easy (2)
| Machine | Platform | OS |
|---|---|---|
| Appointment | HTB | Linux |
| Vaccine | HTB | Linux |
Easy (4)
| Machine | Platform | OS |
|---|---|---|
| Simple CTF | THM | Linux |
| PC | HTB | Linux |
| Shoppy | HTB | Linux |
| Stocker | HTB | Linux |
Medium (10)
| Machine | Platform | OS |
|---|---|---|
| Cache | HTB | Linux |
| Clicker | HTB | Linux |
| Cronos | HTB | Linux |
| Game Zone | THM | Linux |
| Magic | HTB | Linux |
| Mango | HTB | Linux |
| Monitored | HTB | Linux |
| Sneaky | HTB | Linux |
| The Cod Caper | THM | Linux |
| Zipping | HTB | Linux |
Hard (7)
| Machine | Platform | OS |
|---|---|---|
| Breadcrumbs | HTB | Windows |
| Control | HTB | Windows |
| Daily Bugle | THM | Linux |
| Enterprise | THM | Windows |
| OverGraph | HTB | Linux |
| Scavenger | HTB | Linux |
| Year of the Dog | THM | Linux |
Insane (2)
| Machine | Platform | OS |
|---|---|---|
| Fatty | HTB | Linux |
| Multimaster | HTB | Windows |
Related techniques
Practise it, then track it. Log every box and the commands you used in ZeroBox. Open ZeroBox