ZeroBox

SQL Injection: practice machines and key commands

SQL injection happens when user input is concatenated into a query, letting you change its logic. Test every parameter, header and cookie with a single quote, a comment sequence and boolean conditions, and watch for errors, timing differences or changed content. Depending on the result you can use UNION queries to read other tables, boolean or time based blind techniques, or stacked queries on some engines. Authentication bypasses and credential dumps are the common wins, and on MSSQL or MySQL with the right privileges you may reach file writes or command execution. sqlmap automates the work, but understand the manual payload first so you can fix it when filters or WAFs get in the way. Save the HTTP request to a file and let sqlmap reuse it. NoSQL variants use operators like $ne instead of quotes. The machines below feature injection as the foothold.

Key commands

Placeholders in braces, such as {TARGET_IP}, are values you fill in for your target.

SQLmap Automated Injection & Database Dump

Batch automated SQL injection extraction with risk and level escalation.

sqlmap -u "http://{TARGET_IP}/item.php?id=1" --batch --random-agent --level=3 --risk=2 --dbs

SQLmap Target Saved HTTP Request File

Pass raw saved Burp Suite POST request file to extract DB tables.

sqlmap -r request.txt -p username --batch --current-db --dump

SQLmap Heavy Injection Probe (Risk 3 / Level 5)

High-potency SQL injection test checking all HTTP headers, cookies, and injection boundaries.

sqlmap -u "http://{TARGET_IP}/page?id=1" --batch --risk=3 --level=5 --threads=4 --dbs

Keep going

SQL Injection machines (25)

3 of these are machines I solved myself and are listed first within each difficulty. Machines are matched by their technique tags. 21 Linux, 4 Windows.

Very Easy (2)

MachinePlatformOSTags
AppointmentHTBLinuxSQLi, Web Auth Bypass, SQL Injection
VaccineHTBLinuxFTP, SQLi, Sudo, Tar Wildcard

Easy (4)

MachinePlatformOSTags
Simple CTFTHMLinuxCMS-Made-Simple, CVE-2019-9053, SQLi, Vim-Sudo
PCHTBLinuxCPTS, gRPC, SQL Injection, Pivoting
ShoppyHTBLinuxHTB, NoSQL-Injection, Reverse-Engineering
StockerHTBLinuxCPTS, NoSQL Injection, Server-Side XSS, NodeJS

Medium (10)

MachinePlatformOSTags
CacheHTBLinuxBasic-SQL-Injection, HTB, Memcached
ClickerHTBLinuxCPTS, NFS, Mass Assignment, SQL Injection
CronosHTBLinuxCommand-Injection, Exploiting-cron-jobs, HTB, SQL-Injection
Game ZoneTHMLinuxSQLi, SSH-Tunneling, Webmin
MagicHTBLinuxBasic-SQL-Injection, HTB, Path-Hijacking, SUID-Abuse
MangoHTBLinuxGTFOBins-Abuse, HTB, NoSQL-Injection
MonitoredHTBLinuxNagios-XI-CVE-2023-40931, Cacti, SQLi, SUID-Abuse
SneakyHTBLinuxBasic-SQL-injection, Basic-buffer-overflow, Enumerating-SNMP, Exploiting-SUID-files
The Cod CaperTHMLinuxOSCP, SQLi, Command Injection, Buffer Overflow
ZippingHTBLinuxZip-Symlink, LFI, SQLi, Shared-Library-Hijack

Hard (7)

MachinePlatformOSTags
BreadcrumbsHTBWindowsForging-PHP-sessions, HTB, SQL-Injection
ControlHTBWindowsBasic-SQL-Injection, CVE-2019-11043, File-System, HTB
Daily BugleTHMLinuxOSCP, Joomla, SQLi, CVE-2019-8942
EnterpriseTHMWindowsActive Directory, ZeroLogon, SQLi, Privilege Escalation
OverGraphHTBLinuxCSRF-attacks, FFmpeg, HTB, NoSQL-injection
ScavengerHTBLinuxHTB, Reversing-Rootkits, SQL-Injection
Year of the DogTHMLinuxSQLi, Gitea, Command-Injection

Insane (2)

MachinePlatformOSTags
FattyHTBLinuxDeserialization, HTB, Path-Traversal, SQL-Injection
MultimasterHTBWindowsCVE-2020-1472, HTB, Password-Cracking, SQL-Injection

Related techniques

Practise it, then track it. Log every box and the commands you used in ZeroBox. Open ZeroBox