Database Schema
Category: Information Disclosure / SQL Injection Difficulty: ⭐⭐⭐ (3/6) Video: Watch video (max. 5 min)
Challenge Overview
The goal is to extract the full database schema via a SQL injection vulnerability in the product search feature.
Tools Used
- Web browser
- Burp Suite (to inspect/craft requests, optional)
Step-by-Step Walkthrough
-
Identify the injection point. The product search endpoint (
/rest/products/search?q=...) passes theqparameter into a SQL query. Submitting a single quote (') causes a server error, confirming the input is not properly sanitized. -
Determine the number of columns. Since the search results render multiple product fields, the underlying
SELECTmust return a matching number of columns. This can be found by incrementally testingUNION SELECT NULL, NULL, ...(orORDER BY n--) until no error occurs — in this case, 9 columns are required. -
Break out of the original query. The payload starts with
test'))— this closes the string literal (') and the parentheses that wrap the search condition in the original query, turning the rest of the input into syntactically valid, attacker-controlled SQL. -
Append a UNION SELECT. The first 8 columns are filled with placeholder values (
1,2,3,4,5,6,7,8) purely to match the expected column count and types of the original query. The 9th column is replaced withsql, pulled from SQLite's internalsqlite_schematable, which stores the schema definition of every table in the database. -
Comment out the rest of the original query using
--so any remaining SQL from the original statement is ignored. -
Assemble and encode the payload:
test')) UNION SELECT 1,2,3,4,5,6,7,8,sql FROM sqlite_schema--URL-encoded:
http://localhost:3000/rest/products/search?q=test'))%20UNION%20SELECT%201,2,3,4,5,6,7,8,sql%20FROM%20sqlite_schema-- -
Submit the request. The response now returns the full database schema (table and column definitions) inside the search results.
Why This Matters (Risk & Consequences)
SQL injection here allows an attacker to read arbitrary data from the database, starting with its structural schema. Knowing the exact table and column names is typically the reconnaissance step before a more targeted attack — e.g. extracting user credentials, personal data, or order/payment information. In more severe cases, SQL injection can also be used to modify or delete data, or escalate to remote code execution depending on the database engine and permissions.
Remediation
- Use parameterized queries / prepared statements for all database access; never concatenate user input into SQL strings.
- Apply strict input validation and allow-listing where possible.
- Run the database with least-privilege accounts so even a successful injection has limited impact.