Use when identifying and exploiting SQL injection vulnerabilities in
Scanned 9/8/2026
Install to Claude Code
npx -y skills add oyi77/1ai-skills --skill exploiting-sql-injection-vulnerabilities --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Exploiting Sql Injection Vulnerabilities?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/oyi77-exploiting-sql-injection-vulnerabilities)More formats (shields.io, HTML) on the badges page.
---
name: exploiting-sql-injection-vulnerabilities
description: Use when identifying and exploiting SQL injection vulnerabilities in
web applications during authorized penetration tests using manual techniques and
automated tools like sqlmap. The tester detects injection points through error-based,
union-based, blind boolean, and time-based blind techniques across all major database
engines (MySQL, PostgreSQL, MSSQL, Oracle) to demonstrate data extraction, authentication
bypass, and potential remote code execution.
domain: cybersecurity
tags:
- SQL-injection
- sqlmap
- database-security
- OWASP-A03
- injection-testing
subdomain: penetration-testing
version: 1.0.0
author: oyi77
license: Apache-2.0
nist_csf:
- ID.RA-01
- ID.RA-06
- GV.OV-02
- DE.AE-07
category: cybersecurity
---
# Exploiting Sql Injection Vulnerabilities
## Overview
Cybersecurity skill for exploiting sql injection vulnerabilities. Follows industry best practices and security standards.
## When to Use
**Trigger phrases:**
- "exploiting sql injection vulnerabilities"
- "Identifies and exploits SQL injection vulnerabilities in web applications during"
- Testing web application input parameters for SQL injection vulnerabilities during an authorized penetration test
- Validating that parameterized queries and input sanitization are properly implemented across all database interactions
- Demonstrating the business impact of a confirmed SQL injection vulnerability by extracting sensitive data
- Verifying that WAF rules and input validation controls effectively block SQL injection payloads
- Testing stored procedures, dynamic SQL, and ORM bypass scenarios in enterprise applications
**Do not use** against databases without written authorization, for extracting or exfiltrating actual customer data beyond what is needed for proof of concept, or against production databases where exploitation could corrupt data integrity.
## When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
## Prerequisites
- Written authorization specifying the target application and permissible level of exploitation (detection only vs. full exploitation)
- Burp Suite Professional configured as an intercepting proxy to capture and modify HTTP requests
- sqlmap installed with current version for automated detection and exploitation
- Knowledge of the target database engine (MySQL, PostgreSQL, MSSQL, Oracle) or ability to fingerprint it
- Test accounts at various privilege levels to test injection in authenticated contexts
## Workflow
```python
# Example: IOC detection
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: str) -> dict:
return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}
```
1. **Reconnaissance** — Gather information about the target related to sql injection vulnerabilities. Identify attack surface.
2. **Vulnerability Identification** — Enumerate potential sql injection vulnerabilities weaknesses using automated and manual techniques.
3. **Exploit Development/Selection** — Choose or develop exploits targeting identified sql injection vulnerabilities vulnerabilities.
4. **Execution** — Execute the sql injection vulnerabilities test in a controlled manner with proper authorization.
5. **Post-Exploitation** — Document the impact and extent of successful exploitation.
6. **Reporting** — Write detailed findings with reproduction steps, impact assessment, and remediation guidance.
## Tools
- **Vulnerability Scanner** — Automated weakness identification
- **Exploitation Framework** — Controlled exploitation testing
- **Reporting Tool** — Findings documentation and tracking
## Process
1. **Reconnaissance** — Gather target information, identify attack surface, enumerate services
1. **Analysis/Exploitation** — Execute the technique, analyze results, document findings
1. **Reporting** — Document IOCs, write findings, provide remediation recommendations
## Verification
- [ ] All sql injection vulnerabilities procedures executed completely and documented
- [ ] Findings validated against multiple data sources
- [ ] False positives identified and filtered
- [ ] Results documented with evidence and timestamps
- [ ] Recommendations provided with risk-based prioritization
## Anti-Rationalization Table
| Rationalization | Reality |
|---|---|
| "We are too small to be targeted" | Automated attacks target everyone. Size does not matter. |
| "Security slows us down" | A breach slows you down 100x more. Build security in from the start. |
| "We will fix it after launch" | Vulnerabilities in production are exploited within hours. Fix before deploy. |Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!