# SQL injection checklist

Prove SQL control manually, identify the dialect and query shape, then progress from data access to file or command execution where supported.

## Recognition

- [ ] Quotes, parentheses, comments, type changes, sorting expressions, or boolean conditions change the response.
- [ ] Database error text, column names, SQL fragments, or consistent timing differences appear.
- [ ] Search, filter, sort, ID, login, report, or JSON parameters influence database-backed content.

## Manual workflow

- [ ] Establish a stable baseline and identify whether the value is numeric, string, list, identifier, ORDER BY, or function input.
- [ ] Balance quotes and parentheses; test true/false conditions and native comments without combining many mutations.
- [ ] Identify MySQL, PostgreSQL, MSSQL, or Oracle through errors, functions, concatenation, timing, and metadata behavior.
- [ ] Count columns with ORDER BY or UNION NULLs and identify visible compatible columns.
- [ ] Enumerate current database/user, schemas, tables, columns, and only the data required for the objective.
- [ ] Evaluate stacked queries, file read/write, database-specific command execution, or web-shell placement.
- [ ] After manual confirmation, use SQLMap narrowly with a saved request and known parameter when it reduces repetitive work.

## Escalation

- [ ] Authentication bypass or administrative credential recovery may lead directly to local.txt.
- [ ] File read can reveal configuration, source, credentials, or writable web roots.
- [ ] File write, stacked queries, MSSQL execution features, or database extensions may lead to a shell and proof.txt.

## Pitfalls

- [ ] Launching SQLMap before understanding the request, parameter, session, CSRF behavior, or query context.
- [ ] Using a UNION with the wrong column count or incompatible data types and concluding the input is safe.
- [ ] Assuming all database dialects share comments, concatenation, metadata tables, or file capabilities.
- [ ] Dumping everything instead of pursuing the shortest objective path.

## Evidence

- [ ] True/false or error confirmation
- [ ] Dialect identification
- [ ] Working enumeration query
- [ ] Administrative or RCE transition
- [ ] Original-location proof screenshot

## Tools

- [ ] Burp/ZAP manual resend
- [ ] Wfuzz or proxy fuzzer
- [ ] SQLMap after confirmation
- [ ] Dialect reference and UNION workbench

## Online references

- [PortSwigger SQL injection labs](<https://portswigger.net/web-security/sql-injection>)
- [OWASP SQL injection testing](<https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/07-Input_Validation_Testing/05-Testing_for_SQL_Injection>)

> Do you want to live curiously?
