SqlStealthRogue: a zero-probe SQL and NoSQL injection data dumper
A minimalist, zero-probe SQL/NoSQL injection data dumper. Single entry file, pure Python standard library, no dependencies.
Concept
SqlStealthRogue is a scalpel, not a swiss-army knife: given a known injection point and a known database, table, and columns, it extracts data at high speed with zero negotiation and zero reconnaissance traffic. sqlmap - even with -D/-T/-C pinned - still fires requests for DBMS fingerprinting, version detection, privilege/table enumeration, WAF detection and technique polling. SqlStealthRogue does the opposite: every single request it sends is a data-extraction request.
Zero extra requests
| Behavior | SqlStealthRogue |
|---|---|
| DBMS fingerprint / version probing | none |
| Privilege / schema enumeration | none (you already know the target) |
| WAF detection / technique polling | none (--dbms + --technique, specify and go) |
| True-mark calibration requests | none (row termination rides on extraction requests) |
| Every request sent | is a data-extraction request |
High-speed extraction (measured on real engines)
| Optimization | Measured effect |
|---|---|
Bit-parallel blind engine (char & mask, 8 concurrent bits) |
5.35x faster, request count identical to serial binary search |
| HTTP keep-alive, thread-local connections | 5.6x faster (auto-downgrades on HTTP/1.0 targets, zero penalty) |
| Error-mode adaptive chunk prefetch | long values fetched in one batch |
| PG/MSSQL large chunks (error messages carry >=800 chars, measured) | 600-char value: 22 -> 6 requests |
| UNION mode | whole table in 1 request |
Custom WAF-bypass plugins (tamper chains)
# 13 sqlmap-compatible tampers built in; compose in order; zero extra traffic
python SqlStealthRogue.py --tamper "randomcase,between,space2comment" ...
# Custom plugin: one .py file with one tamper() function
python SqlStealthRogue.py --tamper mybypass --tamper-dir /path/to/tampers ...
Built-in tampers: space2comment space2plus space2randomblank between equaltolike randomcase charencode chardoubleencode halfversionedmorekeywords apostrophemask percentage unionalltounion xforwardedfor.
Minimal-blast-radius abort on misconfiguration
A wrong parameter never floods the target - the cost of a mistake is capped at "first row, first value":
| Misconfiguration | Packets actually sent |
|---|---|
| Statically invalid args / unknown tamper / dbms x technique mismatch | 0 |
| Injection point unreachable | <= 2 |
| Template or true-mark syntax error | 8-16 |
| Always-true true-mark / always-matching regex (sentinel guards abort) | ~128 (would be 16,384+ without guards) |
| Bad UNION template | 1 |
12-engine real-machine verification matrix
| Engine | error | bool | time | prefix | union |
|---|---|---|---|---|---|
| MySQL 8 | yes | yes | yes | - | yes |
| PostgreSQL 14 | yes | yes | yes | - | yes |
| MSSQL 2022 | yes | yes | yes | - | yes |
| SQLite | - | yes | yes | - | yes |
| Redis | - | yes | partial | - | yes |
| MongoDB 7 | - | yes | yes | yes | - |
| openGauss 5 | yes | yes | yes | - | yes |
| OceanBase CE | - | yes | yes | - | yes |
| Oracle 23ai | - | yes | yes | - | yes |
| Elasticsearch 8 | - | yes | partial | - | yes |
| Milvus 2.4 | - | - | - | - | yes |
| pgvector | yes | yes | yes | - | yes |
Top comments (0)