DEV Community

lupingQAQ
lupingQAQ

Posted on

SqlStealthRogue: a zero-probe SQL and NoSQL data dumper

SqlStealthRogue: a zero-probe SQL and NoSQL injection data dumper

A minimalist, zero-probe SQL/NoSQL injection data dumper. Single entry file, pure Python standard library, no dependencies.

Concept

SqlStealthRogue is a scalpel, not a swiss-army knife: given a known injection point and a known database, table, and columns, it extracts data at high speed with zero negotiation and zero reconnaissance traffic. sqlmap - even with -D/-T/-C pinned - still fires requests for DBMS fingerprinting, version detection, privilege/table enumeration, WAF detection and technique polling. SqlStealthRogue does the opposite: every single request it sends is a data-extraction request.

Zero extra requests

Behavior SqlStealthRogue
DBMS fingerprint / version probing none
Privilege / schema enumeration none (you already know the target)
WAF detection / technique polling none (--dbms + --technique, specify and go)
True-mark calibration requests none (row termination rides on extraction requests)
Every request sent is a data-extraction request

High-speed extraction (measured on real engines)

Optimization Measured effect
Bit-parallel blind engine (char & mask, 8 concurrent bits) 5.35x faster, request count identical to serial binary search
HTTP keep-alive, thread-local connections 5.6x faster (auto-downgrades on HTTP/1.0 targets, zero penalty)
Error-mode adaptive chunk prefetch long values fetched in one batch
PG/MSSQL large chunks (error messages carry >=800 chars, measured) 600-char value: 22 -> 6 requests
UNION mode whole table in 1 request

Custom WAF-bypass plugins (tamper chains)

# 13 sqlmap-compatible tampers built in; compose in order; zero extra traffic
python SqlStealthRogue.py --tamper "randomcase,between,space2comment" ...

# Custom plugin: one .py file with one tamper() function
python SqlStealthRogue.py --tamper mybypass --tamper-dir /path/to/tampers ...
Enter fullscreen mode Exit fullscreen mode

Built-in tampers: space2comment space2plus space2randomblank between equaltolike randomcase charencode chardoubleencode halfversionedmorekeywords apostrophemask percentage unionalltounion xforwardedfor.

Minimal-blast-radius abort on misconfiguration

A wrong parameter never floods the target - the cost of a mistake is capped at "first row, first value":

Misconfiguration Packets actually sent
Statically invalid args / unknown tamper / dbms x technique mismatch 0
Injection point unreachable <= 2
Template or true-mark syntax error 8-16
Always-true true-mark / always-matching regex (sentinel guards abort) ~128 (would be 16,384+ without guards)
Bad UNION template 1

12-engine real-machine verification matrix

Engine error bool time prefix union
MySQL 8 yes yes yes - yes
PostgreSQL 14 yes yes yes - yes
MSSQL 2022 yes yes yes - yes
SQLite - yes yes - yes
Redis - yes partial - yes
MongoDB 7 - yes yes yes -
openGauss 5 yes yes yes - yes
OceanBase CE - yes yes - yes
Oracle 23ai - yes yes - yes
Elasticsearch 8 - yes partial - yes
Milvus 2.4 - - - - yes
pgvector yes yes yes - yes

Repo: https://github.com/lupingQAQ/SqlStealthRogue

Top comments (0)