Attack chain 8 steps

SQL Injection to Full Breach

The whole chain in order — from the first touch to the objective — with the point at which each stage could have been stopped.

The chain, step by step

Each step depends on the one before it. Break any link and the chain stops there.

  1. 1

    Step 1 of 8

    Reconnaissance finds a search page that echoes a URL parameter back into the response.

  2. 2

    Step 2 of 8

    A single quote produces a database error, confirming that input reaches the query unparameterised.

  3. 3

    Step 3 of 8

    Boolean-based probing determines the injection point and the backend DBMS flavour.

  4. 4

    Step 4 of 8

    A UNION SELECT reveals the table and column layout without any destructive traffic.

  5. 5

    Step 5 of 8

    The account table is dumped, exposing stored password hashes for offline cracking.

  6. 6

    Step 6 of 8

    Weak hashes fall quickly, yielding credentials that are reused on email and admin panels.

  7. 7

    Step 7 of 8

    A reused administrator password grants access to the application's control panel.

  8. 8

    Step 8 of 8

    With admin access, a file-write primitive or command execution lands a shell on the server.

Entries behind these steps

The vulnerabilities, techniques and malware that make each stage possible.

We use only the cookies needed to run this site — your session, your sign-in state and CSRF protection. There are no advertising or analytics trackers. How cookies are used