The chain, step by step
Each step depends on the one before it. Break any link and the chain stops there.
-
1
Step 1 of 8
Reconnaissance finds a search page that echoes a URL parameter back into the response.
-
2
Step 2 of 8
A single quote produces a database error, confirming that input reaches the query unparameterised.
-
3
Step 3 of 8
Boolean-based probing determines the injection point and the backend DBMS flavour.
-
4
Step 4 of 8
A UNION SELECT reveals the table and column layout without any destructive traffic.
-
5
Step 5 of 8
The account table is dumped, exposing stored password hashes for offline cracking.
-
6
Step 6 of 8
Weak hashes fall quickly, yielding credentials that are reused on email and admin panels.
-
7
Step 7 of 8
A reused administrator password grants access to the application's control panel.
-
8
Step 8 of 8
With admin access, a file-write primitive or command execution lands a shell on the server.
Entries behind these steps
The vulnerabilities, techniques and malware that make each stage possible.