Operator On The Wire
Join
← Back to Knowledge Base
RED TEAM / SQL / MYSQL / ENUMERATION

User Context

-- Current MySQL user and authenticated host
SELECT USER(), CURRENT_USER();

-- Check privileges of current user
SHOW GRANTS FOR CURRENT_USER();

-- List all MySQL users with FILE/SUPER (potential RCE or file access)
SELECT User, Host, File_priv, Super_priv 
FROM mysql.user 
WHERE File_priv='Y' OR Super_priv='Y';

Inspect grants for the current user and sensitive flags.

SELECT USER(),CURRENT_USER();
SHOW GRANTS FOR CURRENT_USER();
SELECT User,Host,File_priv,Super_priv FROM mysql.user WHERE File_priv='Y' OR Super_priv='Y';