Operator On The Wire
Join
← Back to Knowledge Base
RED TEAM / SQL / MYSQL

MYSQL Matrix

Feature / AreaRequirementCapability UnlockedRiskNotes
DB EnumerationAny loginDiscover DBs, tables, versionFirst recon: WHERE and WHAT
Privileges & GrantsSELECT on mysql.* or CURRENTSee what current user can doShows RCE potential (FILE/SUPER)
File Import/Exportsecure_file_priv path, FILERead/write files via INFILE/OUTFILEData exfil, webshell drop
local_infile Uploadslocal_infile=ONClient-side file uploadsCan be abused depending on context
INTO OUTFILE WebshellFILE privilege + webroot pathDirect RCE via PHP/webshellClassic SQLi→RCE chain
UDF Exploitation (Win)FILE + plugin_dir writeLoad malicious DLL, OS command executionPersistent, powerful RCE
UDF Exploitation (Linux)FILE + plugin_dir writeLoad .so and call sys_eval()Often leads to root privesc