0x05 - DB Dump via Underscore Wildcards
0x05 - DB Dump via Underscore Wildcards
Pentest Tips & Tricks
A01 - Broken Access Control
A01 - Broken Access Control
A02 - Cryptographic Failures
A02 - Cryptographic Failures
A03 - Injection Attacks
A03 - Injection Attacks
A04 – Insecure Design
A04 – Insecure Design
A05 – Security Misconfiguration
A05 – Security Misconfiguration
A06 – Vulnerable Components
A06 – Vulnerable Components
A07 – Identification and Authentication Failures
A07 – Identification and Authentication Failures
Recon & Attack Surface
Recon & Attack Surface
Tooling & Automation
Tooling & Automation
Creative, Strategic, and Mindset
Creative, Strategic, and Mindset
Bug Bounty $$$
Bug Bounty $$$
AI/ML/LLM/MCP
AI/ML/LLM/MCP
Latest Tips & Tricks
Latest Tips & Tricks
Did you know you can dump a whole database table even without SQL injection?
The underscore _ character is a less-known payload that you can use when pentesting the search functions of an application
This is an alternative to the more common asterisk (*) and percent sign (%) payloads that usually get blocked by WAFs and developers.
By using a wildcard character it's possible to match and read a larger set of values which can uncover sensitive information stored on the DB table.
Note that the _ wildcard represents ONLY A SINGLE CHARACTER so you need to add multiple underscore wildcards to dump all the info
How to do it
Find a search function within the app and intercept the request
Increase the results size number to max (i.e: 10.000) if needed
Replace the search string with the wildcard payload
_Continue to increase the payload until no more values are returns (
__,___,____,_____, etc.)Note how these payloads match all values and the server ends up dumping the whole table