Detect Potential SQL Injection Payloads in GET URIs via Webserver Access Logs

Flags HTTP GET URIs containing SQL injection indicator strings in webserver access logs, excluding 404 responses.

FreeReviewedSigma · High · v2
Category
webserver
Author
Saw Win Naung, Nasreddine Bencherchali (Nextron Systems), Thurein Oo (Yoma Bank) (SigmaHQ), DRL 1.1
Published
2020-02-22
Updated
2026-07-31
title: Detect Potential SQL Injection Payloads in GET URIs via Webserver Access Logs
id: 60532039-8cb3-4661-b3fd-ee5543346a84
status: test
description: This rule flags HTTP GET requests where the requested URI contains common SQL injection string patterns and encoded payloads (e.g., UNION SELECT, OR 1=1, SELECT version/database, and time-delay function usage). Attackers use these payloads to probe for database query weaknesses and potentially extract or manipulate data. It relies on webserver access log fields for request method, URI content, and HTTP status, including the exclusion of a specific 404 status filter set.
references:
  - https://www.acunetix.com/blog/articles/exploiting-sql-injection-example/
  - https://www.acunetix.com/blog/articles/using-logs-to-investigate-a-web-application-attack/
  - https://brightsec.com/blog/sql-injection-payloads/
  - https://github.com/payloadbox/sql-injection-payload-list
  - https://book.hacktricks.xyz/pentesting-web/sql-injection/mysql-injection
  - https://github.com/SigmaHQ/sigma/blob/master/rules/web/webserver_generic/web_sql_injection_in_access_logs.yml
author: Saw Win Naung, Nasreddine Bencherchali (Nextron Systems), Thurein Oo (Yoma Bank), Huntrule Team
date: 2020-02-22
modified: 2023-09-04
tags:
  - attack.initial-access
  - attack.t1190
logsource:
  category: webserver
detection:
  selection:
    cs-method: GET
  keywords:
    - "@@version"
    - "%271%27%3D%271"
    - "=select "
    - =select(
    - =select%20
    - concat_ws(
    - CONCAT(0x
    - from mysql.innodb_table_stats
    - from%20mysql.innodb_table_stats
    - group_concat(
    - information_schema.tables
    - json_arrayagg(
    - or 1=1#
    - or%201=1#
    - "order by "
    - order%20by%20
    - "select * "
    - select database()
    - select version()
    - select%20*%20
    - select%20database()
    - select%20version()
    - select%28sleep%2810%29
    - SELECTCHAR(
    - table_schema
    - UNION ALL SELECT
    - UNION SELECT
    - UNION%20ALL%20SELECT
    - UNION%20SELECT
    - "'1'='1"
  filter_main_status:
    sc-status: 404
  condition: selection and keywords and not 1 of filter_main_*
falsepositives:
  - Java scripts and CSS Files
  - User searches in search boxes of the respective website
  - Internal vulnerability scanners can cause some serious FPs when used, if you experience a lot of FPs due to this think of adding more filters such as "User Agent" strings and more response codes
level: high
license: DRL-1.1
related:
  - id: 5513deaf-f49a-46c2-a6c8-3f111b5cb453
    type: derived