<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://truxwiki.com/index.php?action=history&amp;feed=atom&amp;title=Generic_SQLite_Exploitation</id>
	<title>Generic SQLite Exploitation - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://truxwiki.com/index.php?action=history&amp;feed=atom&amp;title=Generic_SQLite_Exploitation"/>
	<link rel="alternate" type="text/html" href="https://truxwiki.com/index.php?title=Generic_SQLite_Exploitation&amp;action=history"/>
	<updated>2026-07-25T23:14:06Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.34.1</generator>
	<entry>
		<id>https://truxwiki.com/index.php?title=Generic_SQLite_Exploitation&amp;diff=10270&amp;oldid=prev</id>
		<title>Sam: /* Exploitation Script Format */</title>
		<link rel="alternate" type="text/html" href="https://truxwiki.com/index.php?title=Generic_SQLite_Exploitation&amp;diff=10270&amp;oldid=prev"/>
		<updated>2025-04-24T20:01:48Z</updated>

		<summary type="html">&lt;p&gt;&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;Exploitation Script Format&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #222; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #222; text-align: center;&quot;&gt;Revision as of 20:01, 24 April 2025&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l29&quot; &gt;Line 29:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 29:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;   &amp;lt;version&amp;gt;8-14&amp;lt;/version&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;   &amp;lt;version&amp;gt;8-14&amp;lt;/version&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;   &amp;lt;filename&amp;gt;ADDataStore.sqlitedb&amp;lt;/filename&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;   &amp;lt;filename&amp;gt;ADDataStore.sqlitedb&amp;lt;/filename&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;  &amp;lt;saveasfiletype&amp;gt;0&amp;lt;/saveasfiletype&amp;gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;   &amp;lt;sql&amp;gt;SELECT DATE(DAYSSINCE1970*86400, 'unixepoch') AS DAY, KEY AS &amp;quot;KEY&amp;quot;, VALUE AS &amp;quot;VALUE&amp;quot; FROM SCALARS&amp;lt;/sql&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;   &amp;lt;sql&amp;gt;SELECT DATE(DAYSSINCE1970*86400, 'unixepoch') AS DAY, KEY AS &amp;quot;KEY&amp;quot;, VALUE AS &amp;quot;VALUE&amp;quot; FROM SCALARS&amp;lt;/sql&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;/sqlite&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;/sqlite&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l58&quot; &gt;Line 58:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 59:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;===&amp;lt;code&amp;gt;source&amp;lt;/code&amp;gt;===&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;===&amp;lt;code&amp;gt;source&amp;lt;/code&amp;gt;===&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;This is usually a link to the source code or article that contained the SQL query.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;This is usually a link to the source code or article that contained the SQL query.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;===&amp;lt;code&amp;gt;saveasfiletype&amp;lt;/code&amp;gt;===&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;This numeric field should contain the integer value for the file type to be written &amp;lt;code&amp;gt;&amp;lt;nowiki&amp;gt;[&amp;lt;/nowiki&amp;gt;[[File_Table#FileTypeID|FileTypeID]]&amp;lt;nowiki&amp;gt;]&amp;lt;/nowiki&amp;gt;&amp;lt;/code&amp;gt; column of the &amp;lt;code&amp;gt;&amp;lt;nowiki&amp;gt;[&amp;lt;/nowiki&amp;gt;[[File_Table|File]]&amp;lt;nowiki&amp;gt;]&amp;lt;/nowiki&amp;gt;&amp;lt;/code&amp;gt; table in the database should any output be generated.&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;If this field is missing or set to zero, the file type will be set to [[Type_Generic_SQLite_Script_Results|1190 (Type_Generic_SQLite_Script_Results)]].&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;This allows you to give a unique file type for the output from an exploitation script to make it easier to find by the analyst.&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;===&amp;lt;code&amp;gt;sql&amp;lt;/code&amp;gt;===&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;===&amp;lt;code&amp;gt;sql&amp;lt;/code&amp;gt;===&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Sam</name></author>
		
	</entry>
	<entry>
		<id>https://truxwiki.com/index.php?title=Generic_SQLite_Exploitation&amp;diff=9846&amp;oldid=prev</id>
		<title>Sam: Created page with &quot;You can extend Truxton to exploit SQLite databases that it doesn't currently support.  =Generic SQLite Exploitation= SQLite is used everywhere. Many applications use them to s...&quot;</title>
		<link rel="alternate" type="text/html" href="https://truxwiki.com/index.php?title=Generic_SQLite_Exploitation&amp;diff=9846&amp;oldid=prev"/>
		<updated>2024-09-12T10:20:32Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;You can extend Truxton to exploit SQLite databases that it doesn&amp;#039;t currently support.  =Generic SQLite Exploitation= SQLite is used everywhere. Many applications use them to s...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;You can extend Truxton to exploit SQLite databases that it doesn't currently support.&lt;br /&gt;
&lt;br /&gt;
=Generic SQLite Exploitation=&lt;br /&gt;
SQLite is used everywhere.&lt;br /&gt;
Many applications use them to store things like program settings, chats, geographic coordinates, etc.&lt;br /&gt;
Trying to exploit all of the formats is an impossible task.&lt;br /&gt;
Truxton solves this problem by giving the user the ability to add any number of custom queries that will be executed during loading.&lt;br /&gt;
The results of these queries will be output as tab-separated values ([https://en.wikipedia.org/wiki/Tab-separated_values TSV]) child file of the SQLite file.&lt;br /&gt;
&lt;br /&gt;
=Concept of Operations=&lt;br /&gt;
If you find or write a script that can exploit a particular kind of SQLite file, here's how you would integrate it with Truxton's exploitation pipeline.&lt;br /&gt;
# Put the SQL query and meta-data into an exploitation script.&lt;br /&gt;
# Put that script into a folder accessible by the [[Load|loader]]&lt;br /&gt;
# Add the folder to the &amp;lt;code&amp;gt;TruxtonSettings.xml&amp;lt;/code&amp;gt; file&lt;br /&gt;
# Restart the [[Truxton Service]]&lt;br /&gt;
&lt;br /&gt;
=Exploitation Script Format=&lt;br /&gt;
The exploitation script is in XML format.&lt;br /&gt;
This sample uses a script from [https://www.mac4n6.com/ Sarah Edward's] [https://github.com/mac4n6/APOLLO/blob/master/modules/aggregate_dictionary_scalars.txt aggregate_dictionary_scalars.txt] script in her open source [https://github.com/mac4n6/APOLLO/tree/master APOLLO] framework.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&amp;lt;sqlite&amp;gt;&lt;br /&gt;
  &amp;lt;id&amp;gt;53514C69-7465-287E-AC3B-DE1C115A2B0A&amp;lt;/id&amp;gt;&lt;br /&gt;
  &amp;lt;scriptversion&amp;gt;1&amp;lt;/scriptversion&amp;gt;&lt;br /&gt;
  &amp;lt;author&amp;gt;Sarah Edwards/mac4n6.com/@iamevltwin&amp;lt;/author&amp;gt;&lt;br /&gt;
  &amp;lt;notes&amp;gt;Keeping track of various values on a per-day basis.&amp;lt;/notes&amp;gt;&lt;br /&gt;
  &amp;lt;source&amp;gt;https://github.com/mac4n6/APOLLO/blob/master/modules/aggregate_dictionary_scalars.txt&amp;lt;/source&amp;gt;&lt;br /&gt;
  &amp;lt;info&amp;gt;&amp;lt;/info&amp;gt;&lt;br /&gt;
  &amp;lt;title&amp;gt;Aggregate Dictionary - Scalar&amp;lt;/title&amp;gt;&lt;br /&gt;
  &amp;lt;version&amp;gt;8-14&amp;lt;/version&amp;gt;&lt;br /&gt;
  &amp;lt;filename&amp;gt;ADDataStore.sqlitedb&amp;lt;/filename&amp;gt;&lt;br /&gt;
  &amp;lt;sql&amp;gt;SELECT DATE(DAYSSINCE1970*86400, 'unixepoch') AS DAY, KEY AS &amp;quot;KEY&amp;quot;, VALUE AS &amp;quot;VALUE&amp;quot; FROM SCALARS&amp;lt;/sql&amp;gt;&lt;br /&gt;
&amp;lt;/sqlite&amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==Fields==&lt;br /&gt;
===&amp;lt;code&amp;gt;author&amp;lt;/code&amp;gt;===&lt;br /&gt;
This should identify who to thank for writing the SQL query.&lt;br /&gt;
It is where you give credit where credit is due.&lt;br /&gt;
&lt;br /&gt;
===&amp;lt;code&amp;gt;filename&amp;lt;/code&amp;gt;===&lt;br /&gt;
This optional field contains the names of the SQLite files that have been known to contain the data the query extracts.&lt;br /&gt;
Truxton doesn't currently use this field but may in the future in some form of [[Triage]] load.&lt;br /&gt;
&lt;br /&gt;
===&amp;lt;code&amp;gt;id&amp;lt;/code&amp;gt;===&lt;br /&gt;
This is a globally unique identifier in a special format which corresponds to the &amp;lt;code&amp;gt;[ID]&amp;lt;/code&amp;gt; column of the &amp;lt;code&amp;gt;[Settings]&amp;lt;/code&amp;gt; table.&lt;br /&gt;
It must begin with &amp;lt;code&amp;gt;53514C69-7465&amp;lt;/code&amp;gt; so that the loader can find the scripts in the database.&lt;br /&gt;
&lt;br /&gt;
===&amp;lt;code&amp;gt;info&amp;lt;/code&amp;gt;===&lt;br /&gt;
This optional field contains free form text describing the data extracted by the query.&lt;br /&gt;
&lt;br /&gt;
===&amp;lt;code&amp;gt;notes&amp;lt;/code&amp;gt;===&lt;br /&gt;
This is used and name of the TSV file.&lt;br /&gt;
&lt;br /&gt;
===&amp;lt;code&amp;gt;scriptversion&amp;lt;/code&amp;gt;===&lt;br /&gt;
This is a counter field used by Truxton to update existing queries in the database.&lt;br /&gt;
If the version specified here is greater than the version of this script in the database, the database will be updated.&lt;br /&gt;
To upgrade an existing script, increment this number and restart the [[Truxton Service]]&lt;br /&gt;
&lt;br /&gt;
===&amp;lt;code&amp;gt;source&amp;lt;/code&amp;gt;===&lt;br /&gt;
This is usually a link to the source code or article that contained the SQL query.&lt;br /&gt;
&lt;br /&gt;
===&amp;lt;code&amp;gt;sql&amp;lt;/code&amp;gt;===&lt;br /&gt;
The SQL query.&lt;br /&gt;
Should this query produce a result, a child file will be created containing the results in TSV format.&lt;br /&gt;
&lt;br /&gt;
===&amp;lt;code&amp;gt;title&amp;lt;/code&amp;gt;===&lt;br /&gt;
This is text that will be used in the details report.&lt;br /&gt;
&lt;br /&gt;
===&amp;lt;code&amp;gt;version&amp;lt;/code&amp;gt;===&lt;br /&gt;
This contains the version of the database or operating system the SQLite came from.&lt;/div&gt;</summary>
		<author><name>Sam</name></author>
		
	</entry>
</feed>