SQLMap
web security
An open source penetration testing tool that automates the process of detecting and exploiting SQL injection flaws.
SQL injectiondatabaseautomation
Legal & Ethical Use
- Authorized SQL injection testing
- Database security assessment
- Security research
- Bug bounty programs
Installation
bash
$
sudo apt install sqlmapBasic Commands
bash
$
sqlmap -u "http://target.com?id=1"Test URL for SQL injection
bash
$
sqlmap -u "url" --dbsEnumerate databases
bash
$
sqlmap -u "url" --tables -D dbnameList tables in database
bash
$
sqlmap -u "url" --dump -T tablenameDump table contents
Advantages
- Powerful automation
- Many database types
- Extensive options
- Active development
Limitations
- Can be dangerous
- Requires understanding
- May cause damage if misused