All tools

Web Application

sqlmap

Automatic SQL injection detection and exploitation tool.

intermediate
Linux
Windows
macOS
Exploitation
Enumeration

Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.

Destructive dumps can violate RoE — confirm data handling rules.

When

You have a potentially injectable parameter and written authorization.

How

Provide URL/request file; detect DBMS; dump carefully with limits.

Why

Deep SQLi automation; still requires understanding of injection theory.

Commands & usage

sqlmap -u 'https://example.com/item?id=1' --batch --dbs
sqlmap -r request.txt --level 3 --risk 2
sqlmap -u 'https://example.com/item?id=1' -D db -T users --dump

Commands are educational examples. Adapt hosts, paths, and rates to your authorized scope.

Tags

sqli
web
injection

Related in Web Application