Web Application
sqlmap
Automatic SQL injection detection and exploitation tool.
Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.
Destructive dumps can violate RoE — confirm data handling rules.
When
You have a potentially injectable parameter and written authorization.
How
Provide URL/request file; detect DBMS; dump carefully with limits.
Why
Deep SQLi automation; still requires understanding of injection theory.
Commands & usage
sqlmap -u 'https://example.com/item?id=1' --batch --dbs
sqlmap -r request.txt --level 3 --risk 2
sqlmap -u 'https://example.com/item?id=1' -D db -T users --dump
Commands are educational examples. Adapt hosts, paths, and rates to your authorized scope.
OWASP
Tags
Related in Web Application
ffuf
Fast web fuzzer for directories, vhosts, parameters, and more.
Gobuster
Directory/DNS/vhost brute-forcing tool written in Go.
Feroxbuster
Recursive content discovery tool with smart filtering.
dirsearch
Feature-rich web path scanner in Python.
Wfuzz
Flexible web application fuzzer for params, headers, auth, etc.
Nuclei
Template-based vulnerability scanner with huge community template set.