sqlmap
The definitive automatic SQL injection and database takeover tool. Deep detection and exploitation across many DBMSes.
Tags: sqli, scanner, python, classic
- Category
- inject
- Maintenance signal
- active
Project repository · Documentation
Use this when: SQLi. Point it at a parameter you already suspect, on a row you own.
Install
git
git clone --depth 1 https://github.com/sqlmapproject/sqlmap.gitapt
sudo apt install -y sqlmapCommand templates
Test a URL
sqlmap -u '{url}' --batch --risk {risk} --level {level}From request file
sqlmap -r {request} --batch --dbs