Skip to content

SQLMap

Automated SQL injection detection engine

VerifiedPentesting· Web Application TestingIntermediateGPL-3.0Open sourceEntry revised 12 Jan 2026
  • Linux
  • macOS
  • Windows
  • Kali
  • Parrot
  • Docker
  • Source

Overview

8 commands documented

SQLMap detects and confirms SQL injection flaws by generating and sending probes, then reporting what the database reveals back. It is a verification tool: it turns a suspicious parameter into a reproducible finding — or rules the parameter out.

It can also enumerate schema, read limited files and, on some database configurations, execute further actions. Those capabilities are only appropriate inside a signed scope with a documented test plan; in a report, the enumeration of your own test data is the evidence, not an exploit demonstration.

Supported platforms

7

Documented install or usage guidance

Learning curve

intermediate

Difficulty of becoming productive, not of the underlying theory

Tags

sql injection, database, web, verification, owasp

Dataset entry

sqlmap.ts

Reviewed 2026-01-12

Installation

Grouped by platform. Elevation requirements are marked per method.

Official archive + Python

RecommendedzipOfficial

SQLMap ships as a pure-Python archive: download it, install Python 3, then run sqlmap.py.

  • Install Python from python.org and tick 'Add to PATH'; the SQLite/PostgreSQL client libraries are optional.
Open official source

Package availability follows your distribution and enabled repositories. Entry revised 12 Jan 2026 — confirm the current release on the project's own download page.

Commands

8 entries

Every command carries its purpose, an example where useful, and the limitations that change how you should read the output.

01Detect an injection point on one parameter

bash

Runs detection techniques against a single GET parameter and reports which ones produced a true/false differential.

python3 sqlmap.py -u 'http://192.0.2.20/item.php?id=17' -p id --batch --level 1 --risk 1
  • Only run against systems you are authorized to test, and keep the request rate agreed in the scope document.

Notes

  • `--batch` accepts defaults so the run is non-interactive; `--level`/`--risk` bound how many tests are attempted. Start at 1/1.

02Read the DBMS banner

bash

Confirms backend DBMS, version and operating system as reported through the injection point.

python3 sqlmap.py -u 'http://192.0.2.20/item.php?id=17' -p id --banner --batch

Example output

Illustrative only — real output depends on the target, version and your position on the network.

[INFO] the back-end DBMS is MySQL
back-end DBMS: MySQL >= 8.0

Notes

  • A banner alone is a low-severity data-disclosure finding; it becomes material when combined with what else is reachable.

03Enumerate database names

bash

Lists schemas visible to the connection the application uses.

python3 sqlmap.py -u 'http://192.0.2.20/item.php?id=17' -p id --dbs --batch --dbms mysql

Notes

  • Declaring `--dbms` skips fingerprinting of other engines, which shortens the run and reduces noise.
  • Enumerating tables containing personal data is usually out of scope: stop at the schema list and ask the client what the names mean.

04Dump a bounded number of rows

bash

Proves read access with the smallest possible sample instead of exfiltrating a table.

python3 sqlmap.py -u 'http://192.0.2.20/item.php?id=17' -p id -D appdb -T users -C id,username --start 1 --count 5 --batch
  • Never dump credentials or personal data during an assessment unless the rules of engagement explicitly authorise it.

Notes

  • `--start`/`--count` are also the difference between a defensible sample and a reportable data breach.

05Run from a saved request

bash

Feeds a raw HTTP request file so headers, cookies, CSRF tokens and JSON bodies are used exactly as captured.

python3 sqlmap.py -r login.req --batch --forms

Notes

  • `--forms` parses the body's form fields as parameters. Delete session values you do not want replayed before saving the file.

06Test filter handling with a tamper script

bash

Applies encoding transformations to probes so you can see whether an input filter is actually mitigating the flaw.

python3 sqlmap.py -u 'http://192.0.2.20/search?q=sock' -p q --tamper=space2comment,between --batch

Notes

  • List what is available with `--list-tampers`. A filter that only strips spaces is a weak control, and that is the finding.

07Test URLs exported from a crawler

bash

Works through a list of URLs rather than one parameter, which is how a whole application gets covered.

python3 sqlmap.py -m urls.txt --batch --threads 2 --delay 1
  • `--threads` multiplies request volume. Keep it at 1-2 against anything that also serves real users.

Notes

  • Pair with a scoped crawler export and log which URLs were tested.

08Reset cached results

bash

Clears the per-URL cache so retests do not silently reuse yesterday's conclusion.

python3 sqlmap.py -u 'http://192.0.2.20/item.php?id=17' --flush-session --batch

Notes

  • The `sqlmap` output directory holds session and log files; store it with the engagement record and clean it afterwards.

Worked examples

Sequences of commands in the order they are used, with what you should expect to learn from each.

Turning a suspicion into a finding

A 'Ref' parameter in a partner portal echoes a SQL error when you type a quote.

  1. 1

    Confirm with the minimum detection level

    python3 sqlmap.py -r ref.req -p Ref --batch --level 1 --risk 1
  2. 2

    Establish what is reachable, without reading user data

    python3 sqlmap.py -r ref.req -p Ref --banner --current-user --current-db --batch
  3. 3

    Retest after the patch, with a clean session

    python3 sqlmap.py -r ref.req -p Ref --flush-session --batch --level 1

A finding with an exact reproduction, an impact statement grounded in what was actually reachable, and a verified retest.

What it is used for

  • Confirm or dismiss an injection suspicion

    Remove ambiguity from a manual test before it reaches a report.

  • Validate a fix

    Re-run the same probes after remediation and keep both outputs.

  • Lab training

    Understand how blind and error-based detection differ, against deliberately vulnerable apps.

Common errors

Symptoms you will actually hit, with the cause and the legitimate fix.

No injection points found on a parameter you know is vulnerableCause 1/4

Possible causes

  • Insufficient level/risk, anti-CSRF token expiring, redirect handling, or an auth cookie that lapsed mid-run.

Usual fix

Re-save the request with a fresh cookie, raise `--level 3 --risk 2`, add `--no-redirect` or `--ignore-redirects` as appropriate, and confirm the session with `--safe-url`.

Run aborts with 'HTTP error 403' or a WAF page every few probesCause 2/4

Possible causes

  • Rate limiting or signature blocking.

Usual fix

Add `--delay`, `--timeout`, `--retries`, and lower `--threads`. If the WAF is the control under test, document that it blocked the tool rather than working around it without approval.

python3 sqlmap.py -u URL -p id --batch --delay 2 --timeout 30 --threads 1
Stale results appear even after the code was patchedCause 3/4

Possible causes

  • Cached session data in the output directory.

Usual fix

Use `--flush-session` for a retest, or `--purge-output` to clear the whole directory at engagement end.

SyntaxError / unsupported Python on a fresh machineCause 4/4

Possible causes

  • Old interpreter, or Python 2 assumptions from an outdated tutorial.

Usual fix

Run with `python3` explicitly and install a current upstream checkout.

Tips

  • Prefer `-r request.req` over `-u`: it keeps the exact headers, so what you tested matches what the browser sends.
  • Run `--dbms` explicitly once you know the engine — fewer probes, faster and cleaner logs.
  • Take the log file from the output directory into your evidence folder; it is the record of what you actually sent.
  • In a report, describe the reachable data class and the confirmation method, not the number of rows you could have taken.

Alternatives & comparisons

Not documented yet: sqlmap has no drop-in equivalent for automated verification; manual testing plus a proxy remains the primary method. Request an entry and it will link up automatically.Request a tool

Side-by-side

References

Where to verify anything on this page. External links open in a new tab.

Found something wrong?Suggest an editMore in Pentesting