sqlmap Commands Explained: Safe Lab Practice and How to Fix SQL Injection
This blog provides a comprehensive guide to using SQLmap, a powerful tool for detecting and exploiting SQL injection vulnerabilities in web applications. It walks through the process of testing the testphp.vulnweb.com website, explaining common SQLmap commands and advanced options like database enumeration, table and column discovery, and data dumping. The guide covers installation methods, testing for vulnerabilities, and using proxies or custom headers for advanced testing. Aimed at both beginners and experienced penetration testers, the blog highlights best practices for ethical hacking and offers practical tips for efficiently identifying and exploiting SQL injection flaws.
Quick answer: sqlmap is an open-source tool that automates detecting SQL injection in web applications. The basic command is sqlmap -u "URL?param=1" --batch, which tests the parameter and reports the injection type and database. Use it only on targets you own or are authorised to test, such as DVWA, and fix findings with parameterised queries and least-privilege database accounts.
Key takeaways
- sqlmap automates SQL injection testing. It does not replace understanding the vulnerability.
- Use it only on lab targets (DVWA, a vendor-provided test site) or systems you have written permission to test. Unauthorised use is illegal under India's IT Act.
- Start with detection only. Options that extract data or touch the operating system are for authorised lab work and are not covered here.
- The fix is in the code: parameterised queries, input validation, least privilege and error handling.
- Havij is discontinued and unmaintained. sqlmap is actively developed.
What is sqlmap?
sqlmap is a free, open-source penetration testing tool that detects and tests SQL injection flaws. It supports many databases, including MySQL, PostgreSQL, Microsoft SQL Server and Oracle, and several injection techniques: boolean-based, error-based, time-based and UNION-based. The project site is sqlmap.org and the code is on GitHub. Older tools such as Havij have been discontinued and are not maintained, so learners should use current tools.
Authorisation first
SQL injection testing can read or change data. Testing a system without permission is an offence under India's IT Act. Use only your own lab, for example DVWA running in a virtual machine, or a deliberately vulnerable site that its owner provides for practice. For real clients, work from a signed scope that allows this kind of testing and says what you may touch.
How do you install sqlmap?
sudo apt update && sudo apt install sqlmap # Kali, Debian, Ubuntu
# or
git clone https://github.com/sqlmapproject/sqlmap.git
cd sqlmap && python3 sqlmap.py --version
sqlmap is already included in Kali Linux. Use Python 3.
What does a basic sqlmap command look like?
Against DVWA on a lab VM (replace the address, cookie and security level with your own):
sqlmap -u "http://192.168.56.101/dvwa/vulnerabilities/sqli/?id=1&Submit=Submit" \
--cookie="PHPSESSID=abc123; security=low" --batch
The -u option gives the URL with a parameter to test. --cookie supplies your logged-in session, because DVWA needs login. --batch accepts default answers to prompts. sqlmap tests each parameter, tells you which ones appear injectable, and names the technique and database type.
What do the main options do?
| Option | Purpose |
|---|---|
-u URL | Target URL including the parameter to test |
--data="a=1&b=2" | Test POST parameters |
-p id | Test only the named parameter |
--cookie | Send session cookies for authenticated pages |
-r request.txt | Load a saved HTTP request, for example from Burp Suite |
--level 1-5 | How many tests and which injection points to try (higher is slower and noisier) |
--risk 1-3 | How risky the payloads are. Higher risk can modify data, so keep low unless in a lab |
--dbms=mysql | Tell sqlmap the database type to save time |
--technique=BEUSTQ | Limit techniques: Boolean, Error, Union, Stacked, Time, Query |
--proxy | Route traffic through a proxy such as Burp for inspection |
--batch | Never ask for input; use defaults |
-v 0-6 | Verbosity of output |
sqlmap has further options for listing databases and tables, and for deeper actions. In a lab you can explore them in the project's usage documentation. For a real engagement, agree in writing what you may enumerate, and do not extract more data than needed to prove the issue.
How do you read the output?
Look for lines such as "Parameter: id (GET)", the injection types found, the payload that worked, and the identified back-end DBMS and web server. The payload shows how the application builds its query. The report you write should explain, in plain language, which input is unsafe and what an attacker could reach.
Why does SQL injection happen?
The application builds an SQL query by joining user input into a string, so input can change the query's meaning. For example, code like "SELECT * FROM products WHERE cat = " + input trusts the input. The OWASP Top 10 lists injection as a leading web risk.
How do developers fix SQL injection?
- Use parameterised queries (prepared statements). The query structure is fixed, and input is sent as data, so it cannot change the query.
- Use an ORM or query builder safely, avoiding raw string concatenation.
- Validate input by type, length and allowed values, as an extra layer and not the only one.
- Least privilege. The application's database account should not be a database administrator or able to read unrelated tables.
- Hide detailed errors from users and log them securely.
- Use a web application firewall as a supplement, not a fix.
- Test in CI with static analysis and dynamic scanning. See the OWASP Cheat Sheet Series for the SQL injection prevention sheet.
# Python example with a parameterised query (psycopg2 / sqlite3 style)
cur.execute("SELECT * FROM products WHERE cat = %s", (cat,))
What are common beginner mistakes with sqlmap?
- Running it against a site they do not own.
- Raising
--leveland--riskwithout understanding the effect. - Trusting output without understanding the underlying injection.
- Forgetting the session cookie, so the scan hits a login page.
Next steps
Practise in a controlled environment through WebAsha's web application hacking and security course. For the discovery side, read discovering SQL injection vulnerabilities.
Related reading
Frequently Asked Questions
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0