sqlmap Commands Explained: Safe Lab Practice and How to Fix SQL Injection

This blog provides a comprehensive guide to using SQLmap, a powerful tool for detecting and exploiting SQL injection vulnerabilities in web applications. It walks through the process of testing the testphp.vulnweb.com website, explaining common SQLmap commands and advanced options like database enumeration, table and column discovery, and data dumping. The guide covers installation methods, testing for vulnerabilities, and using proxies or custom headers for advanced testing. Aimed at both beginners and experienced penetration testers, the blog highlights best practices for ethical hacking and offers practical tips for efficiently identifying and exploiting SQL injection flaws.

Dec 07, 2024 - 14:55
Updated: 7 days ago
116.6k
sqlmap Commands Explained: Safe Lab Practice and How to Fix SQL Injection

Quick answer: sqlmap is an open-source tool that automates detecting SQL injection in web applications. The basic command is sqlmap -u "URL?param=1" --batch, which tests the parameter and reports the injection type and database. Use it only on targets you own or are authorised to test, such as DVWA, and fix findings with parameterised queries and least-privilege database accounts.

Key takeaways

  • sqlmap automates SQL injection testing. It does not replace understanding the vulnerability.
  • Use it only on lab targets (DVWA, a vendor-provided test site) or systems you have written permission to test. Unauthorised use is illegal under India's IT Act.
  • Start with detection only. Options that extract data or touch the operating system are for authorised lab work and are not covered here.
  • The fix is in the code: parameterised queries, input validation, least privilege and error handling.
  • Havij is discontinued and unmaintained. sqlmap is actively developed.

What is sqlmap?

sqlmap is a free, open-source penetration testing tool that detects and tests SQL injection flaws. It supports many databases, including MySQL, PostgreSQL, Microsoft SQL Server and Oracle, and several injection techniques: boolean-based, error-based, time-based and UNION-based. The project site is sqlmap.org and the code is on GitHub. Older tools such as Havij have been discontinued and are not maintained, so learners should use current tools.

Authorisation first

SQL injection testing can read or change data. Testing a system without permission is an offence under India's IT Act. Use only your own lab, for example DVWA running in a virtual machine, or a deliberately vulnerable site that its owner provides for practice. For real clients, work from a signed scope that allows this kind of testing and says what you may touch.

How do you install sqlmap?

sudo apt update && sudo apt install sqlmap # Kali, Debian, Ubuntu
# or
git clone https://github.com/sqlmapproject/sqlmap.git
cd sqlmap && python3 sqlmap.py --version

sqlmap is already included in Kali Linux. Use Python 3.

What does a basic sqlmap command look like?

Against DVWA on a lab VM (replace the address, cookie and security level with your own):

sqlmap -u "http://192.168.56.101/dvwa/vulnerabilities/sqli/?id=1&Submit=Submit" \
 --cookie="PHPSESSID=abc123; security=low" --batch

The -u option gives the URL with a parameter to test. --cookie supplies your logged-in session, because DVWA needs login. --batch accepts default answers to prompts. sqlmap tests each parameter, tells you which ones appear injectable, and names the technique and database type.

What do the main options do?

OptionPurpose
-u URLTarget URL including the parameter to test
--data="a=1&b=2"Test POST parameters
-p idTest only the named parameter
--cookieSend session cookies for authenticated pages
-r request.txtLoad a saved HTTP request, for example from Burp Suite
--level 1-5How many tests and which injection points to try (higher is slower and noisier)
--risk 1-3How risky the payloads are. Higher risk can modify data, so keep low unless in a lab
--dbms=mysqlTell sqlmap the database type to save time
--technique=BEUSTQLimit techniques: Boolean, Error, Union, Stacked, Time, Query
--proxyRoute traffic through a proxy such as Burp for inspection
--batchNever ask for input; use defaults
-v 0-6Verbosity of output

sqlmap has further options for listing databases and tables, and for deeper actions. In a lab you can explore them in the project's usage documentation. For a real engagement, agree in writing what you may enumerate, and do not extract more data than needed to prove the issue.

How do you read the output?

Look for lines such as "Parameter: id (GET)", the injection types found, the payload that worked, and the identified back-end DBMS and web server. The payload shows how the application builds its query. The report you write should explain, in plain language, which input is unsafe and what an attacker could reach.

Why does SQL injection happen?

The application builds an SQL query by joining user input into a string, so input can change the query's meaning. For example, code like "SELECT * FROM products WHERE cat = " + input trusts the input. The OWASP Top 10 lists injection as a leading web risk.

How do developers fix SQL injection?

  1. Use parameterised queries (prepared statements). The query structure is fixed, and input is sent as data, so it cannot change the query.
  2. Use an ORM or query builder safely, avoiding raw string concatenation.
  3. Validate input by type, length and allowed values, as an extra layer and not the only one.
  4. Least privilege. The application's database account should not be a database administrator or able to read unrelated tables.
  5. Hide detailed errors from users and log them securely.
  6. Use a web application firewall as a supplement, not a fix.
  7. Test in CI with static analysis and dynamic scanning. See the OWASP Cheat Sheet Series for the SQL injection prevention sheet.
# Python example with a parameterised query (psycopg2 / sqlite3 style)
cur.execute("SELECT * FROM products WHERE cat = %s", (cat,))

What are common beginner mistakes with sqlmap?

  • Running it against a site they do not own.
  • Raising --level and --risk without understanding the effect.
  • Trusting output without understanding the underlying injection.
  • Forgetting the session cookie, so the scan hits a login page.

Next steps

Practise in a controlled environment through WebAsha's web application hacking and security course. For the discovery side, read discovering SQL injection vulnerabilities.

Related reading

Frequently Asked Questions

sqlmap is an open-source tool that automates detecting SQL injection vulnerabilities in web applications and identifies the database in use. Penetration testers use it in authorised tests to confirm and demonstrate the issue.

The basic form is sqlmap -u "http://target/page?id=1" --batch, run only against a lab or authorised target. Add --cookie for authenticated pages and use -p to test a specific parameter.

No. Use sqlmap only on systems you own or have written permission to test. Unauthorised testing is an offence under India's IT Act. Practise on DVWA or other deliberately vulnerable labs.

Use parameterised queries or prepared statements, avoid building SQL by string concatenation, validate input, give the database account least privilege and hide detailed errors. Test regularly.

No. Havij is discontinued and unmaintained. Learners should use current, maintained tools such as sqlmap in authorised labs, and focus on understanding how SQL injection works and how to fix it.

--level sets how many tests and injection points sqlmap tries, and --risk sets how aggressive the payloads are. Higher values are slower, noisier and riskier, so keep them low outside a lab.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0
Vaishnavi

Vaishnavi is a skilled tech professional at the Ethical Hacking Training Institute in Pune, responsible for managing and optimizing the technical infrastructure that supports advanced cybersecurity education. With deep expertise in network security, backend operations, and system performance, she ensures that practical labs, online modules, and assessments run smoothly and securely. Her behind-the-scenes contributions play a vital role in delivering a seamless and secure learning experience for aspiring ethical hackers.