SQLMap Cheat Sheet
sqlmap -h
View the basic help menu
sqlmap -hh
View the advanced help menu
Run SQLMap without asking for user input
SQLMap with POST request
POST request specifying an injection point with an asterisk
sqlmap -r req.txt
Passing an HTTP request file to SQLMap
sqlmap ... --cookie='PHPSESSID=ab4530f4a7d10448457fa8b0eadac29c'
Specifying a cookie header
sqlmap -u www.target.com --data='id=1' --method PUT
Specifying a PUT request
Store traffic to an output file
Specify verbosity level
sqlmap -u "www.example.com/?q=test" --prefix="%'))" --suffix="-- -"
Specifying a prefix or suffix
sqlmap -u www.example.com/?id=1 -v 3 --level=5
Specifying the level and risk
Basic DB enumeration
Table enumeration
Table/row enumeration
Conditional enumeration
Database schema enumeration
Searching for data
Password enumeration and cracking
Anti-CSRF token bypass
sqlmap --list-tampers
List all tamper scripts
Check for DBA privileges
Reading a local file
Writing a file
Spawning an OS shell
Last updated