← Back to Tools
Web Hacking

SQLMap

Automated SQL injection tool that detects and exploits database vulnerabilities.

Category
Web Hacking
Platform
Linux / Kali
Type
CLI / Open Source
Skill Level
Beginner → Advanced

What is SQLMap?

SQLMap is a widely used tool in the Web Hacking phase of penetration testing. It provides security professionals with the ability to gather intelligence, test systems, and identify weaknesses in a controlled, authorized environment.

⚠ Legal Notice

Only use this tool on systems you own or have explicit written authorization to test. Unauthorized use is a criminal offense under Pakistan's PECA 2016 and similar laws worldwide.

Installation

On Kali Linux, most tools are pre-installed. If not, use the following:

# Update package list first
sudo apt update

# Install SQLMap
sudo apt install sqlmap -y

# Verify installation
sqlmap --version

Basic Usage

Start with these fundamental commands to get familiar with the tool:

# Basic syntax
sqlmap [options] [target]

# Get help
sqlmap --help

# Run a basic scan or operation
sqlmap -h

Common Use Cases

Tips & Best Practices

Always document your findings and commands during a test. Keep your tools updated and understand each flag before using it in a real engagement.