Terminal Dojo
Help العربية Sign inGet started

Command library / sqlmap

sqlmap

BashDraft — pending expert review3 practice missions

Detect and exploit SQL injection automatically

Tests a URL parameter for SQL injection and, if vulnerable, can automatically enumerate databases, tables and rows. -u is the only required flag; --batch stops it from ever pausing to ask an interactive question, which matters for scripted lab runs.

Practice sqlmap

Usage

sqlmap -u url [--batch] [--dbs] [--dump]
Scope: Only against applications you own or are explicitly authorised to test. SQL injection testing can modify or expose real data — never point this at a production system without written authorisation.

Options and flags

Examples

Common mistakes

sqlmap "http://target/page.php?id=1" sqlmap -u "http://target/page.php?id=1"

The target is never a bare argument — sqlmap always needs it introduced with -u.

Related commands

niktogobuster