Sqlmap is the most popular tool for carrying out automated sql injections against vulnerable systems. In this tutorial we are going to learn to use it. Sqlmap binary option tutorial for beginners one of the most popular and powerful sql injection automation tool out there.

Given a vulnerable http request url, sqlmap can exploit the remote database and do a lot of hacking like extracting database names, tables, columns, all the data in the tables etc. It can even read and write files on the remote file system under certain conditions. Written in python it is one of the most powerful hacking tools out there. Sqlmap is the metasploit of sql injections. Sqlmap is included in pen testing linux distros like kali linux, backtrack, backbox etc. Since its written in python, first you have to install python on your system. On ubuntu install python from synaptic.

On windows install activestate python. In this tutorial we are going to learn how to use sqlmap to exploit a vulnerable web application and see what all can be done with such a tool. To understand this tutorial you should have thorough knowledge of how database driven web applications work. We just added a single quote in the parameter.

If this url throws an error or reacts in an unexpected manner then it is clear that the database has got the unexpected single quote which the application did not escape properly. So in this case this input parameter «id» is vulnerable to sql injection. Now its time to move on to sqlmap to hack such urls. The sqlmap command is run from the terminal with the python interpreter. The above is the first and most simple command to run with the sqlmap tool.