sqlmap
E192901
sqlmap is an open-source penetration testing tool that automates the detection and exploitation of SQL injection vulnerabilities in web applications.
All labels observed (1)
| Label | Occurrences |
|---|---|
| sqlmap canonical | 1 |
Statements (88)
| Predicate | Object |
|---|---|
| instanceOf |
command-line tool
ⓘ
open-source software ⓘ penetration testing tool ⓘ security testing tool ⓘ software tool ⓘ |
| category |
Database security software
ⓘ
Penetration testing software ⓘ Web security software ⓘ |
| developedIn |
Python
ⓘ
surface form:
Python programming language
|
| genre |
SQL injection testing
ⓘ
database security ⓘ web application security ⓘ |
| hasComponent |
OS takeover module
ⓘ
database fingerprinting module ⓘ enumeration module ⓘ tamper script engine ⓘ |
| hasFeature |
OS command execution via SQL injection
ⓘ
WAF evasion techniques ⓘ automatic detection of SQL injection flaws ⓘ automatic exploitation of SQL injection flaws ⓘ automatic recognition of database management system ⓘ automatic recognition of web application technology stack ⓘ batch mode ⓘ command-line interface ⓘ data dumping ⓘ database schema enumeration ⓘ database takeover ⓘ database user enumeration ⓘ integration with Tor and proxies for anonymity ⓘ logging of requests and responses ⓘ proxy support ⓘ resume of interrupted data dumps ⓘ session management ⓘ support for custom payloads ⓘ support for multiple levels of verbosity ⓘ support for user-defined injection points ⓘ support for various injection techniques ⓘ tamper scripts ⓘ tor network support ⓘ |
| implements |
SQL injection detection
ⓘ
SQL injection exploitation ⓘ blind SQL injection ⓘ data extraction ⓘ database enumeration ⓘ database fingerprinting ⓘ error-based SQL injection ⓘ file system access via SQL injection ⓘ out-of-band SQL injection ⓘ time-based SQL injection ⓘ |
| license |
GNU General Public License
ⓘ
surface form:
GNU General Public License v2
GNU General Public License ⓘ
surface form:
GPL-2.0-only
|
| operatingSystem |
Linux
ⓘ
Unix-like systems ⓘ Windows ⓘ macOS ⓘ |
| primaryLanguage | Python ⓘ |
| repository | https://github.com/sqlmapproject/sqlmap ⓘ |
| sourceModel | open source ⓘ |
| supports |
Cookie parameters
ⓘ
DNS exfiltration ⓘ Firebird ⓘ GET parameters ⓘ HTTP ⓘ HTTP headers ⓘ HTTPS ⓘ IBM DB2 ⓘ MariaDB ⓘ SQL Server ⓘ
surface form:
Microsoft SQL Server
MySQL ⓘ Oracle Database ⓘ POST parameters ⓘ PostgreSQL ⓘ SAP MaxDB ⓘ SQLite ⓘ Sybase ⓘ URL query strings ⓘ authentication mechanisms testing ⓘ cookie-based sessions ⓘ custom HTTP headers ⓘ stacked queries ⓘ stored SQL injection ⓘ union-based SQL injection ⓘ |
| usedFor |
ethical hacking
ⓘ
penetration testing ⓘ security auditing ⓘ vulnerability assessment ⓘ |
| website | https://sqlmap.org/ ⓘ |
| writtenIn | Python ⓘ |
Referenced by (1)
Full triples — surface form annotated when it differs from this entity's canonical label.