sqlmapproject/sqlmap

Pythonsqlmap.org

Automatic SQL injection and database takeover tool

sql-injectiondetectionexploitationpythondatabasepentestingapi-securityappsecsecurity-testingsecurity-testing-toolsqlinjectionwebapp-security
Croissance des étoiles
Étoiles
38.4k
Forks
6.4k
Croissance hebdomadaire
+48
Issues
25
10k20k30k
mai 2012févr. 2017nov. 2021sept. 2026
ArtefactsPyPI
README

sqlmap

.github/workflows/tests.yml Python 2.7|3.x License x

sqlmap is an open source penetration testing tool that automates the process of detecting and exploiting SQL injection flaws and taking over of database servers. It comes with a powerful detection engine, many niche features for the ultimate penetration tester, and a broad range of switches including database fingerprinting, over data fetching from the database, accessing the underlying file system, and executing commands on the operating system via out-of-band connections.

Screenshots

Screenshot

You can visit the collection of screenshots demonstrating some of the features on the wiki.

Installation

You can download the latest tarball by clicking here or latest zipball by clicking here.

Preferably, you can download sqlmap by cloning the Git repository:

git clone --depth 1 https://github.com/sqlmapproject/sqlmap.git sqlmap-dev

sqlmap works out of the box with Python version 2.7 and 3.x on any platform.

Usage

To get a list of basic options and switches use:

python sqlmap.py -h

To get a list of all options and switches use:

python sqlmap.py -hh

You can find a sample run here. To get an overview of sqlmap capabilities, a list of supported features, and a description of all options and switches, along with examples, you are advised to consult the user's manual.

Translations

Dépôts similaires
chaitin/SafeLine

SafeLine is a self-hosted WAF(Web Application Firewall) / reverse proxy to protect your web apps from attacks and exploits.

GoGo ModulesGNU General Public License v3.0firewallhttp-flood
ly.safepoint.cloud/fUxS0GW
22.5k1.5k
Hacker0x01/hacker101

Source code for Hacker101.com - a free online web and mobile security class.

SCSStutorialOthereducationhacking
hacker101.com
14.5k2.7k
digininja/DVWA

Damn Vulnerable Web Application (DVWA)

PHPPackagistGNU General Public License v3.0dvwaphp
13.6k5.1k
reddelexc/hackerone-reports

Top disclosed reports from HackerOne

PythonPyPIawesomewriteupshackerone
6.5k1.1k
andresriancho/w3af

w3af: web application attack and audit framework, the open source web vulnerability scanner.

PythonPyPIscannersecurity
w3af.org
4.9k1.2k
Arachni/arachni

Web Application Security Scanner Framework

RubyRubyGemsOtherarachnidom
arachni-scanner.com
4k783
1N3/IntruderPayloads

A collection of Burpsuite Intruder payloads, BurpBounty payloads, fuzz lists, malicious file uploads and web pentesting methodologies and checklists.

BlitzBasicawesomeburpsuiteintruder
xerosecurity.com
4k1.2k
codingo/NoSQLMap

Automated NoSQL database enumeration and web application exploitation tool.

PythonPyPIGNU General Public License v3.0nosqlnosql-databases
3.3k628
kleiton0x00/Advanced-SQL-Injection-Cheatsheet

A cheat sheet that contains advanced queries for SQL Injection of all types.

tutorialsqlcheatsheet
kleiton0x00.github.io
3.3k704
palahsu/DDoS-Ripper

DDos Ripper a Distributable Denied-of-Service (DDOS) attack server that cuts off targets or surrounding infrastructure in a flood of Internet traffic

PythonPyPIcliMozilla Public License 2.0ddos-attacksddos-tool
2.9k694
ron190/jsql-injection

jSQL Injection is a Java application for automatic SQL database injection.

JavaMavenGNU General Public License v2.0javasql-injection
ron190.github.io/jsql-injection/
1.8k439
Safe3/uusec-waf

Industry-leading free, high-performance, AI and semantic technology Web Application Firewall and API Security Gateway (WAAP) - UUSEC WAF.

ShellBSD 2-Clause "Simplified" Licensewafapplication-security
waf.uusec.com
1.7k170