Voltar ao ranking

sqlmapproject/sqlmap

Pythonsqlmap.org

Automatic SQL injection and database takeover tool

sql-injectiondetectionexploitationpythondatabasepentestingapi-securityappsecsecurity-testingsecurity-testing-toolsqlinjectionwebapp-security
Crescimento de estrelas
Estrelas
38k
Forks
6.3k
Crescimento semanal
Issues
25
10k20k30k
mai. de 2012jan. de 2017out. de 2021jul. de 2026
ArtefatosPyPIpip install sqlmap
README

sqlmap

.github/workflows/tests.yml Python 2.7|3.x License x

sqlmap is an open source penetration testing tool that automates the process of detecting and exploiting SQL injection flaws and taking over of database servers. It comes with a powerful detection engine, many niche features for the ultimate penetration tester, and a broad range of switches including database fingerprinting, over data fetching from the database, accessing the underlying file system, and executing commands on the operating system via out-of-band connections.

Screenshots

Screenshot

You can visit the collection of screenshots demonstrating some of the features on the wiki.

Installation

You can download the latest tarball by clicking here or latest zipball by clicking here.

Preferably, you can download sqlmap by cloning the Git repository:

git clone --depth 1 https://github.com/sqlmapproject/sqlmap.git sqlmap-dev

sqlmap works out of the box with Python version 2.7 and 3.x on any platform.

Usage

To get a list of basic options and switches use:

python sqlmap.py -h

To get a list of all options and switches use:

python sqlmap.py -hh

You can find a sample run here. To get an overview of sqlmap capabilities, a list of supported features, and a description of all options and switches, along with examples, you are advised to consult the user's manual.

Translations

Repositórios relacionados
chaitin/SafeLine

SafeLine is a self-hosted WAF(Web Application Firewall) / reverse proxy to protect your web apps from attacks and exploits.

GoGo ModulesGNU General Public License v3.0firewallhttp-flood
ly.safepoint.cloud/fUxS0GW
21.9k1.4k
Hacker0x01/hacker101

Source code for Hacker101.com - a free online web and mobile security class.

SCSSOthereducationhacking
hacker101.com
14.5k2.7k
digininja/DVWA

Damn Vulnerable Web Application (DVWA)

PHPPackagistGNU General Public License v3.0dvwaphp
13.4k5k
reddelexc/hackerone-reports

Top disclosed reports from HackerOne

PythonPyPIwriteupshackerone
6.4k1.1k
payloadbox/sql-injection-payload-list

🎯 SQL Injection Payload List

MIT Licensesql-injectionattacker
ismailtasdelen.medium.com
5.3k1.2k
andresriancho/w3af

w3af: web application attack and audit framework, the open source web vulnerability scanner.

PythonPyPIscannersecurity
w3af.org
4.9k1.2k
Arachni/arachni

Web Application Security Scanner Framework

RubyRubyGemsOtherarachnidom
arachni-scanner.com
4k786
1N3/IntruderPayloads

A collection of Burpsuite Intruder payloads, BurpBounty payloads, fuzz lists, malicious file uploads and web pentesting methodologies and checklists.

BlitzBasicburpsuiteintruder
xerosecurity.com
4k1.2k
codingo/NoSQLMap

Automated NoSQL database enumeration and web application exploitation tool.

PythonPyPIGNU General Public License v3.0nosqlnosql-databases
3.3k625
kleiton0x00/Advanced-SQL-Injection-Cheatsheet

A cheat sheet that contains advanced queries for SQL Injection of all types.

sqlcheatsheet
kleiton0x00.github.io
3.2k702
palahsu/DDoS-Ripper

DDos Ripper a Distributable Denied-of-Service (DDOS) attack server that cuts off targets or surrounding infrastructure in a flood of Internet traffic

PythonPyPIMozilla Public License 2.0ddos-attacksddos-tool
2.9k685
ron190/jsql-injection

jSQL Injection is a Java application for automatic SQL database injection.

JavaMavenGNU General Public License v2.0javasql-injection
ron190.github.io/jsql-injection/
1.8k440