sqlmap/README.md

47 lines
2.4 KiB
Markdown
Raw Normal View History

2013-05-28 12:49:24 +04:00
sqlmap
==
2013-04-04 18:40:15 +04:00
2012-06-27 13:12:48 +04:00
sqlmap is an open source penetration testing tool that automates the process of detecting and exploiting SQL injection flaws and taking over of database servers. It comes with a powerful detection engine, many niche features for the ultimate penetration tester and a broad range of switches lasting from database fingerprinting, over data fetching from the database, to accessing the underlying file system and executing commands on the operating system via out-of-band connections.
2013-04-29 13:14:48 +04:00
![Screenshot](https://raw.github.com/wiki/sqlmapproject/sqlmap/images/sqlmap_screenshot.png)
2013-05-28 12:49:24 +04:00
Installation
----
2013-04-04 19:05:04 +04:00
2013-05-28 12:48:09 +04:00
You can download the latest tarball by clicking [here](https://github.com/sqlmapproject/sqlmap/tarball/master) or latest zipball by clicking [here](https://github.com/sqlmapproject/sqlmap/zipball/master).
Preferably, you can download sqlmap by cloning the [Git](https://github.com/sqlmapproject/sqlmap) repository:
2013-04-04 19:05:04 +04:00
git clone https://github.com/sqlmapproject/sqlmap.git sqlmap-dev
2013-05-28 12:48:09 +04:00
sqlmap works out of the box with [Python](http://www.python.org/download/) version '''2.6.x''' and '''2.7.x''' on any platform.
2013-05-28 12:49:24 +04:00
Usage
----
2013-04-04 19:05:04 +04:00
2013-04-04 19:08:36 +04:00
To get a list of basic options and switches use:
2013-04-04 19:05:04 +04:00
python sqlmap.py -h
2013-04-04 19:08:36 +04:00
To get a list of all options and switches use:
2013-04-04 19:05:04 +04:00
python sqlmap.py -hh
2013-05-28 12:48:09 +04:00
You can find a sample run [here](https://gist.github.com/stamparm/5335217).
To get an overview of sqlmap capabilities, list of supported features and description of all options and switches, along with examples, you are advised to consult the [user's manual](https://github.com/sqlmapproject/sqlmap/wiki).
2013-04-04 19:05:04 +04:00
2013-05-28 12:49:24 +04:00
Links
----
* Homepage: http://sqlmap.org
2012-08-23 21:08:57 +04:00
* Download: [.tar.gz](https://github.com/sqlmapproject/sqlmap/tarball/master) or [.zip](https://github.com/sqlmapproject/sqlmap/zipball/master)
2012-07-16 18:03:04 +04:00
* Commits RSS feed: https://github.com/sqlmapproject/sqlmap/commits/master.atom
* Issue tracker: https://github.com/sqlmapproject/sqlmap/issues
* User's manual: https://github.com/sqlmapproject/sqlmap/wiki
2013-05-28 12:48:09 +04:00
* Frequently Asked Questions (FAQ): https://github.com/sqlmapproject/sqlmap/wiki/FAQ
* Mailing list subscription: https://lists.sourceforge.net/lists/listinfo/sqlmap-users
2012-07-16 18:03:04 +04:00
* Mailing list RSS feed: http://rss.gmane.org/messages/complete/gmane.comp.security.sqlmap
* Mailing list archive: http://news.gmane.org/gmane.comp.security.sqlmap
* Twitter: [@sqlmap](https://twitter.com/sqlmap)
2012-07-16 18:03:04 +04:00
* Demos: [#1](http://www.youtube.com/user/inquisb/videos) and [#2](http://www.youtube.com/user/stamparm/videos)