News
sqlmap is an open source penetration testing tool that automates the process of detecting and exploiting SQL injection flaws and taking over of database servers. It comes with a powerful detection engine, many niche features for the ultimate penetration tester and a broad range of switches lasting from database fingerprinting, over data fetching from the database, to accessing the underlying file system and executing commands on the operating system via out-of-band connections.
getsystem command which include, among others,
the
kitrap0d technique (
MS10-015).
sqlmap can be downloaded from its SourceForge File List page. It is available in two formats:
You can also checkout the latest development version from the subversion repository:
$ svn checkout https://svn.sqlmap.org/sqlmap/trunk/sqlmap sqlmap-dev
This is strongly recommended before reporting any bug to the mailing list.
The sqlmap-users@lists.sourceforge.net mailing list is
the preferred way to ask questions, report bugs, suggest new
features and discuss with other users,
contributors and
the developers. To subscribe use the online
web form.
The mailing list is archived online on SourceForge,
Gmane and
is available also via Gmane RSS
feed.
sqlmap is released under the terms of the General Public License v2. sqlmap is copyrighted by its developers.
Miroslav Stampar
(@stamparm) - Developer
PGP Key ID: 0xB5397B1B
You can contact both developers by writing to dev@sqlmap.org.
We are looking for people who can write some clean Python code, are up to do security research, know about web application security, database assessment and takeover, software refactoring and are motivated to join the development team.
If this sounds interesting to you, get in touch!