Sqlmap is one penetration testing open source tool that automates the process of detecting and exploiting SQL injection flaws and taking over server databases.
Specifications
- Full support for database management systems MySQL, Oracle , PostgreSQL , Microsoft SQL Server , Microsoft Access , IBM DB2 , SQLite , Firebird , Sybase , SAP MaxDB and HSQLDB .
- Full support for five SQL import techniques: boolean-based blind, time-based blind, error-based, UNION queryand stacked queries.
- Support for directly to the database without doing it via SQL injection, providing DBMS credentials, IP address, port and name database.
- Is it possible to provide a single URL of the target, get the list of targets from archives registration of requests server of Burp or his server WebScarab , get the entire HTTP request from a text file or get the list of targets by providing sqlmap with a Google dork query on Google and analyzes the σελίδα of its results. You can also define a field based on the regular expression used to specify the addresses to be parsed.
- Option to define it maximum number of HTTP (S) (multi-threading) requests to speed up SQL injection techniques. Conversely, it is also possible to specify the number of seconds between each HTTP request (S).
- Manages automatically HTTP header Set cookie from the application, restoring the session if it expires. Testing and operating at these prices is also supported. Conversely, you can also ignore any header Set cookie .
- HTTP protocol support Basic, Digest, NTLM and certificate .
- Support HTTP Proxy (S) to transmit requests to the destination application that also works with HTTPS requests and certified proxies.
- Options for price falsification HTTP header Referer and price HTTP header set User Agent are user-defined or randomly selected from a text file.
- Support for analysis of HTML formsfrom the destination URL and create HTTP requests (S) on these pages to test form parameters for vulnerabilities.
- Automatically saves the session (queries and their output, even if partially retrieved) to a real-time text file when downloading data, and continues the injectionanalyzing the session file.
- Support for playback of back-end database structure and table entriesin a local SQLite 3 database.
- Option to update sqlmap to the latest development version from the subversion repository.
- Support for parsing HTTP (S) responses and displaying any DBMS error message to the user.
- Integration with projects open IT security code such as Metasploit and w3af .
You can download the program from here.