Using sqlmap to find SQL Injection on the login page
SQL Injections are always in the OWASP top three in every iteration of OWASP Web Top 10 Vulnerabilities for a reason. They are the most damaging to web applications and thus to businesses as well. Finding an SQL Injection is difficult, but if you happen to find one, exploiting it manually till you get access on the server is even harder and time consuming. Therefore, it is important to use an automated approach because during the penetration testing activity, time is always running out and you will always want to confirm the existence of an SQL Injection sooner than later.
Sqlmap is an open source penetration testing tool that automates the process of detecting and exploiting SQL Injection flaws and taking over of database servers written in Python and being regularly maintained by their developers. SQLMap has become a powerful tool and is very reliable in identifying and detecting SQL Injection in various parameters.
In this recipe, we...