Operator tip · sqlmap
Dump with intent
--tables / --columns before --dump. Know what you're extracting and why it is in scope.
Guide
--dump feels like winning. It is also how you exfiltrate an entire PII table you did not need for the finding. Enumerate with intent.
Why it matters
Good reports show you confirmed SQLi, identified the sensitive table, and extracted the minimum rows that prove impact. Dumping everything slows you down, bloats loot, and can violate scope even on a "vulnerable by design" app if PII rules apply.
How-to
sqlmap -u "…" --batch --dbs sqlmap -u "…" --batch -D appdb --tables sqlmap -u "…" --batch -D appdb -T users --columns sqlmap -u "…" --batch -D appdb -T users -C id,username --dump
- Prefer
--count/ few columns over full table dumps. - Scrub loot from shared machines when the lab ends.
- In writeups: show the query path + one redacted row, not a CSV dump.