Operator tip · sqlmap
Level/risk deliberately
Start low: default level/risk, then climb. Add --tamper only when a WAF actually blocks. Always --batch in labs you own.
Guide
sqlmap's higher --level / --risk values try more payloads — including some that are noisy or destructive. Climbing without a reason is how you DoS a shared lab DB.
Why it matters
Default settings catch many classic injections. Raise level/risk only after a negative with evidence you are on a parameterized-looking parameter that still smells injectable. Add --tamper when a WAF clearly interferes — not as a first switch.
How-to
sqlmap -u "http://TARGET/item?id=1" --batch --cookie="SESSION=…" # still nothing interesting? sqlmap -u "…" --batch --level=2 --risk=1 # WAF blocking? sqlmap -u "…" --batch --tamper=space2comment
--batchskips prompts — fine on boxes you own.- Prefer
-r request.txtfrom Burp for authenticated flows. - Do not combine max level/risk + aggressive tampers on day one.