Operator tip · sqlmap

Level/risk deliberately

Start low: default level/risk, then climb. Add --tamper only when a WAF actually blocks. Always --batch in labs you own.

med sqlisqlmapwaf
/sqlmap/ · /tips/sqlmap-level-risk/

Guide

sqlmap's higher --level / --risk values try more payloads — including some that are noisy or destructive. Climbing without a reason is how you DoS a shared lab DB.

Why it matters

Default settings catch many classic injections. Raise level/risk only after a negative with evidence you are on a parameterized-looking parameter that still smells injectable. Add --tamper when a WAF clearly interferes — not as a first switch.

How-to

sqlmap -u "http://TARGET/item?id=1" --batch --cookie="SESSION=…"
# still nothing interesting?
sqlmap -u "…" --batch --level=2 --risk=1
# WAF blocking?
sqlmap -u "…" --batch --tamper=space2comment