Master SQL Injection Testing From Basics to Advanced
This book is ideal for information security professionals and students seeking to master SQLMap with practical application. You will learn to perform SQL injection tests from basic to advanced, integrating tools like Nmap, Burp Suite, OWASP ZAP, and CI/CD pipelines. The content covers injections in SQL databases (MySQL, PostgreSQL, MSSQL, Oracle), NoSQL (MongoDB), automation with Hydra, custom scripts, and WAF evasion.
Includes:
• Installation, configuration, and basic execution of SQLMap
• Enumeration of databases, tables, and columns
• Automation with batch, logs, and multiple targets
• Integration with Nmap, Burp Suite, Jenkins, GitLab, GitHub Actions
• Injection in REST APIs, GraphQL, JSON, XML, and SPA
• Authenticated testing with cookies, sessions, and tokens
• Exploration of Blind SQL Injection and WAF bypass
• Advanced use of tamper scripts and proxying with OWASP ZAP
Master SQLMap to operate precisely in audits, pentests, bug bounties, and strengthen corporate defenses, turning technical knowledge into a strategic advantage.
sqlmap, nmap, burp suite, ci/cd, sql injection, nosql, hydra, blind sql injection, tamper scripts, devsecops
Diego Rodrigues
Technical Author and Independent Researcher
ORCID: https://orcid.org/0009-0006-
StudioD21 Smart Tech Content & Intell Systems
E-mail: [email protected]
LinkedIn: www.linkedin.com/in/
International technical author (tech writer) focusing on structured production of applied knowledge. He is the founder of StudioD21 Smart Tech Content & Intell Systems, where he leads the creation of intelligent frameworks and the publication of technical textbooks supported by artificial intelligence, such as the Kali Linux Extreme series, SMARTBOOKS D21, among others.
Holder of 42 international certifications issued by institutions such as IBM, Google, Microsoft, AWS, Cisco, META, Ec-Council, Palo Alto and Boston University, he works in the fields of Artificial Intelligence, Machine Learning, Data Science, Big Data, Blockchain, Connectivity Technologies, Ethical Hacking and Threat Intelligence.
Since 2003, he has developed more than 200 technical projects for brands in Brazil, USA and Mexico. In 2024, he established himself as one of the greatest authors of technical books of the new generation, with more than 180 titles published in six languages. His work is based on his own applied technical writing protocol TECHWRITE 2.2, aimed at scalability, conceptual precision and practical applicability in professional environments.