Automated SQL Injection Scanning Tool for Vulnerable Website

Authors

  • Mohamad Mustaqim Mohd Shukri Universiti Tun Hussein Onn Malaysia
  • Nordiana Rahim Universiti Tun Hussein Onn Malaysia

Keywords:

sql injection, Penetration Testing, Automated Tool

Abstract

SQL injection (SQLi) remains one of the most prevalent and dangerous security vulnerabilities in web applications, as it allows attackers to manipulate backend database queries and gain unauthorized access to sensitive data. This paper presents the development of an Automated SQL Injection Scanning Tool for vulnerable websites, which aims to improve the efficiency and accuracy of SQLi detection during web security assessments. The tool incorporates multiple detection techniques, including error-based, boolean-based blind, time-based blind, and union-based SQL injection, all executed through HTTP request analysis. Developed using Python and PyQt5, the tool features a modern graphical user interface, a comprehensive payload management system, SQL scanning capabilities, and a detailed reporting module. The development process followed the Agile methodology to support iterative enhancements and prioritize user-centered improvements throughout the project. The effectiveness of the tool was validated through testing on the Damn Vulnerable Web Application (DVWA), a widely used platform for evaluating web security tools. After the tool identified potential SQL injection points, manual verification was performed by injecting SQL payloads directly into DVWA to confirm the vulnerabilities. The results showed that the tool accurately detected all targeted SQL injection vulnerabilities, with no false positives recorded during the testing phase. Future enhancements will focus on expanding the tool’s detection capabilities to include other common web vulnerabilities such as Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF). Additional improvements will include the implementation of evasion techniques and multi-threaded scanning to further increase performance and coverage

Downloads

Download data is not yet available.

Downloads

Published

06-07-2026

Issue

Section

Articles

How to Cite

Mohd Shukri, M. M., & Rahim, N. . (2026). Automated SQL Injection Scanning Tool for Vulnerable Website. Applied Information Technology And Computer Science, 7(1), 1290-1306. https://publisher.uthm.edu.my/periodicals/index.php/aitcs/article/view/20549