Here we have first used SQL map to extract confidential data from a target's database which automates the process of detecting and exploiting SQL injection flaws.
Also we write SQL query to perform a SQL injection attack to retrive the names of databases on the target's server, and understand how sqlmap works behind the curtains.