Detection
Test with single quotes and boolean conditions: a syntax error or changed response confirms the injection point.sqlmap
Let sqlmap automate discovery and extraction: use-r with a saved Burp request for the cleanest results.
-r with a saved Burp request for the cleanest results.