> For the complete documentation index, see [llms.txt](https://ret2basic.gitbook.io/ctfnote/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ret2basic.gitbook.io/ctfnote/web/sql-injection-sqli/sqlmap/code-review-tamper.md).

# Code Review: tamper

## What is tamper?

The `tamper` module in sqlmap modifies the payload in order to **bypass WAF**. The syntax is:

```bash
sqlmap -u <url> --tamper <tamper_script>
```

There are 53 official tamper scripts provided by sqlmap, which can be found on its Github repo:

{% embed url="<https://github.com/sqlmapproject/sqlmap/tree/master/tamper>" %}
sqlmap tamper
{% endembed %}

And we can write our own tamper scripts in some cases, just follow the template and write the `def tamper(payload, **kwargs)` function.

## Template

```python
#!/usr/bin/env python

from lib.core.enums import PRIORITY

__priority__ = PRIORITY.LOW

def dependencies():
    pass

def tamper(payload, **kwargs):
 
    retVal = payload

    # tamper the payload
    if payload:
        pass

    return retVal
```

###

## Reference
