当前位置:网站首页>Sqlmap tutorial (III) practical skills II
Sqlmap tutorial (III) practical skills II
2022-07-06 05:58:00 【A τθ】
One 、–technique Use the specified injection method
In some projects , It is inevitable that the network will react slowly ,idc And testing sqlmap The ability of . As a professional penetration tester , We must be fast, accurate and ruthless .
There are some SQL The injection point only allows time injection , It is designated at this time SQLMAP The injection type of is T
Here are --technique Explanation of the value of the parameter :
B:Boolean-basedblindSQLinjection( Boolean Injection )
E:Error-basedSQLinjection( Error reporting injection )
U:UNIONquerySQLinjection( Query injection can be combined )
S:StackedqueriesSQLinjection( Multi statement query injection )
T:Time-basedblindSQLinjection( Injection based on time delay )
Q:InlineSQLInjection( Inline Injection )
Two 、 Use time-based delay injection
sqlmap -u "192.168.1.50/06/vul/sqli/sqli_str.php?name=1&submit=1" --dbms mysql -v 3 -D pikachu --technique=T
Support multiple injection detection , The default is all :
sqlmap -u "192.168.1.50/06/vul/sqli/sqli_str.php?name=1&submit=1" --dbms mysql -v 3 -D pikachu --technique=BEUT


3、 ... and 、 Set timeout
--time-out This parameter is to set the timeout Some web pages are slow to respond , You can use this parameter to increase the access timeout time . The default is 30
sqlmap -u "192.168.1.50/06/vul/sqli/sqli_str.php?name=1&submit=1" --dbms mysql -v 3 -D pikachu --timeout=10
Four 、 Read text for SQL Injection detection
sqlmap -r post.txt



5、 ... and 、 Specify parameters to inject
-p Specify the parameters to be tested
sqlmap -u "http://192.168.0.103/06/vul/sqli/sqli_str.php?name=1&submit=1" -p name --dbms mysql -v 1
Use * For injection
If url When it is pseudo static , have access to * No. indicates that this is the place of detection ;
sqlmap -u "http://192.168.0.103/06/vul/sqli/id/1*./html POST Inject sqlmap -u "http://192.168.0.103/06/vul/sqli/sqli_id.php" --data "id=1&submit=1" -p id -v 1
6、 ... and 、 Modify the default maximum thread size
sqlmap/lib/core/settings.py
The default maximum thread is 10 You can set the maximum number of threads to 100
MAX_NUMBER_OF_THREADS = 100

边栏推荐
- continue和break的区别与用法
- Hongliao Technology: how to quickly improve Tiktok store
- 关于 PHP 启动 MongoDb 找不到指定模块问题
- Station B Liu Erden softmx classifier and MNIST implementation -structure 9
- The ECU of 21 Audi q5l 45tfsi brushes is upgraded to master special adjustment, and the horsepower is safely and stably increased to 305 horsepower
- Download, install and use NVM of node, and related use of node and NRM
- B站刘二大人-线性回归及梯度下降
- c语言——冒泡排序
- Web service connector: Servlet
- How Huawei routers configure static routes
猜你喜欢
![[paper reading] nflowjs: synthetic negative data intensive anomaly detection based on robust learning](/img/9c/2753f68ecec3555aaca23800dada1e.png)
[paper reading] nflowjs: synthetic negative data intensive anomaly detection based on robust learning

SQLMAP使用教程(三)实战技巧二

Download, install and use NVM of node, and related use of node and NRM

Cannot build artifact 'test Web: War expanded' because it is included into a circular depend solution

如何在业务代码中使用 ThinkPHP5.1 封装的容器内反射方法
![[Jiudu OJ 08] simple search x](/img/a7/12a00c5d1db2deb064ff5f2e83dc58.jpg)
[Jiudu OJ 08] simple search x

What preparations should be made for website server migration?

Station B, Master Liu Er - dataset and data loading

(column 22) typical column questions of C language: delete the specified letters in the string.

Hongliao Technology: Liu qiangdong's "heavy hand"
随机推荐
Novice entry SCM must understand those things
(column 22) typical column questions of C language: delete the specified letters in the string.
[string] palindrome string of codeup
Mysql database master-slave cluster construction
High quality coding tool clion
养了只小猫咪
Garbage collector with serial, throughput priority and response time priority
Auto. JS learning notes 17: basic listening events and UI simple click event operations
H3C S5820V2_5830V2交换机IRF2堆叠后升级方法
The usage and difference between strlen and sizeof
MIT6.s081-2020 Lab2 System Calls
Report on market depth analysis and future trend prediction of China's arsenic trioxide industry from 2022 to 2028
B站刘二大人-线性回归及梯度下降
[untitled]
B站刘二大人-数据集及数据加载 Lecture 8
ArcGIS application foundation 4 thematic map making
Application Security Series 37: log injection
Winter 2021 pat class B problem solution (C language)
Node 之 nvm 下载、安装、使用,以及node 、nrm 的相关使用
Query the standard text code corresponding to a work center (s) in the production order