10-14-2024, 06:05 PM
Ban reason: Multi-Accounting @LEON477 | https://breachforums.sb/Forum-Ban-Appeals if you feel this is incorrect. (Permanent)
|
SQLmap
by stride2168 - Monday October 14, 2024 at 06:05 PM
|
|
10-14-2024, 06:05 PM
Ban reason: Multi-Accounting @LEON477 | https://breachforums.sb/Forum-Ban-Appeals if you feel this is incorrect. (Permanent)
10-14-2024, 06:06 PM
It not just manual from sqlmap -hh ?
10-14-2024, 06:20 PM
(10-14-2024, 06:06 PM)alkoholic Wrote: It not just manual from sqlmap -hh ? Yep, sqlmap -hh is a great help just by looking at options! Though that is beyond the horizon, understanding how to apply those options to the right situation, for instance in bypassing WAF or using particular tamper scripts- that really brings the difference. However, along with that depth into strategies and pitfalls makes it much easier to handle unexpected situations when you're actually out testing.
Ban reason: Multi-Accounting @LEON477 | https://breachforums.sb/Forum-Ban-Appeals if you feel this is incorrect. (Permanent)
10-14-2024, 06:28 PM
(10-14-2024, 06:20 PM)stride2168 Wrote:(10-14-2024, 06:06 PM)alkoholic Wrote: It not just manual from sqlmap -hh ? Yeah , bypass WAF , --random-agent , on another times you need find manual SQL injection, so you can write tamper script. Another options its just easy setup for simple injections. TUT is good then you write some additional information, like firebird database can be dumbed only using --current-db , because -D will not work
10-14-2024, 06:38 PM
(10-14-2024, 06:28 PM)alkoholic Wrote:(10-14-2024, 06:20 PM)stride2168 Wrote:(10-14-2024, 06:06 PM)alkoholic Wrote: It not just manual from sqlmap -hh ? Absolutely, hitting sqlmap -hh is a great first step to get in to see the basics, but when you are dealing with real scenarios, there is much, much more. Knowing when and how to use those options makes all the difference. For example, you may require the native custom tamper scripts particularly if you have more sensitive WAFs that will detect common payloads. But apart from this, at times, to evade some of the databases like Firebird, you'll require certain customizations such as- you noted the --current-db option for dumping on Firebird because just -D is not enough. All these are what lead you to levels of getting past simple injections and make your testing much more effective. It's also worth noting that while --random-agent is fine for simple evasions, chaining it with --delay and a particular tamper gets things even less detectable. Tutorials can definitely be your foundation, but layering in your own techniques atop that builds far more resilient strategies for real application.
Ban reason: Multi-Accounting @LEON477 | https://breachforums.sb/Forum-Ban-Appeals if you feel this is incorrect. (Permanent)
10-15-2024, 01:31 AM
Sqlmap is interesting
10-15-2024, 01:51 AM
this better not be sqlmap -hh lol
Ban reason: Leeching | http://breachddyfwvcp4kzccos5oxtdbssmfbp...an-Appeals if you feel this is incorrect. (Permanent)
10-15-2024, 02:35 PM
(10-14-2024, 06:38 PM)stride2168 Wrote:(10-14-2024, 06:28 PM)alkoholic Wrote:(10-14-2024, 06:20 PM)stride2168 Wrote:(10-14-2024, 06:06 PM)alkoholic Wrote: It not just manual from sqlmap -hh ? Every tut is not worth time until you not learn how to do manually sql injection. You can't select right tampers until your injection not working. But most of times on MySQL you can just use --tamper between,space2comment
11-27-2024, 06:46 PM
I want to learn SQLmap.
Ban reason: Leeching | http://breachddyfwvcp4kzccos5oxtdbssmfbp...an-Appeals if you feel this is incorrect. (Permanent)
12-04-2024, 03:49 PM
very good! very useful!!!!
|
|
« Next Oldest | Next Newest »
|
| Possibly Related Threads… | |||||
| Thread | Author | Replies | Views | Last Post | |
| AdvanceAI-SQLMap | 36 | 2,146 |
01-23-2026, 07:16 PM Last Post: |
||