Get the App
SLTechnology News&Howtos  ›  Network Security  › 

4 of DVWA series uses SQLMap for medium level injection

Shulou Source: shulou.com Published: 2022-06-01 03:26:38 10月02日 Update

Let's try to use SQLMap for injection at the medium level.

First detect the existence of the injection point and execute the following command:

Sqlmap.py-u http://192.168.80.1/dvwa/vulnerabilities/sqli/?id=1&Submit=Submit

No injection point was found in the test result, because DVWA needs to be logged in before it can be used, so you need to get the cookie of the current session to maintain the connection state during the * process. Use Burpsuite to intercept data packets and obtain cookie.

Add the-- cookie parameter to the SQLMap to continue with the injection.

Sqlmap.py-u "http://192.168.80.1/dvwa/vulnerabilities/sqli/?id=1&Submit=Submit"-- cookie=" security=medium; PHPSESSID=2f120ee00f32798d11de936832312549 "

Now the injection point has been successfully detected.

There will be another series of blog posts about sqlmap and Burpsuite in the future.

Tags: Probe level success parameters commands data status results process this is face China plus try detect log in Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Shulou Technology Microsoft vpn MySQL Huawei