Login Register




The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


How many people use SQLMap? filter_list
Author
Message
How many people use SQLMap? #1
How many people use SQLMap?
My IT skills that I know perfect is SQL, HTML ,css ,wordpress, PHP.
coding skills that I know is Java, JavaScript and C#

Reply

RE: How many people use SQLMap? #2
It's a standard in penetration testing. It's basically a fuzzer that can confirm that what you found is or isn't an SQL injection vulnerability (as opposed to things like broken parsing). It can identify different types of backends that might be annoying having to manually poke and try each and every possibility/combination. It can even escalate to gain further access besides the typical data querying such as getting shells(?) to see how poorly configured the database is. Use it if you're whitelisted and given permission, otherwise I wouldn't recommend using it.

Reply

RE: How many people use SQLMap? #3
(03-24-2019, 07:39 PM)reGEN Wrote: It's a standard in penetration testing. It's basically a fuzzer that can confirm that what you found is or isn't an SQL injection vulnerability (as opposed to things like broken parsing). It can identify different types of backends that might be annoying having to manually poke and try each and every possibility/combination. It can even escalate to gain further access besides the typical data querying such as getting shells(?) to see how poorly configured the database is. Use it if you're whitelisted and given permission, otherwise I wouldn't recommend using it.

good valid point. Now, what tools would you do in carrying out a database hack?
My IT skills that I know perfect is SQL, HTML ,css ,wordpress, PHP.
coding skills that I know is Java, JavaScript and C#

Reply

RE: How many people use SQLMap? #4
(03-25-2019, 12:41 AM)darkninja1980 Wrote:
(03-24-2019, 07:39 PM)reGEN Wrote: It's a standard in penetration testing. It's basically a fuzzer that can confirm that what you found is or isn't an SQL injection vulnerability (as opposed to things like broken parsing). It can identify different types of backends that might be annoying having to manually poke and try each and every possibility/combination. It can even escalate to gain further access besides the typical data querying such as getting shells(?) to see how poorly configured the database is. Use it if you're whitelisted and given permission, otherwise I wouldn't recommend using it.

good valid point. Now, what tools would you do in carrying out a database hack?

Dunno, I'm still new to web h4x Biggrin

Reply

RE: How many people use SQLMap? #5
(03-27-2019, 01:57 AM)reGEN Wrote:
(03-25-2019, 12:41 AM)darkninja1980 Wrote:
(03-24-2019, 07:39 PM)reGEN Wrote: It's a standard in penetration testing. It's basically a fuzzer that can confirm that what you found is or isn't an SQL injection vulnerability (as opposed to things like broken parsing). It can identify different types of backends that might be annoying having to manually poke and try each and every possibility/combination. It can even escalate to gain further access besides the typical data querying such as getting shells(?) to see how poorly configured the database is. Use it if you're whitelisted and given permission, otherwise I wouldn't recommend using it.

good valid point. Now, what tools would you do in carrying out a database hack?

Dunno, I'm still new to web h4x  Biggrin

no problems Smile Wink
My IT skills that I know perfect is SQL, HTML ,css ,wordpress, PHP.
coding skills that I know is Java, JavaScript and C#

Reply