![]() |
|
How many people use SQLMap? - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: Hacking (https://sinister.li/Forum-Hacking) +--- Forum: Hacking Tools (https://sinister.li/Forum-Hacking-Tools) +--- Thread: How many people use SQLMap? (/Thread-How-many-people-use-SQLMap) |
How many people use SQLMap? - darkninja1980 - 03-24-2019 How many people use SQLMap? RE: How many people use SQLMap? - reGEN - 03-24-2019 It's a standard in penetration testing. It's basically a fuzzer that can confirm that what you found is or isn't an SQL injection vulnerability (as opposed to things like broken parsing). It can identify different types of backends that might be annoying having to manually poke and try each and every possibility/combination. It can even escalate to gain further access besides the typical data querying such as getting shells(?) to see how poorly configured the database is. Use it if you're whitelisted and given permission, otherwise I wouldn't recommend using it. RE: How many people use SQLMap? - darkninja1980 - 03-25-2019 (03-24-2019, 07:39 PM)reGEN Wrote: It's a standard in penetration testing. It's basically a fuzzer that can confirm that what you found is or isn't an SQL injection vulnerability (as opposed to things like broken parsing). It can identify different types of backends that might be annoying having to manually poke and try each and every possibility/combination. It can even escalate to gain further access besides the typical data querying such as getting shells(?) to see how poorly configured the database is. Use it if you're whitelisted and given permission, otherwise I wouldn't recommend using it. good valid point. Now, what tools would you do in carrying out a database hack? RE: How many people use SQLMap? - reGEN - 03-27-2019 (03-25-2019, 12:41 AM)darkninja1980 Wrote:(03-24-2019, 07:39 PM)reGEN Wrote: It's a standard in penetration testing. It's basically a fuzzer that can confirm that what you found is or isn't an SQL injection vulnerability (as opposed to things like broken parsing). It can identify different types of backends that might be annoying having to manually poke and try each and every possibility/combination. It can even escalate to gain further access besides the typical data querying such as getting shells(?) to see how poorly configured the database is. Use it if you're whitelisted and given permission, otherwise I wouldn't recommend using it. Dunno, I'm still new to web h4x
RE: How many people use SQLMap? - darkninja1980 - 03-27-2019 (03-27-2019, 01:57 AM)reGEN Wrote:(03-25-2019, 12:41 AM)darkninja1980 Wrote:(03-24-2019, 07:39 PM)reGEN Wrote: It's a standard in penetration testing. It's basically a fuzzer that can confirm that what you found is or isn't an SQL injection vulnerability (as opposed to things like broken parsing). It can identify different types of backends that might be annoying having to manually poke and try each and every possibility/combination. It can even escalate to gain further access besides the typical data querying such as getting shells(?) to see how poorly configured the database is. Use it if you're whitelisted and given permission, otherwise I wouldn't recommend using it. no problems
|