mirror of
https://github.com/sqlmapproject/sqlmap.git
synced 2025-04-28 21:03:45 +03:00
Pff.. just layout
This commit is contained in:
parent
9526f0c4c2
commit
3edb30968b
|
@ -18,7 +18,13 @@ url="http://sqlmap.sourceforge.net" name="sqlmap">.
|
||||||
<sect1>What is sqlmap?
|
<sect1>What is sqlmap?
|
||||||
|
|
||||||
<p>
|
<p>
|
||||||
sqlmap is an open source penetration testing tool that automates the process of detecting and exploiting SQL injection flaws and taking over of database servers. It comes with a kick-ass detection engine, many niche features for the ultimate penetration tester and a broad range of switches lasting from database fingerprinting, over data fetching from the database, to accessing the underlying file system and executing commands on the operating system via out-of-band connections.
|
sqlmap is an open source penetration testing tool that automates the
|
||||||
|
process of detecting and exploiting SQL injection flaws and taking over
|
||||||
|
of database servers. It comes with a kick-ass detection engine, many niche
|
||||||
|
features for the ultimate penetration tester and a broad range of switches
|
||||||
|
lasting from database fingerprinting, over data fetching from the
|
||||||
|
database, to accessing the underlying file system and executing commands
|
||||||
|
on the operating system via out-of-band connections.
|
||||||
|
|
||||||
<sect1>How do I execute sqlmap?
|
<sect1>How do I execute sqlmap?
|
||||||
|
|
||||||
|
|
|
@ -824,7 +824,8 @@ Options:
|
||||||
--keep-alive Use persistent HTTP(s) connections
|
--keep-alive Use persistent HTTP(s) connections
|
||||||
--null-connection Retrieve page length without actual HTTP response body
|
--null-connection Retrieve page length without actual HTTP response body
|
||||||
--threads=THREADS Max number of concurrent HTTP(s) requests (default 1)
|
--threads=THREADS Max number of concurrent HTTP(s) requests (default 1)
|
||||||
--group-concat Use GROUP_CONCAT MySQL technique in dumping phase
|
--group-concat Use GROUP_CONCAT (MySQL/error) in dumping phase
|
||||||
|
(experimental)
|
||||||
|
|
||||||
Injection:
|
Injection:
|
||||||
These options can be used to specify which parameters to test for,
|
These options can be used to specify which parameters to test for,
|
||||||
|
@ -845,15 +846,15 @@ Options:
|
||||||
--risk=RISK Risk of tests to perform (0-3, default 1)
|
--risk=RISK Risk of tests to perform (0-3, default 1)
|
||||||
--string=STRING String to match in page when the query is valid
|
--string=STRING String to match in page when the query is valid
|
||||||
--regexp=REGEXP Regexp to match in page when the query is valid
|
--regexp=REGEXP Regexp to match in page when the query is valid
|
||||||
--text-only Compare pages based only on their textual content
|
--text-only Compare pages based only on the textual content
|
||||||
|
|
||||||
Techniques:
|
Techniques:
|
||||||
These options can be used to tweak how specific SQL injection
|
These options can be usedto tweak testing of specific SQL injection
|
||||||
techniques are tested.
|
techniques.
|
||||||
|
|
||||||
--time-sec=TIMESEC Seconds to delay the DBMS response (default 5)
|
--time-sec=TIMESEC Seconds to delay the DBMS response (default 5)
|
||||||
--union-cols=UCOLS Range of columns to test for UNION query SQL injection
|
--union-cols=UCOLS Range of columns to test for UNION query SQL injection
|
||||||
--union-char=UCHAR Character to use to bruteforce number of columns
|
--union-char=UCHAR Character to use for bruteforcing number of columns
|
||||||
|
|
||||||
Fingerprint:
|
Fingerprint:
|
||||||
-f, --fingerprint Perform an extensive DBMS version fingerprint
|
-f, --fingerprint Perform an extensive DBMS version fingerprint
|
||||||
|
@ -937,9 +938,8 @@ Options:
|
||||||
General:
|
General:
|
||||||
These options can be used to set some general working parameters.
|
These options can be used to set some general working parameters.
|
||||||
|
|
||||||
-x XMLFILE Dump the data into an XML file
|
|
||||||
-s SESSIONFILE Save and resume all data retrieved on a session file
|
|
||||||
-t TRAFFICFILE Log all HTTP traffic into a textual file
|
-t TRAFFICFILE Log all HTTP traffic into a textual file
|
||||||
|
-s SESSIONFILE Save and resume all data retrieved on a session file
|
||||||
--flush-session Flush session file for current target
|
--flush-session Flush session file for current target
|
||||||
--eta Display for each output the estimated time of arrival
|
--eta Display for each output the estimated time of arrival
|
||||||
--update Update sqlmap
|
--update Update sqlmap
|
||||||
|
@ -948,7 +948,7 @@ Options:
|
||||||
|
|
||||||
Miscellaneous:
|
Miscellaneous:
|
||||||
--beep Alert when sql injection found
|
--beep Alert when sql injection found
|
||||||
--check-payload IDS detection testing of injection payload
|
--check-payload IDS detection testing of injection payloads
|
||||||
--cleanup Clean up the DBMS by sqlmap specific UDF and tables
|
--cleanup Clean up the DBMS by sqlmap specific UDF and tables
|
||||||
--forms Parse and test forms on target url
|
--forms Parse and test forms on target url
|
||||||
--gpage=GOOGLEPAGE Use google dork results from specified page number
|
--gpage=GOOGLEPAGE Use google dork results from specified page number
|
||||||
|
|
Loading…
Reference in New Issue
Block a user