From b12d9552747c1ca1ec9c81055e224c8fb9efdfaf Mon Sep 17 00:00:00 2001
From: Bernardo Damele sqlmap user's manual
by
-Bernardo Damele A. G.
version 0.6.4, DDth of MMM 2009
+Bernardo Damele A. G.version 0.6.4, 3rd of February 2009
This document is the user's manual to use
sqlmap.
@@ -407,7 +407,7 @@ $ python sqlmap.py -h
sqlmap/0.6.4 coded by Bernardo Damele A. G. <bernardo.damele@gmail.com>
and Daniele Bellucci <daniele.bellucci@gmail.com>
-
+
Usage: sqlmap.py [options]
Options:
@@ -3801,7 +3801,8 @@ back-end DBMS: PostgreSQL
sql> SELECT COUNT(name) FROM users
[10:11:57] [INFO] fetching SQL SELECT statement query output: 'SELECT COUNT(name) FROM users'
[10:11:57] [INPUT] can the SQL query provided return multiple entries? [Y/n] n
-[10:11:59] [INFO] query: SELECT COALESCE(CAST(COUNT(name) AS CHARACTER(10000)), CHR(32)) FROM users
+[10:11:59] [INFO] query: SELECT COALESCE(CAST(COUNT(name) AS CHARACTER(10000)), CHR(32))
+FROM users
[10:11:59] [INFO] retrieved: 4
[10:11:59] [INFO] performed 13 queries in 0 seconds
SELECT COUNT(name) FROM users: '4'
@@ -3809,12 +3810,14 @@ SELECT COUNT(name) FROM users: '4'
sql> INSERT INTO users (id, name, surname) VALUES (5, 'from', 'sql shell');
[10:12:35] [INFO] testing stacked queries support on parameter 'id'
[10:12:40] [INFO] the web application supports stacked queries on parameter 'id'
-[10:12:40] [INFO] executing SQL data manipulation query: 'INSERT INTO users (id, name, surname) VALUES (5, 'from', 'sql shell');'
+[10:12:40] [INFO] executing SQL data manipulation query: 'INSERT INTO users (id, name, surname)
+VALUES (5, 'from', 'sql shell');'
[10:12:40] [INFO] done
sql> SELECT COUNT(name) FROM users
[10:12:51] [INFO] fetching SQL SELECT statement query output: 'SELECT COUNT(name) FROM users'
[10:12:51] [INPUT] can the SQL query provided return multiple entries? [Y/n] n
-[10:12:53] [INFO] query: SELECT COALESCE(CAST(COUNT(name) AS CHARACTER(10000)), CHR(32)) FROM users
+[10:12:53] [INFO] query: SELECT COALESCE(CAST(COUNT(name) AS CHARACTER(10000)), CHR(32))
+FROM users
[10:12:53] [INFO] retrieved: 5
[10:12:54] [INFO] performed 20 queries in 0 seconds
SELECT COUNT(name) FROM users: '5'
@@ -3822,7 +3825,15 @@ SELECT COUNT(name) FROM users: '5'
TODO
+As you can see from this last example, when the user provides a SQL
+statement other than SELECT
, sqlmap recognizes it, tests if the
+web application supports stacked queries and in case it does, it executes
+the provided SQL statement in a multiple statement.
Beware that some web application technologies do not support stacked +queries on specific database management systems. For instance, PHP does not +support stacked queries when the back-end DBMS is MySQL, but it does +support when the back-end DBMS is PostgreSQL.
h+05yH$@
zMlmB4e#)D@@0dDsulM2KQczM#%lhnUKJIOH&@jp=PUVG^FJd?0_+Mwqe0_)|G^Swh
zfsA?aiJ*U4%<7LJ>zQEU#f;=X)El)ihCe*TOl>kWSduLnad?DlFXrC=e9)G5gKSR<
zmcair!dC#5-&&8EIFH!xZUTu+H3m$8xehJ*?rZm3x+o58CtLKzZAeJvtTNHQWt4y5
z;i$K5#&%rB4bz|bJX|eunLQ4uwQ$6j7QnU|Q!C8&&1KFoF?fB9+wL7vwJvp{R4PEDg_yP9Ndm9TULZCFKZgC88X@c1-Ar)8o
zCq3q%oYn>^K6Q#P?NX1tE4yzB$IIn$AGC2sj8sDIIK*{q4l}pdv)m{dF_2}S_@XId
zq`ud}lVOK=xRne-*t+u61|8Q6z?@QFtBMzzEZJSL-SwQc@+|3WoHV1|9&TqyfSVNX
z2A%FuB;+J{32%#!XH*M>2`$={(pr#`H-SHdFMC3|tQ{5)yI@?kC!ClL`)n7MAId$x
z^ujV%$1D29D=MRhO=Gu4j}GWdaw7OzOUyMhwe>|p_2xL(^5mQhhb^2rP!9Cuf{?0<
zm6oL}hs{yWY+YfOGHWcupRU}~`+dGD8n@d*X92k?OyXaKh&n7im)97i-y-zR<952l
znW+>H9zY11h!q%a`VPiidnMuloy0gY8s`OacjX_
-TODO
+As you can see from this last example, when the user provides a SQL
+statement other than SELECT, sqlmap recognizes it, tests if the
+web application supports stacked queries and in case it does, it executes
+the provided SQL statement in a multiple statement.
+
+
+Beware that some web application technologies do not support stacked
+queries on specific database management systems. For instance, PHP does not
+support stacked queries when the back-end DBMS is MySQL, but it does
+support when the back-end DBMS is PostgreSQL.
8&*AtNc=xv8pj3^Y2b+
kO^jAWeZvV*v;+1XjnLKI1S6lY=9J5(<+7OCU`?#
zgT1WR&iOa>^C0j*AI#Q!U|hr|T#?zh8ZvAC)1