Minor layout adjustments in the user's manual

This commit is contained in:
Bernardo Damele 2009-01-13 23:16:34 +00:00
parent fd7cb9101c
commit bc3b4c6936
3 changed files with 30 additions and 28 deletions

View File

@ -58,15 +58,16 @@ for the latest version.</EM>
<HR> <HR>
<H2><A NAME="s1">1.</A> <A HREF="#toc1">Introduction</A></H2> <H2><A NAME="s1">1.</A> <A HREF="#toc1">Introduction</A></H2>
<P>sqlmap is an automatic <P>sqlmap is an open source command-line automatic
<A HREF="http://www.google.com/search?q=SQL+injection">SQL injection</A> tool. Its goal is to detect and take advantage of <A HREF="http://www.google.com/search?q=SQL+injection">SQL injection</A>
SQL injection vulnerabilities on web applications. Once it detects one or tool.
more SQL injections on the target host, the user can choose among a Its goal is to detect and take advantage of SQL injection vulnerabilities
variety of options to perform an extensive back-end database management in web applications. Once it detects one or more SQL injections on the
system fingerprint, retrieve DBMS session user and database, enumerate target host, the user can choose among a variety of options to perform an
users, password hashes, privileges, databases, dump entire or user's extensive back-end database management system fingerprint, retrieve DBMS
specific DBMS tables/columns, run his own SQL <CODE>SELECT</CODE> statement, session user and database, enumerate users, password hashes, privileges,
read specific files on the file system and much more.</P> databases, dump entire or user's specific DBMS tables/columns, run his own
SQL statement, read specific files on the file system and more.</P>
<H2><A NAME="ss1.1">1.1</A> <A HREF="#toc1.1">Requirements</A> <H2><A NAME="ss1.1">1.1</A> <A HREF="#toc1.1">Requirements</A>
@ -232,8 +233,8 @@ and the session user privileges.</LI>
<UL> <UL>
<LI>Full support for <B>MySQL</B>, <B>Oracle</B>, <B>PostgreSQL</B> <LI>Full support for <B>MySQL</B>, <B>Oracle</B>, <B>PostgreSQL</B>
and <B>Microsoft SQL Server</B> back-end database management systems. and <B>Microsoft SQL Server</B> back-end database management systems.
Besides these four database management systems, sqlmap can also identify Besides these four database management systems software. sqlmap can also
Microsoft Access, DB2, Informix, Sybase and Interbase. identify Microsoft Access, DB2, Informix, Sybase and Interbase.
</LI> </LI>
<LI><B>Extensive back-end database management system fingerprint</B> <LI><B>Extensive back-end database management system fingerprint</B>
based upon based upon
@ -3596,9 +3597,9 @@ SELECT user, host, password FROM mysql.user LIMIT 1, 3 [3]:
</CODE></BLOCKQUOTE> </CODE></BLOCKQUOTE>
</P> </P>
<P>The SQL shell option gives you access to run your own SQL <CODE>SELECT</CODE> <P>The SQL shell option gives you access to run your own SQL statement
statement interactively, like a SQL console logged into the back-end interactively, like a SQL console logged into the back-end database
database management system. management system.
This feature has TAB completion and history support.</P> This feature has TAB completion and history support.</P>
<P>Example of history support on a <B>PostgreSQL 8.3.5</B> target:</P> <P>Example of history support on a <B>PostgreSQL 8.3.5</B> target:</P>

Binary file not shown.

View File

@ -16,15 +16,16 @@ for the latest version.
<sect>Introduction <sect>Introduction
<p> <p>
sqlmap is an automatic <htmlurl url="http://www.google.com/search?q=SQL+injection" sqlmap is an open source command-line automatic
name="SQL injection"> tool. Its goal is to detect and take advantage of <htmlurl url="http://www.google.com/search?q=SQL+injection" name="SQL injection">
SQL injection vulnerabilities on web applications. Once it detects one or tool.
more SQL injections on the target host, the user can choose among a Its goal is to detect and take advantage of SQL injection vulnerabilities
variety of options to perform an extensive back-end database management in web applications. Once it detects one or more SQL injections on the
system fingerprint, retrieve DBMS session user and database, enumerate target host, the user can choose among a variety of options to perform an
users, password hashes, privileges, databases, dump entire or user's extensive back-end database management system fingerprint, retrieve DBMS
specific DBMS tables/columns, run his own SQL <tt>SELECT</tt> statement, session user and database, enumerate users, password hashes, privileges,
read specific files on the file system and much more. databases, dump entire or user's specific DBMS tables/columns, run his own
SQL statement, read specific files on the file system and more.
<sect1>Requirements <sect1>Requirements
@ -189,8 +190,8 @@ Major features implemented in sqlmap include:
<itemize> <itemize>
<item>Full support for <bf>MySQL</bf>, <bf>Oracle</bf>, <bf>PostgreSQL</bf> <item>Full support for <bf>MySQL</bf>, <bf>Oracle</bf>, <bf>PostgreSQL</bf>
and <bf>Microsoft SQL Server</bf> back-end database management systems. and <bf>Microsoft SQL Server</bf> back-end database management systems.
Besides these four database management systems, sqlmap can also identify Besides these four database management systems software. sqlmap can also
Microsoft Access, DB2, Informix, Sybase and Interbase. identify Microsoft Access, DB2, Informix, Sybase and Interbase.
<item><bf>Extensive back-end database management system fingerprint</bf> <item><bf>Extensive back-end database management system fingerprint</bf>
based upon based upon
@ -3497,9 +3498,9 @@ SELECT user, host, password FROM mysql.user LIMIT 1, 3 [3]:
</verb></tscreen> </verb></tscreen>
<p> <p>
The SQL shell option gives you access to run your own SQL <tt>SELECT</tt> The SQL shell option gives you access to run your own SQL statement
statement interactively, like a SQL console logged into the back-end interactively, like a SQL console logged into the back-end database
database management system. management system.
This feature has TAB completion and history support. This feature has TAB completion and history support.
<p> <p>