From d305183447e44a478bfe769248313764fced61ee Mon Sep 17 00:00:00 2001
From: Bernardo Damele
Switch: -
-union-cols
TODO
+By default sqlmap tests for UNION query SQL injection technique using 1 to
+10 columns. However, this range can be increased up to 50 columns by
+providing an higher -
-level
value. See the relevant
+paragraph for details.
You can manually tell sqlmap to test for this type of SQL injection with a
+specific range of columns by providing the tool with the
+-
-union-cols
switch followed by a range of integers. For
+instance, 12-16
means tests for UNION query SQL injection by
+using 12 up to 16 columns.
Switch: -
-union-char
TODO
+By default sqlmap tests for UNION query SQL injection technique using
+NULL
character. However, by providing an higher
+-
-level
value sqlmap will performs tests also with a
+random number because there are some corner cases where UNION query tests
+with NULL
fail whereas with a random integer they succeed.
You can manually tell sqlmap to test for this type of SQL injection with a
+specific character by providing the tool with the
+-
-union-char
switch followed by a string.
Switches: -
-common-tables
TODO
+There are cases where -
-tables
switch can not be used to
+retrieve the databases' table names. These cases usually fit into one
+of the following categories:
+
information_schema
is not available.If any of the first two cases apply and you provided the
+-
-tables
switch, sqlmap will prompt you with a question
+to fall back to this technique.
+Either of these cases apply to your situation, sqlmap can possibly still
+identify some existing tables if you provide it with the
+-
-common-tables
switch. sqlmap will perform a
+brute-force attack in order to detect the existence of common tables
+across the DBMS.
The list of common table names is txt/common-tables.txt
and you
+can edit it as you wish.
Switches: -
-common-columns
TODO
+As per tables, there are cases where -
-columns
switch
+can not be used to retrieve the databases' tables' column names. These
+cases usually fit into one of the following categories:
+
information_schema
is not available.If any of the first two cases apply and you provided the
+-
-columns
switch, sqlmap will prompt you with a question
+to fall back to this technique.
+Either of these cases apply to your situation, sqlmap can possibly still
+identify some existing tables if you provide it with the
+-
-common-columns
switch. sqlmap will perform a
+brute-force attack in order to detect the existence of common columns
+across the DBMS.
The list of common table names is txt/common-columns.txt
and you
+can edit it as you wish.
UrJx2cWIwL0 3^gc#-4Qk&w}vf|U7`cqSZ>h|*d4_t02%
zy5mvvFgPr^$13dn$Q1ckb%pI^;7={u$*sG-5wVpw96zxac1p_;ztHWlS74Ao*3Xdl
zen>nt!>CRfO@G|(KW(XL)i^f|-7B87gr?_(pP4?5n4!-N2h;0On3XIS1aZ>5kF0q}
z#mdNAmbH!~_k40Ss`U324B7ZQ;Bbk=rCLV(zcJN+3qXLJkZEiH6+Vy)S_q=?jzh!R
z)79I<(%O@fpGP2t%Z(LsCJaD^h%y3Dae>^>YoK>g3JbsEkft=`hu$pV1fYX3@Bpv@
z&=X2iSUQL)4*&-b$oWrqlpK2c29zLfN)V?2I}q|I6k1NACI-O8``@iVXgvuRC*;x#
zYC%Mc0dR=_cQY41Cp$kEkkZB5$q9lb0w9L0-$2Ky9fD%D)8AmxAV}E&F37Sx^xwL3
z9DoeR4ebkx%|bbyW7oA|?62_4hHLV2a>2a*(
|zfcSM&8a^E1cXxA|yMuZpj|i0_;_&l_7hbl<-9zQz8W;eC06
z%EXcBv`>@1Bp;Xh@q69`yD;4?dL>x_8RyONg{FKsr4$(1IACd#_p~Y9<8t=;2Mf;Z
zkh}GFATj^WZ|fM#SsAxJa#wjB-RN}Q#6^vxnqI@rKJ&ZcoZ))|#SD8Bug+a}r_I@+
zo+okQ_dKT~Gb~G&wpdKrvoT}v)JIRR1!9*>%VJWm?VEk%@v#p%x3bl47B!vTs+bd&
z7gM<|dZABS+;=%&KP!vX4-QRm?={kQ+Wycr^qIY6c}3m>^Vcah;`3wDjYGJ$%gPVQ
zKU#8*DXF>s&HdonTy@Xk*st{&9fLwYmt9n{np6>~XrAg^!&o!zx}Hywgir0Dgml2t
z8F3%pE2y{m&TV^NrF8JAPt%)cH;0Rzrx;9s?w8@zw6gTv{K6C&rpk^kgRi|cntSXU
z#~qR9?B2Gra%7HVr=VO+XEFRv&)ZF0$-&f=+Xfe|eoG5a`f~M=o3Rm1Pfz9dQ@@}4
zrt}Zq^$ko`S?&Gs=L49w`&jX~?}eJ%wu~==<