mirror of
https://github.com/ivuorinen/cheatsheet-tldr.git
synced 2026-02-06 02:44:36 +00:00
Update cheatsheets
This commit is contained in:
10
tldr/sqlmap
10
tldr/sqlmap
@@ -10,20 +10,20 @@ source: https://github.com/tldr-pages/tldr.git
|
||||
|
||||
- Run sqlmap against a single target URL:
|
||||
|
||||
`python sqlmap.py {{[-u|--url]}} "{{http://www.target.com/vuln.php?id=1}}"`
|
||||
`python sqlmap.py {{[-u|--url]}} "{{http://www.example.com/vuln.php?id=1}}"`
|
||||
|
||||
- Send data in a POST request (`--data` implies POST request):
|
||||
|
||||
`python sqlmap.py {{[-u|--url]}} "{{http://www.target.com/vuln.php}}" --data="{{id=1}}"`
|
||||
`python sqlmap.py {{[-u|--url]}} "{{http://www.example.com/vuln.php}}" --data="{{id=1}}"`
|
||||
|
||||
- Change the parameter delimiter (& is the default):
|
||||
|
||||
`python sqlmap.py {{[-u|--url]}} "{{http://www.target.com/vuln.php}}" --data="{{query=foobar;id=1}}" --param-del="{{;}}"`
|
||||
`python sqlmap.py {{[-u|--url]}} "{{http://www.example.com/vuln.php}}" --data="{{query=foobar;id=1}}" --param-del="{{;}}"`
|
||||
|
||||
- Select a random `User-Agent` from `./txt/user-agents.txt` and use it:
|
||||
|
||||
`python sqlmap.py {{[-u|--url]}} "{{http://www.target.com/vuln.php}}" --random-agent`
|
||||
`python sqlmap.py {{[-u|--url]}} "{{http://www.example.com/vuln.php}}" --random-agent`
|
||||
|
||||
- Provide user credentials for HTTP protocol authentication:
|
||||
|
||||
`python sqlmap.py {{[-u|--url]}} "{{http://www.target.com/vuln.php}}" --auth-type {{Basic}} --auth-cred "{{testuser:testpass}}"`
|
||||
`python sqlmap.py {{[-u|--url]}} "{{http://www.example.com/vuln.php}}" --auth-type {{Basic}} --auth-cred "{{testuser:testpass}}"`
|
||||
|
||||
Reference in New Issue
Block a user