ALERT!
Click here to register with a few steps and explore all our cool stuff we have to offer!

Jump to content



Photo

Taking an injectable URL and putting it into SQL map?


  • Please log in to reply
Taking an injectable URL and putting it into SQL map?

#1

ThePaidAssassin
ThePaidAssassin
    Offline
    0
    Rep
    1
    Likes

    Member

  • PipPipPip
Posts: 71
Threads: 4
Joined: Feb 21, 2018
Credits: 0
Six years registered
#1

So I have an injectable URL however I cannot get SQLmap to inject it and extract the database. I've tried a bunch of things but can't get my head around it

 

URL: (It wouldn't let me post the sql url)

 

https://gyazo.com/fe...be5c44afb38e46b

 
how do I convert this? and what is the secret to doing for all future reference. Technically speaking I could just dump it using SQLI Dumper but I dont really want to dump a 200k database.


Any help is appreciated. Thanks.

  • 0

#2

AlfredJr
AlfredJr
    Offline
    0
    Rep
    0
    Likes

    Member

  • PipPipPip
Posts: 27
Threads: 2
Joined: Feb 28, 2018
Credits: 0
Six years registered
#2

Yea i too had the same question. Bump


  • 0

#3

benno12371
benno12371
    Offline
    0
    Rep
    1
    Likes

    New Member

  • PipPip
Posts: 23
Threads: 0
Joined: Feb 07, 2018
Credits: 0
Six years registered
#3
Dont know why but SQLmap doesnt likes this kind of urls with the SQLi Dumper Parameter on the end

  • 0

#4

ThePaidAssassin
ThePaidAssassin
    Offline
    0
    Rep
    1
    Likes

    Member

  • PipPipPip
Posts: 71
Threads: 4
Joined: Feb 21, 2018
Credits: 0
Six years registered
#4

Bump. Still lost. Willing to offer some sort of money as a reward.


  • 0

#5

LGgamemoy4
LGgamemoy4
    Offline
    0
    Rep
    1
    Likes

    Addicted

  • PipPipPipPipPip
Posts: 164
Threads: 5
Joined: Aug 01, 2017
Credits: 0
Six years registered
#5

https://gyazo.com/9e...0cb0d324cf12d1d The file doesn't exists.


  • 0

#6

ThePaidAssassin
ThePaidAssassin
    Offline
    0
    Rep
    1
    Likes

    Member

  • PipPipPip
Posts: 71
Threads: 4
Joined: Feb 21, 2018
Credits: 0
Six years registered
#6

https://gyazo.com/9e...0cb0d324cf12d1d The file doesn't exists.

Its a fake website so I dont have to give out the information...


  • 0

#7

Yukana
Yukana
    Offline
    63
    Rep
    456
    Likes

    🦅

Posts: 795
Threads: 224
Joined: May 22, 2015
Credits: 0

Eight years registered
#7

 

So I have an injectable URL however I cannot get SQLmap to inject it and extract the database. I've tried a bunch of things but can't get my head around it

 

URL: (It wouldn't let me post the sql url)

 

https://gyazo.com/fe...be5c44afb38e46b

 
how do I convert this? and what is the secret to doing for all future reference. Technically speaking I could just dump it using SQLI Dumper but I dont really want to dump a 200k database.


Any help is appreciated. Thanks.

 

 

Remove the extras upntil 999'

Then do the normal sqlmap.py -d url etc

how far have u gotten?


  • 0

#8

ThePaidAssassin
ThePaidAssassin
    Offline
    0
    Rep
    1
    Likes

    Member

  • PipPipPip
Posts: 71
Threads: 4
Joined: Feb 21, 2018
Credits: 0
Six years registered
#8

Remove the extras upntil 999'

Then do the normal sqlmap.py -d url etc

how far have u gotten?

Tried that, im doing level=5 risk=3 still getting no vulnerable. Tried using random agent for the time outs and a custom inject before the "  '  ". I've tried specifically targetting the injection type to cut the useless test on the other methods. Now I'm seriously struggling :D Any help? I added you on discord. I have a couple of questions for you. Will pay for your time.


  • 0

#9

CosmicOrc
CosmicOrc
    Offline
    0
    Rep
    3
    Likes

    Member

  • PipPipPip
Posts: 41
Threads: 0
Joined: Mar 06, 2018
Credits: 0
Six years registered
#9

Tried that, im doing level=5 risk=3 still getting no vulnerable. Tried using random agent for the time outs and a custom inject before the "  '  ". I've tried specifically targetting the injection type to cut the useless test on the other methods. Now I'm seriously struggling :D Any help? I added you on discord. I have a couple of questions for you. Will pay for your time.


If u willing to pay so i can help you

  • 0


 Users browsing this thread: and 1 guests