SQL

SQLmap

(capture burp request on search function)

Sqlmap -r request.txt –dbms=mysql –dump
  • -r uses request file

  • –dbms specify what type of database

  • –dump outputs entire database

SQLmap cookies

  • -cookie editor can be used to get the cooking for sqlmap

  • sqlmap -u 'url-to-search-query' --cookie="PHPSESSID=cookie"

Last updated