DWVA Tutorial (ii)--SQL injection

Source: Internet
Author: User
Tags sql injection

Welcome to the SQL injection section, this time we are using the Sqlmap tool.

We have detected the existence of the classic parameter ID, with a cheeky statement: SQL injection vulnerabilities exist.

So how do we prove it?

Good habits, first grab the bag, get the method submitted, pulled out the almighty sqlmap.

Focus, knock on the blackboard, crazy time: 302?

Here we ignore it (it is not not understood to say) direct carriage to see what will happen.

"Fake It!!" My sqlmap has never been a reliable!! "Cough, this sentence I have been shouting for two months."

The reason is very simple, sqlmap access to the page was reset to the login interface.

So here we have to give it a cookie: Of course, the cookie was captured when it was caught in front of the packet.

Perfect Infusion ~

At the end of the time, sprinkle the flowers, without breaking the saying ~

What the? No post injection method?

Dwvasql injection By default, there is no post injection method, of course, by modifying the source code to implement post submission,

Here we are not to discuss, the usual, work contact with real cases to publish the tutorial.

So, here it is.

I can lose a personal public number weak, fan too little has been no passion for writing,

If you like technology, like Parrotsec, like two times, look forward to meet you.

It's not what Lori controls, just like the girl paper happened to be Lori, hum ~

DWVA Tutorial (ii)--SQL injection

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.