From 0c5d3df54635d9115cc6ed21639d368be115b645 Mon Sep 17 00:00:00 2001
From: Bernardo Damele sqlmap user's manual
by
-Bernardo Damele A. G.
version 0.6.2, 4th of November 2008
+Bernardo Damele A. G.version 0.6.3, DDth of November 2008
This document is the user's manual to use
sqlmap.
@@ -295,19 +295,19 @@ It is available in various formats:
$ python sqlmap.py -h
- sqlmap/0.6.2 coded by Bernardo Damele A. G. <bernardo.damele@gmail.com>
+ sqlmap/0.6.3 coded by Bernardo Damele A. G. <bernardo.damele@gmail.com>
and Daniele Bellucci <daniele.bellucci@gmail.com>
Usage: sqlmap.py [options] {-u <URL> | -g <google dork> | -c <config file>}
@@ -535,7 +535,7 @@ $ python sqlmap.py -u http://192.168.1.121/sqlmap/mysql/get_int.php?id=1&cat
[hh:mm:28] [TRAFFIC OUT] HTTP request:
GET /sqlmap/mysql/get_int.php?id=1&cat=2 HTTP/1.1
Host: 192.168.1.121:80
-User-agent: sqlmap/0.6.2 (http://sqlmap.sourceforge.net)
+User-agent: sqlmap/0.6.3 (http://sqlmap.sourceforge.net)
Connection: close
[...]
[hh:mm:29] [INFO] testing MySQL
@@ -544,7 +544,7 @@ Connection: close
GET /sqlmap/mysql/get_int.php?id=1%20AND%20ORD%28MID%28%28CONCAT%28CHAR%2852%29%2C%20
CHAR%2852%29%29%29%2C%201%2C%201%29%29%20%3E%2063%20AND%207994=7994&cat=2 HTTP/1.1
Host: 192.168.1.121:80
-User-agent: sqlmap/0.6.2 (http://sqlmap.sourceforge.net)
+User-agent: sqlmap/0.6.3 (http://sqlmap.sourceforge.net)
Connection: close
[...]
@@ -562,7 +562,7 @@ $ python sqlmap.py -u http://192.168.1.121/sqlmap/mysql/get_int.php?id=1&cat
[hh:mm:32] [TRAFFIC OUT] HTTP request:
GET /sqlmap/mysql/get_int.php?id=1&cat=2 HTTP/1.1
Host: 192.168.1.121:80
-User-agent: sqlmap/0.6.2 (http://sqlmap.sourceforge.net)
+User-agent: sqlmap/0.6.3 (http://sqlmap.sourceforge.net)
Connection: close
[hh:mm:32] [TRAFFIC IN] HTTP response (OK - 200):
@@ -580,7 +580,7 @@ Content-Type: text/html
GET /sqlmap/mysql/get_int.php?id=1%20AND%20ORD%28MID%28%28CONCAT%28CHAR%2852%29%2C%20
CHAR%2852%29%29%29%2C%201%2C%201%29%29%20%3E%2063%20AND%204435=4435&cat=2 HTTP/1.1
Host: 192.168.1.121:80
-User-agent: sqlmap/0.6.2 (http://sqlmap.sourceforge.net)
+User-agent: sqlmap/0.6.3 (http://sqlmap.sourceforge.net)
Connection: close
[hh:mm:33] [TRAFFIC IN] HTTP response (OK - 200):
@@ -607,7 +607,7 @@ $ python sqlmap.py -u http://192.168.1.121/sqlmap/mysql/get_int.php?id=1&cat
[hh:mm:23] [TRAFFIC OUT] HTTP request:
GET /sqlmap/mysql/get_int.php?id=1&cat=2 HTTP/1.1
Host: 192.168.1.121:80
-User-agent: sqlmap/0.6.2 (http://sqlmap.sourceforge.net)
+User-agent: sqlmap/0.6.3 (http://sqlmap.sourceforge.net)
Connection: close
[hh:mm:23] [TRAFFIC IN] HTTP response (OK - 200):
@@ -632,7 +632,7 @@ Content-Type: text/html
GET /sqlmap/mysql/get_int.php?id=1%20AND%20ORD%28MID%28%28CONCAT%28CHAR%2851%29%2C%20
CHAR%2851%29%29%29%2C%201%2C%201%29%29%20%3E%2063%20AND%201855=1855&cat=2 HTTP/1.1
Host: 192.168.1.121:80
-User-agent: sqlmap/0.6.2 (http://sqlmap.sourceforge.net)
+User-agent: sqlmap/0.6.3 (http://sqlmap.sourceforge.net)
Connection: close
[hh:mm:24] [TRAFFIC IN] HTTP response (OK - 200):
@@ -749,7 +749,7 @@ $ python sqlmap.py -u "http://192.168.1.121/sqlmap/pgsql/get_int.php?id=1&ca
$ python sqlmap.py -u "http://192.168.1.121/sqlmap/mysql/get_int.php?id=1&cat=2" -v 1 \
- -p user-agent --user-agent "sqlmap/0.6.2 (http://sqlmap.sourceforge.net)"
+ -p user-agent --user-agent "sqlmap/0.6.3 (http://sqlmap.sourceforge.net)"
[hh:mm:40] [WARNING] the testable parameter 'user-agent' you provided is not into the GET
[hh:mm:40] [INFO] testing connection to the target url
@@ -895,7 +895,7 @@ $ python sqlmap.py -u "http://192.168.1.125/sqlmap/get_str.asp?name=luther" -v 3
[hh:mm:39] [TRAFFIC OUT] HTTP request:
GET /sqlmap/get_str.asp?name=luther HTTP/1.1
Host: 192.168.1.125:80
-User-agent: sqlmap/0.6.2 (http://sqlmap.sourceforge.net)
+User-agent: sqlmap/0.6.3 (http://sqlmap.sourceforge.net)
Cookie: ASPSESSIONIDSABTRCAS=HPCBGONANJBGFJFHGOKDMCGJ
Connection: close
@@ -907,7 +907,7 @@ Connection: close
GET /sqlmap/get_str.asp?name=luther HTTP/1.1
Host: 192.168.1.125:80
Cookie: ASPSESSIONIDSABTRCAS=469
-User-agent: sqlmap/0.6.2 (http://sqlmap.sourceforge.net)
+User-agent: sqlmap/0.6.3 (http://sqlmap.sourceforge.net)
Connection: close
[hh:mm:40] [WARNING] Cookie parameter 'ASPSESSIONIDSABTRCAS' is not dynamic
@@ -955,7 +955,7 @@ $ python sqlmap.py -u "http://192.168.1.121/sqlmap/pgsql/get_int.php?id=1&ca
GET /sqlmap/pgsql/get_int.php?id=1&cat=2 HTTP/1.1
Host: 192.168.1.121:80
Referer: http://www.google.com
-User-agent: sqlmap/0.6.2 (http://sqlmap.sourceforge.net)
+User-agent: sqlmap/0.6.3 (http://sqlmap.sourceforge.net)
Connection: close
[...]
@@ -972,7 +972,7 @@ Connection: close
-sqlmap/0.6.2 (http://sqlmap.sourceforge.net)
+sqlmap/0.6.3 (http://sqlmap.sourceforge.net)
@@ -1058,7 +1058,7 @@ $ python sqlmap.py -u "http://192.168.1.121/sqlmap/mysql/basic/get_int.php?id=1&
GET /sqlmap/mysql/basic/get_int.php?id=1&cat=2 HTTP/1.1
Host: 192.168.1.121:80
Authorization: Basic dGVzdHVzZXI6dGVzdHBhc3M=
-User-agent: sqlmap/0.6.2 (http://sqlmap.sourceforge.net)
+User-agent: sqlmap/0.6.3 (http://sqlmap.sourceforge.net)
Connection: close
[...]
@@ -1075,7 +1075,7 @@ nonce="qcL9udlSBAA=f3b77da349fcfbf1a59ba37b21e291341159598f",
uri="/sqlmap/mysql/digest/get_int.php?id=1&cat=2",
response="e1bf3738b4bbe04e197a12fb134e13a2", algorithm="MD5", qop=auth, nc=00000001,
cnonce="df1c0902c931b640"
-User-agent: sqlmap/0.6.2 (http://sqlmap.sourceforge.net)
+User-agent: sqlmap/0.6.3 (http://sqlmap.sourceforge.net)
Connection: close
[...]
@@ -1164,6 +1164,14 @@ character of the query output. The thread then ends after approximately
seven HTTP requests, the maximum to retrieve a query output character.
+Delay in seconds between each HTTP request
+
+Option: --delay
+
+It is possible to specify a number of seconds to wait between each HTTP
+request. The valid value is a float, for instance 0.5.
+
+
5.2 Injection
@@ -1200,7 +1208,7 @@ $ python sqlmap.py -u "http://192.168.1.121/sqlmap/mysql/get_int_refresh.php?id=
[hh:mm:50] [TRAFFIC OUT] HTTP request:
GET /sqlmap/mysql/get_int_refresh.php?id=1&cat=2 HTTP/1.1
Host: 192.168.1.121:80
-User-agent: sqlmap/0.6.2 (http://sqlmap.sourceforge.net)
+User-agent: sqlmap/0.6.3 (http://sqlmap.sourceforge.net)
Connection: close
[hh:mm:50] [TRAFFIC IN] HTTP response (OK - 200):
@@ -1222,7 +1230,7 @@ Content-Type: text/html
[hh:mm:51] [TRAFFIC OUT] HTTP request:
GET /sqlmap/mysql/get_int_refresh.php?id=1&cat=2 HTTP/1.1
Host: 192.168.1.121:80
-User-agent: sqlmap/0.6.2 (http://sqlmap.sourceforge.net)
+User-agent: sqlmap/0.6.3 (http://sqlmap.sourceforge.net)
Connection: close
[hh:mm:51] [TRAFFIC IN] HTTP response (OK - 200):
@@ -1244,7 +1252,7 @@ Content-Type: text/html
[hh:mm:51] [TRAFFIC OUT] HTTP request:
GET /sqlmap/mysql/get_int_refresh.php?id=1&cat=2 HTTP/1.1
Host: 192.168.1.121:80
-User-agent: sqlmap/0.6.2 (http://sqlmap.sourceforge.net)
+User-agent: sqlmap/0.6.3 (http://sqlmap.sourceforge.net)
Connection: close
[hh:mm:51] [TRAFFIC IN] HTTP response (OK - 200):
@@ -2072,7 +2080,7 @@ Table: users
| 1 | luther | blissett |
| 2 | fluffy | bunny |
| 3 | wu | ming |
-| 4 | sqlmap/0.6.2 (http://sqlmap.sourceforge.net) | user agent header |
+| 4 | sqlmap/0.6.3 (http://sqlmap.sourceforge.net) | user agent header |
| 5 | NULL | nameisnull |
+----+----------------------------------------------+-------------------+
@@ -2126,7 +2134,7 @@ Table: users
| 1 | luther | blissett |
| 2 | fluffy | bunny |
| 3 | wu | ming |
-| 4 | sqlmap/0.6.2 (http://sqlmap.sourceforge.net) | user agent header |
+| 4 | sqlmap/0.6.3 (http://sqlmap.sourceforge.net) | user agent header |
| 5 | | nameisnull |
+----+----------------------------------------------+-------------------+
@@ -2140,7 +2148,7 @@ $ cat /software/sqlmap/output/192.168.1.121/dump/public/users.csv
"1","luther","blissett"
"2","fluffy","bunny"
"3","wu","ming"
-"4","sqlmap/0.6.2 (http://sqlmap.sourceforge.net)","user agent header"
+"4","sqlmap/0.6.3 (http://sqlmap.sourceforge.net)","user agent header"
"5","","nameisnull"
@@ -2170,7 +2178,7 @@ Table: users
+----+----------------------------------------------+-------------------+
| 2 | fluffy | bunny |
| 3 | wu | ming |
-| 4 | sqlmap/0.6.2 (http://sqlmap.sourceforge.net) | user agent header |
+| 4 | sqlmap/0.6.3 (http://sqlmap.sourceforge.net) | user agent header |
+----+----------------------------------------------+-------------------+
@@ -2201,7 +2209,7 @@ Table: users
| 1 | luther | blissett |
| 2 | fluffy | bunny |
| 3 | wu | ming |
-| 4 | sqlmap/0.6.2 (http://sqlmap.sourceforge.net) | user agent header |
+| 4 | sqlmap/0.6.3 (http://sqlmap.sourceforge.net) | user agent header |
| 5 | NULL | nameisnull |
+----+----------------------------------------------+-------------------+
@@ -2291,7 +2299,7 @@ Table: users
+----+----------------------------------------------+-------------------+
| id | name | surname |
+----+----------------------------------------------+-------------------+
-| 4 | sqlmap/0.6.2 (http://sqlmap.sourceforge.net) | user agent header |
+| 4 | sqlmap/0.6.3 (http://sqlmap.sourceforge.net) | user agent header |
| 2 | fluffy | bunny |
| 1 | luther | blisset |
| 3 | wu | ming |
@@ -2854,7 +2862,7 @@ GET /sqlmap/mysql/get_int.php?id=1%20UNION%20ALL%20SELECT%20NULL%2C%20CONCAT%28C
%2C%20CHAR%2832%29%29%2CCHAR%28122%2C110%2C105%2C89%2C121%2C65%29%29%2C%20NULL--%20AND%2
06043=6043&cat=2 HTTP/1.1
Host: 192.168.1.121:80
-User-agent: sqlmap/0.6.2 (http://sqlmap.sourceforge.net)
+User-agent: sqlmap/0.6.3 (http://sqlmap.sourceforge.net)
Connection: close
[hh:mm:25] [TRAFFIC IN] HTTP response (OK - 200):
@@ -2996,7 +3004,7 @@ $ python sqlmap.py --update -v 4
[hh:mm:55] [TRAFFIC OUT] HTTP request:
GET /doc/VERSION HTTP/1.1
Host: sqlmap.sourceforge.net
-User-agent: sqlmap/0.6.2 (http://sqlmap.sourceforge.net)
+User-agent: sqlmap/0.6.3 (http://sqlmap.sourceforge.net)
Connection: close
[hh:mm:55] [TRAFFIC IN] HTTP response (OK - 200):
@@ -3015,7 +3023,7 @@ X-Pad: avoid browser bug
[hh:mm:56] [TRAFFIC OUT] HTTP request:
GET /FAQs/SQLServerVersionDatabase/tabid/63/Default.aspx HTTP/1.1
Host: www.sqlsecurity.com
-User-agent: sqlmap/0.6.2 (http://sqlmap.sourceforge.net)
+User-agent: sqlmap/0.6.3 (http://sqlmap.sourceforge.net)
Cookie: .ASPXANONYMOUS=dvus03cqyQEkAAAANDI0M2QzZmUtOGRkOS00ZDQxLThhMTUtN2ExMWJiNWVjN2My0;
language=en-US
Connection: close
diff --git a/doc/README.pdf b/doc/README.pdf
index dcf086f2e34b7601dc53adf049ca6191a2ea1f78..78d54b3e6aa4ee736a10399245050ea1cd1a7e4b 100644
GIT binary patch
delta 107736
zcmb4q2Urx%(k?k?kSIB)h23SBU2@KdAVHLzGYFE=6;X+bFu+O@5hN->k|YI*3Ic+F
z1j(S}EJ@@J;5q;I{ogtFx%YWsd#1alr@Okk>aFUUoNn6DVcIf2VxWnL8W1OD5>a#X
zunp#N_2Tk#wD7(g1!sV?`QZP6SvzcLWb+TAynJRXJ=I|MQZcZ|^^Q0fEIe29+mEx*9Pq
z0^2-{%Y6ZU9%lQS?vw%ygT)2lQs>+Kf3zMPj0pW*4Iw1Yv^+%)EgpEunS(qn%+8DW
z9Klo5@n41U?~3Pd`}bek9&0;*ccDTf*NFgQj1`+P4>nJWNpzu&XJ)wixmc0`_ICZj
zm!3jzr%Y9X$(2Q!r+(GjRMKm=be`7U0G_i+2RG0A+&7c4iyPMHrfq)JEEr^E)jY7a
zH$|F=?4BQLB|zdvXg`YbQyb;7`0 fk+!9m92ZPf&!BdjTgcfXNG2LgCbSLdtczt2ld}N1Oya-iecyknR1-pF
zjX`_TDo&DG;zm}|U@ZvT$by4f yI0~dSu;f&QBTG1l#-do7B~*
zKFjdY&PCUy%bh3B8axKo>Syn@5a03&zYi7405!lAT;Mx6sq0#EsWz
zGHk(+5K_z0&5L;FB#rIZNlmWG()BKb@6T)VGXS%<}Kx6CvXfuE<#fGp<{oSH#0b
z>4+z+=eZUDlKaGw-;dqZ=SK)Tp9&KOd501W8Ev1~8#*pnO6|LC8Vet-Zp^SgqwT(%
z*G}K{t^vp?*e%OLz3if1VM)@Z_inE
z?Tv=C>!-IS@XTt~j|E
2}L4CgU1{A
zqeTrn!BZvw2dYjq9P#o5wr5=McJBvjk_-z&%VmW)3SFBo55*J<6Fsu+OWf*Jtuu_I
z*x#K!@;01@Aa%o`b6Zf%QcvSZmYJftL!>JADn(eYTIa^k+4X9Bj?9zKQB{V^_Ej-x
zBbsL|j|rV&O@RhKMt51+FwMrmK|-!CpdwxfF>}X_pwA$GlR9a>Fp{5_0zWQ@q
t_qVOM}#!D5luhpY~seWB%
z*ypE>WyWR
OuC=19Yu*l-lP
zHZZDSc$*Lm+~B;;{ur
8y)n`r{gv=)EY_T4RRcft3c_
zd9uPyymfQ>fMGE> gs|n^oRLjW{ecekMt@wX+&!P_
zy9UhY@wG|gqf-Xqk4C`tk`XWZN%?vmauOcT1Cw8#%pP?9qi~G+~fm-
zflz%p3-O*qcQ1x$_#}=Svvk&t!<2-<_zV2X^J{Tt<09Yn5#%60VhiMh39IDf|1i_l
zZ-G9J#}X+g9X)-=kWAVv#CrqW(*p)*n0FAN$UgPM*xIy6Tl8W)gE7sn$kFNU)`Aod
zc~QIk^tt