diff --git a/doc/README.html b/doc/README.html index 61f77b6da..c62704f70 100644 --- a/doc/README.html +++ b/doc/README.html @@ -105,9 +105,9 @@ it packaged in their formats and ready to be installed. Windows users can download and install the Python setup-ready installer for x86, AMD64 and Itanium too.
sqlmap relies on the -Metasploit Framework for some of its post-exploitation takeover +Metasploit Framework for some of its post-exploitation takeover features. You need to grab a copy of it from the -download +download page - the required version is 3.5 or higher. For the ICMP tunneling out-of-band takeover technique, sqlmap requires Impacket library too.
@@ -418,7 +418,7 @@ subversion repository. message to the user.Switch: --predict-output
This switch is used in inference algorithm for sequential statistical
-prediction of characters of value being retrieved. Based on items given in
-txt/common-outputs.txt together with the knowledge of current
-enumeration used statistical table with the most promising values is being
-built. In case that the value can be found among the common output values,
-as the process progresses, subsequent character tables are being narrowed
-more and more. If used in combination with retrieval of common DBMS
-entities, as with system table names and privileges, speed up is
-significant. Of course, you can edit the common outputs file according to
-your needs if, for instance, you notice common patterns in database table
-names or similar.
txt/common-outputs.txt combined with the knowledge of current
+enumeration used. In case that the value can be found among the common
+output values, as the process progresses, subsequent character tables are
+being narrowed more and more. If used in combination with retrieval of
+common DBMS entities, as with system table names and privileges, speed up
+is significant. Of course, you can edit the common outputs file according
+to your needs if, for instance, you notice common patterns in database
+table names or similar.
Note that this switch is not compatible with --threads
switch.
Note that the multi-threading switch does not affect any other SQL -injection technique. The maximum number of concurrent requests is set to -10 for performance and site reliability reasons.
+The maximum number of concurrent requests is set to 10 for +performance and site reliability reasons.
Note that this switch is not compatible with
--predict-output switch.
--tamper switch.
@@ -1701,12 +1701,12 @@ def tamper(payload):
You can check valid and usable tamper scripts in the tamper/
directory.
Example against a MySQL target assuming > character, spaces and
-SELECT string are banned:
Example against a MySQL target assuming that > character,
+spaces and capital SELECT string are banned:
.-$ python sqlmap.py -u "http://debiandev/sqlmap/mysql/get_int.php?id=1" --tamper \ +$ python sqlmap.py -u "http://192.168.136.131/sqlmap/mysql/get_int.php?id=1" --tamper \ tamper/between.py,tamper/randomcase.py,tamper/space2comment.py -v 3 [hh:mm:03] [DEBUG] cleaning up configuration parameters @@ -1816,7 +1816,7 @@ injected) page content with the injected wrong page content. This way the distinction will be based upon string presence or regular expression match. -In cases with lot of active (e.g. scripts, embeds, etc.) content in the +
In cases with lot of active content (e.g. scripts, embeds, etc.) in the HTTP responses' body, you can filter pages (
@@ -2987,7 +2987,7 @@ a--text-onlyswitch) just for their textual content. This way, in a good number of cases, you can automatically tune the detection engine.<DB_NAME>/<TABLE_NAME>.csvfile intoYou can then use sqlmap itself to read and query the locally created SQLite 3 file. For instance,
+sqlite:///tmp/sqlmap/output/192.168.136.131/dump/testdb.sqlite3 --tablepython sqlmap.py -d -sqlite:///tmp/sqlmap/output/debiandev/dump/testdb.sqlite3 --table.Simple wizard interface for beginner users
diff --git a/doc/README.pdf b/doc/README.pdf index 6b1d90096..f47d69ccb 100644 --- a/doc/README.pdf +++ b/doc/README.pdf @@ -1685,13 +1685,13 @@ endobj /Type /Annot /Border[0 0 0]/H/I/C[0 1 1] /Rect [161.681 146.384 261.605 157.174] -/Subtype/Link/A<> +/Subtype/Link/A<> >> endobj 619 0 obj << /Type /Annot /Border[0 0 0]/H/I/C[0 1 1] /Rect [189.412 132.755 232.629 143.546] -/Subtype/Link/A<> +/Subtype/Link/A<> >> endobj 620 0 obj << /Type /Annot @@ -1994,7 +1994,7 @@ endobj /Type /Annot /Border[0 0 0]/H/I/C[0 1 1] /Rect [342.73 70.142 390.982 80.933] -/Subtype/Link/A<> +/Subtype/Link/A<> >> endobj 664 0 obj << /Type /Annot @@ -2446,7 +2446,7 @@ endobj /Type /Annot /Border[0 0 0]/H/I/C[0 1 1] /Rect [252.653 528.323 300.905 539.113] -/Subtype/Link/A<> +/Subtype/Link/A<> >> endobj 728 0 obj << /Type /Annot @@ -2912,16 +2912,21 @@ endobj /ProcSet [ /PDF /Text ] >> endobj 791 0 obj << -/Length 2138 +/Length 2110 /Filter /FlateDecode >> stream -xڭXKϯ`ywI|y\}"Bn]FɯO39ހ($ջ"oE>\+0*>^W5@ًBQލuD^»\$ʓh46ޟ~n[#j/l1_de Nrh kbM DFU4X %U8J 0rݠ>a6OMʌ MSMaKכ )|5nyIJ_eI=M=ki-g-Ei4 mRzA")<+q2!>(͇(OF;2~g4<.}az猷_9MC?'뇣dXi'l,ّy/![ z=@Arr=82 -䋀˸t.6A'iG=%YD2n(&HZ@lw@%/#&w4qŗRIb.Q?QϧiqRc겙:>cTH\~eqEq -6$ RZ,<ȑ'O-j="Fz`mZcѬǞݫA+aB/+{N7SZ@O nj۠k8%0y=ri{[`|d\iB+Acǻ@Kµ.h*&V.ql-l5=cf;KmU.d%b]&"|;:/tSTk EHdl⣖-F(;fԵ#P`3[]c=A#ˀX4Wa8 }r]Af ?%$A^BQX* }٦_RӇIs\% 9f8>1!W[{5R 7l4([w= [QS@ 26;Ar??Y+&"8 8+@:`1з2.fדnHXZ+N 4hD >F܈a* - 9W49,}d 1WFZ+ÿ"Ghh;y+90Gb0p DH"p F[րAF6 氀Rw.NȮ)k"y%s7Bs`f,{9 GIVYj(cIQ5`:[ZgӈkB6(4ޢ>0q Un 2Ձ&!C~hq̕[fpӻ' Z&cЏ[{NkRa|㨆fj#bWprż m`;F[?K#>c(/g!lT몀:X<4+(| $6ҴzR/Q4P/I-~K(2>ς([T;=\# -GP,2]uWs7}i` -%?ޮ-a"4* xⱨW,e;IZpO-+| ]<^rx4@t