Re: [sqlmap-users] Blind injection
Brought to you by:
inquisb
From: Sebastian N. <seb...@sy...> - 2013-08-06 11:14:05
|
Hi, --second-order=S.. Resulting page URL searched for second-order response should be what you need :) Kind regards, Sebastian Nerz Am 06.08.2013 13:04, schrieb Marcell Fodor: > Hi, > > With manual testing, I have a working blind injection in post request. To > see if the result true/false sqlmap should check for a string at a > different page. In other words sqlmap should inject to A.php and check for > a string in B.php > > Can this be done? > > M > > > > ------------------------------------------------------------------------------ > Get your SQL database under version control now! > Version control is standard for application code, but databases havent > caught up. So what steps can you take to put your SQL databases under > version control? Why should you start doing it? Read more to find out. > http://pubads.g.doubleclick.net/gampad/clk?id=48897031&iu=/4140/ostg.clktrk > > > > _______________________________________________ > sqlmap-users mailing list > sql...@li... > https://lists.sourceforge.net/lists/listinfo/sqlmap-users > -- Sebastian Nerz Dipl.-Inform. IT-Security Consultant mailto:seb...@sy... ___________________________________________________________ SySS GmbH Wohlboldstraße 8 72072 Tübingen Germany Voice: +49 7071 407856-31 Fax: +49 7071 407856-19 WWW: http://www.syss.de PGP FP: 79DC 2CEC D18D F92F CBB4 AF09 D12D 26A4 9180 FDB2 Geschaeftsfuehrer Sebastian Schreiber Registergericht: Amtsgericht Stuttgart / HRB 382420 Steuernummer: 86118 / 55809 |