Unconfigured Ad Widget



No announcement yet.

Sql Injection com o SQLMAP

  • Filter
  • Tempo
  • Show
Clear All
new posts

  • Font Size
    Boa bem explicado .
    leia O político honesto não pode ser encontrado

    O político que você estava procurando não pode ser encontrado ou não existe!
    É uma lenda, trocou de nome ou está eternamente fora do ar.

    Por favor tente o seguinte:

    Verifique se você está mesmo votando na pessoa certa.
    Aguarde algumas décadas para uma renovação.
    Não adianta clicar no botão Voltar e tentar outro.

    HTTP Error 404 - Político honesto não encontrado.
    Internet Information Services (IIS)


    • Font Size
      Excelente Tutorial


      • Font Size
        Se puder me ajude nesse parameto .. onde eu dou continuacaco na minha busca pela DB do site

        19:11:27] [INFO] testing connection to the target URL
        [19:11:27] [WARNING] the web server responded with an HTTP error code (403) which could interfere with the results of the tests
        [19:11:27] [INFO] testing if the target URL is stable. This can take a couple of seconds
        [19:11:29] [INFO] target URL is stable
        [19:11:29] [INFO] testing if GET parameter 'id_categoria' is dynamic
        [19:11:29] [WARNING] GET parameter 'id_categoria' does not appear dynamic
        [19:11:29] [WARNING] heuristic (basic) test shows that GET parameter 'id_categoria' might not be injectable
        [19:11:29] [INFO] testing for SQL injection on GET parameter 'id_categoria'
        [19:11:30] [INFO] testing 'AND boolean-based blind - WHERE or HAVING clause'
        [19:11:33] [INFO] testing 'MySQL >= 5.0 AND error-based - WHERE or HAVING clause'
        [19:11:33] [INFO] testing 'PostgreSQL AND error-based - WHERE or HAVING clause'
        [19:11:34] [INFO] testing 'Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause'
        [19:11:35] [INFO] testing 'Oracle AND error-based - WHERE or HAVING clause (XMLType)'
        [19:11:36] [INFO] testing 'MySQL inline queries'
        [19:11:36] [INFO] testing 'PostgreSQL inline queries'
        [19:11:37] [INFO] testing 'Microsoft SQL Server/Sybase inline queries'
        [19:11:37] [INFO] testing 'Oracle inline queries'
        [19:11:37] [INFO] testing 'SQLite inline queries'
        [19:11:37] [INFO] testing 'MySQL > 5.0.11 stacked queries'
        [19:11:38] [INFO] testing 'PostgreSQL > 8.1 stacked queries'
        [19:11:39] [INFO] testing 'Microsoft SQL Server/Sybase stacked queries'
        [19:11:40] [INFO] testing 'MySQL > 5.0.11 AND time-based blind'
        [19:11:41] [INFO] testing 'PostgreSQL > 8.1 AND time-based blind'
        [19:11:41] [INFO] testing 'Microsoft SQL Server/Sybase time-based blind'
        [19:11:42] [INFO] testing 'Oracle AND time-based blind'
        [19:11:43] [INFO] testing 'MySQL UNION query (NULL) - 1 to 10 columns'
        [19:11:51] [INFO] testing 'Generic UNION query (NULL) - 1 to 10 columns'
        [19:11:51] [WARNING] using unescaped version of the test because of zero knowledge of the back-end DBMS. You can try to explicitly set it using option '--dbms'
        [19:12:01] [WARNING] GET parameter 'id_categoria' is not injectable
        [19:12:01] [CRITICAL] all tested parameters appear to be not injectable. Try to increase '--level'/'--risk' values to perform more tests. Also, you can try to rerun by providing either a valid value for option '--string' (or '--regexp')

        obrigado pela atencao

