Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Not a bug Just a question seeking for help #5791

Open
agx47 opened this issue Oct 8, 2024 · 0 comments
Open

Not a bug Just a question seeking for help #5791

agx47 opened this issue Oct 8, 2024 · 0 comments

Comments

@agx47
Copy link

agx47 commented Oct 8, 2024

Hello,

I tested a symbol (') syntax error in the target www.example.com/id='. In the browser itself, I got no syntax error. However, when testing the same in Burp Suite, I received a syntax error, and the same occurred in the Python response.

Sqlmap cannot find the back-end DBMS unless I use --skip-urlencode, but that leads to the following message:

css
Copy code
It looks like the back-end DBMS is 'MySQL'. Do you want to skip test payloads specific for other DBMSes? [Y/n] y
For the remaining tests, do you want to include all tests for 'MySQL', extending the provided level (1) and risk (1) values? [Y/n] y
[18:20:44] [INFO] testing 'AND boolean-based blind - WHERE or HAVING clause'
[18:20:44] [PAYLOAD] 11
[18:20:45] [PAYLOAD] 11) AND 6931=3971 AND (6919 BETWEEN 6919 AND 6919
[18:20:45] [CRITICAL] unable to connect to the target URL. Sqlmap is going to retry the request(s)
Is there a parameter I should use for this case?

Sorry to bother you.

P.S.: Sqlmap didn’t find any WAF mechanisms.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant