sqlmapproject / sqlmap

Automatic SQL injection and database takeover tool
http://sqlmap.org
Other
32.51k stars 5.72k forks source link

This is not a false positive result, a self-written script calmly reads data from SQLITE and sqlmap does not want to, but I want to use your script because it is faster #4968

Closed JustiFox closed 2 years ago

JustiFox commented 2 years ago

This is not a false positive result, a self-written script calmly reads data from SQLi and sqlmap does not want to, but I want to use your script because it is faster

https://imgur.com/a/9Je9IzE

Originally posted by @JustiFox in https://github.com/sqlmapproject/sqlmap/issues/4965#issuecomment-1024737975

turboman99maker commented 2 years ago

I recognize something : are you using Acu ? :-(

stamparm commented 2 years ago

oh man. this doesn't look good

also, you are mentioning "self-written" script while i see an excerpt from some automated web scanning tool (Acunetix).

please, post a script to see what's going on. anything less than the script (e.g. "oh man, it was actually an Acunetix") and i'll close this down in less than a second and will instantly delete all the subsequent issues

JustiFox commented 2 years ago

sqli.zip script for getting tables from the database @stamparm the script copes with its task quite well, the screenshot from Acunetix was just as an example that not only slqmap shows sqli

stamparm commented 2 years ago

I need more info. Can you send URL to miroslav@sqlmap.org? The script itself doesn't show nor prove anything

JustiFox commented 2 years ago

I need more info. Can you send URL to miroslav@sqlmap.org? The script itself doesn't show nor prove anything

I sent the link to your email

stamparm commented 2 years ago

Discussed in email