Re: [sqlmap-users] Direct connection to Oracle supported?

2013-10-21 Thread inbox
 I wish it were so easy.  I tried with and without quotes and also specifying --dbms=Oracle I'll clone the github version and try that in case the Kali version is somehow screwed up.   Maybe you forgot the quotes ? python sqlmap.py -d "mysql://admin:admin@192.168.21.17:3306/testdb" -f --banner

Re: [sqlmap-users] Bug in SQLMap

2013-10-21 Thread FAZ
Thanks for your reply ... Test started -- October Webinars: Code for Performance Free Intel webinars can help you accelerate application performance. Explore tips for MPI, OpenMP, advanced profiling, and more. Get the most

Re: [sqlmap-users] Bug in SQLMap

2013-10-21 Thread Miroslav Stampar
Hi. I've made couple of changes this moment. Can you please retry it now? Also, in case that it fails again I would need more information about the data itself. Thing is that we are already prepared for large table dumps but your case is kind of specific. How many columns are there in that table?

Re: [sqlmap-users] post inject with blind-sql-injection

2013-10-21 Thread Miroslav Stampar
Hi. First thing that you have to be aware that web scanners like AppScan tend to give false positives here and there. You can check your sample by removing the "injection part" from the request itself. Put this into the request.txt file: POST /xxx/space.php?appname=feed&mod=home&act=ta HTTP/1

Re: [sqlmap-users] Direct connection to Oracle supported?

2013-10-21 Thread Yoan Agostini
Maybe you forgot the quotes ? python sqlmap.py -d "mysql://admin:admin@192.168.21.17:3306/testdb" -f --banner --dbs --users On Mon, Oct 21, 2013 at 8:17 PM, Miroslav Stampar < miroslav.stam...@gmail.com> wrote: > Hi. > > sqlmap supports it. Sample console output: > > $ python sqlmap.py -d "ora

Re: [sqlmap-users] Direct connection to Oracle supported?

2013-10-21 Thread Miroslav Stampar
Hi. sqlmap supports it. Sample console output: $ python sqlmap.py -d "oracle://SYSTEM:testpass@192.168.5.27:1521/testdb" -v 5 --banner sqlmap/1.0-dev-8dac47f - automatic SQL injection and database takeover tool http://sqlmap.org [!] legal disclaimer: Usage of sqlmap for attacking target

Re: [sqlmap-users] x-mac-turkish error report

2013-10-21 Thread Miroslav Stampar
Hi. Thank you for your report. It should be fixed now [1]. Kind regards, Miroslav Stampar [1] https://github.com/sqlmapproject/sqlmap/commit/8dac47f7e5d0b940c77ef77ef43713d24309ea91 On Mon, Oct 21, 2013 at 7:20 PM, warezhacking wrote: > I've got an error on my computer(windows) > > Windows 7

[sqlmap-users] x-mac-turkish error report

2013-10-21 Thread warezhacking
I've got an error on my computer(windows) Windows 7 Professional 64-bit [19:17:28] [WARNING] unknown web page charset 'x-mac-turkish'. Please report by e-mail to sqlmap-users@lists.sourceforge.net. -- October Webinars: C

[sqlmap-users] Direct connection to Oracle supported?

2013-10-21 Thread Brian Milliron
Using sqlmap on a recently updated Kali installation, I tried to connect to an Oracle db using this command: sqlmap -d Oracle://user:pass@10.10.10.10:1521/SID I get the error message "[CRITICAL] sqlmap was not able to fingerprint the back-end database management system. Support for this DBMS will

[sqlmap-users] post inject with blind-sql-injection

2013-10-21 Thread is2reg
method is post, but url have parameter following is data: ** POST /xxx/space.php?appname=feed&mod=home&act=ta HTTP/1.1 Content-Type: application/x-www-form-urlencoded; charset=utf-8 Accept: text/html, */*; q=0.01 X-Requested-With: XMLHttpRequest Cookie: CmProvid=js; WT_FPC=id=2