Time based SQL injection found
by - Thursday, January 1, 1970 at 12:00 AM
Hey Guys! I found time based SQL injection in my university website. I am trying to extract the tables and records using sqlmap but it is taking so much time. Is there any other ways to extract tables and database? It is using Microsoft SQL and IIS
Reply
are you hacking them for a A+
Thanks @Sjni for VIP rank! You cool asf :pomhappy:
Reply
Try increasing thread count.

--threads=5
Telegram: @BreachPine
Thank you @Astaroth for God :pomlove:

Reply
(November 25, 2022, 09:24 PM)Amphibia Wrote: are you hacking them for a A+

Na not for grades it's an attendance system portal for teachers


(November 25, 2022, 09:25 PM)pine Wrote: Try increasing thread count.

--threads=5


It won't help in time based SQL injection. I have tried it
Reply
Persistence parameter could help, like increasing number o threads
Reply
(November 25, 2022, 09:24 PM)technologykailm Wrote: Hey Guys! I found time based SQL injection in my university website. I am trying to extract the tables and records using sqlmap but it is taking so much time. Is there any other ways to extract tables and database? It is using Microsoft SQL and IIS


Just specify the db name it said to u and the thechnique
Reply
if you dont have schema name you can force system to give an error. you may see schema name from there.
Reply


 Users viewing this thread: Time based SQL injection found: No users currently viewing.