用于对抗样本、模型提取、提示注入、成员推断、训练投毒、LoRA 滥用、LLM 越狱等 AI/ML 相关 CTF 题;触发名:ctf-ai-ml
日本語の概要は準備中です。原文の説明を表示しています。
Strix sqlmap 命令手册,覆盖目标语法、无交互执行与常见枚举流程;触发名:strix-sqlmap
インストール方法を見るインストールする前に、エージェントに与えられる指示の中身を確認できます。
Official docs:
Canonical syntax:
sqlmap -u "<target_url_with_params>" [options]
High-signal flags:
-u, --url <url> target URL-r <request_file> raw HTTP request input-p <param> test specific parameter(s)--batch non-interactive mode--level <1-5> test depth--risk <1-3> payload risk profile--threads <n> concurrency--technique <letters> technique selection--forms parse and test forms from target page--cookie <cookie> and --headers <headers> authenticated context--timeout <seconds> and --retries <n> transport stability--tamper <scripts> WAF/input-filter evasion--random-agent randomize user-agent--ignore-proxy bypass configured proxy--dbs, -D <db> --tables, -D <db> -T <table> --columns, -D <db> -T <table> -C <cols> --dump--flush-session clear cached scan stateAgent-safe baseline for automation:
sqlmap -u "https://target.tld/item?id=1" -p id --batch --level 2 --risk 1 --threads 5 --timeout 10 --retries 1 --random-agent
Common patterns:
sqlmap -u "https://target.tld/item?id=1" -p id --batch --level 2 --risk 1 --threads 5sqlmap -u "https://target.tld/login" --data "user=admin&pass=test" -p pass --batch --level 2 --risk 1sqlmap -u "https://target.tld/login" --forms --batch --level 2 --risk 1 --random-agentsqlmap -u "https://target.tld/item?id=1" -p id --batch --dbssqlmap -u "https://target.tld/item?id=1" -p id --batch -D appdb --tablessqlmap -u "https://target.tld/item?id=1" -p id --batch -D appdb -T users -C id,email,role --dumpCritical correctness rules:
--batch in automation to avoid interactive prompts.-p when possible.--flush-session when retesting after request/profile changes.--level 1-2, --risk 1) and escalate only when needed.Usage rules:
--cookie/--headers) aligned with manual validation state.-D/-T/-C) over broad dump-first behavior.-h/--help during normal execution unless absolutely necessary.Failure recovery:
--flush-session.--threads and test targeted --tamper chains.--level/--risk gradually.If uncertain, query web_search with:
site:github.com/sqlmapproject/sqlmap/wiki/usage sqlmap <flag>
まだレビューはありません。使ってみた感想をお寄せください。
概要と使いどころ
用于对抗样本、模型提取、提示注入、成员推断、训练投毒、LoRA 滥用、LLM 越狱等 AI/ML 相关 CTF 题;触发名:ctf-ai-ml
日本語の概要は準備中です。原文の説明を表示しています。
用于 XSS、SQL 注入、SSTI、SSRF、XXE、JWT、鉴权绕过、文件上传、请求走私、OAuth/OIDC、SAML 与原型污染等 Web 类 CTF 题;触发名:ctf-web
日本語の概要は準備中です。原文の説明を表示しています。
用于缓冲区溢出、格式化字符串、堆利用、ROP、ret2libc、shellcode、内核利用、seccomp 绕过与沙箱逃逸等 pwn 类 CTF 题;触发名:ctf-pwn
日本語の概要は準備中です。原文の説明を表示しています。
用于 RSA、AES、ECC、格攻击、LWE、CVP、Coppersmith、Pollard、Wiener、填充预言机、GCM、KDF、伪随机数与零知识证明等密码学和数学类 CTF 题;触发名:ctf-crypto
日本語の概要は準備中です。原文の説明を表示しています。
用于公开资料检索、社交媒体分析、地理定位、DNS、用户名枚举、反向图片搜索、历史快照、公开记录与坐标识别等 OSINT 类 CTF 题;触发名:ctf-osint
日本語の概要は準備中です。原文の説明を表示しています。
用于混淆脚本、恶意样本、自定义加密协议、C2 流量、PE/.NET 二进制、RC4/AES 通信、YARA、shellcode、进程注入与反分析等恶意软件类 CTF 题;触发名:ctf-malware
日本語の概要は準備中です。原文の説明を表示しています。