Comments (4)
Thank you for response again.
I see what you are saying now. It makes sense.
Thank you for help.
from scant3r.
hi @sinanozdemir
./scant3r.py -m headers
: for scanning headers not parameters , if you need to scan custom header you can add it in modules/headers.py
file
SCAN_Headers = [
'User-agent',
'referer',
'Example'
] # add you headers here
you can use -S
option for scan all parameters after the modules ends its work
$ echo 'http://testphp.vulnweb.com/search.php?test=query' | ./scant3r.py -m headers -S
best regards ❤️
from scant3r.
Thank you for your response, but adding the below headers still didn't return a valid SQL injection result:
Here are the headers:
I added a few of them to the headers.py:
echo 'http://sql1.webapp.site/newsdetails.php?id=26' | ./scant3r.py -m headers -S
still nothing:
I am not sure what's going on here.
Thanks
from scant3r.
if you add something like ' " \
in the parameter/headers do you get an sql error message in the response ?
If the answer is no, then this is not vulnerable for scant3r , because scant3r add " '
for get SQL error like syntax error | mysql_error | etc ..
, If the response includes this error, it will print that it is vulnerable
https://github.com/knassar702/scant3r/blob/master/wordlists/make_payload.py#L22
In this case, this is blind sql injection
you scan use SQLMAP project or scan it manually for example try to execute sleep(5)
function or something like that 😃
Some resources can help you
best regards ❤️
from scant3r.
Related Issues (20)
- Module Methods HOT 2
- Dont open this just a Demo videos and images
- how fix HOT 3
- Is it yet another nuclei like scanner? HOT 2
- Taking long time to scan HOT 3
- Facing error HOT 2
- NOt working HOT 4
- Tool Not Working HOT 4
- No option to set a Target URL. HOT 1
- Getting error of send the payload with 125 timeout value everytime running with file or url HOT 2
- 这种情况是否是误报呢?如果不是那应该如何利用? HOT 4
- [bug] Lorsrf doesn't work - AttributeError: 'list' object has no attribute 'json' HOT 2
- [bug] failed to resolve host name HOT 2
- Better error handler
- Lua Scripting
- Pipx installation? HOT 3
- create .file for scant3r
- [BUG] No output result HOT 1
- when install found error HOT 7
- cannot access scant3r after the installation - ~/.local/bin HOT 2
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from scant3r.