0.添加sqlmap目录到环境变量,否则命令行中找不到sqlmap.py;
1.下载sqlmap.jar (不是sqlmap工具) ;
2.burp>extender>extensions,添加插件
3.添加后多了标签页“Sqlmap”;
4.选择目标请求,发送到sqlmap
5.弹出命令窗口:
C:\Users\TEST_Y~1\AppData\Local\Temp\\1563959877234.req,文件内容是接口请求详情:
POST /address/un_reg_list HTTP/1.1
accept: application/json
version: 1.0.0
Content-Type: application/json;charset=utf-8
Content-Length: 121
Host: 192.168.1.68:5000
Connection: close
Cookie: session=eyJ1c2VybmFtZSI6IjRiODAwODcyLWM3MDYtNDhlZS1iYTE1LWEzNGU0OTliYmY3YiJ9.XTghtA.pA7fW9n6pntnZ328ZLE_Uaa6BTA
User-Agent: okhttp/3.6.0
{"data":{"req_time":1563959604647,"customer_id":20181},"merchant_id":"crm-app","sign":"2b8fe3827f0154fa17371d8de801236e"}
6.burpsuite-sqlmap中可用添加参数
7.本机安装多版本python时,需要设置默认python为2.x版本;设置后重新启动burpsuite 。默认python3.x版本会如此提示:
D:\BurpsuiteUnlimited>sqlmap.py -r C:\Users\TEST_Y~1\AppData\Local\Temp\\1563957751189.req --level 3
[CRITICAL] incompatible Python version detected ('3.6.2'). For successfully running sqlmap you'll have to use version 2.6 or 2.7 (visit 'http://www.python.org/download/')