HELP! SQLMap Essentials - What's the contents of table flag4? (Case #4)

Hi, I have been struggling for 2 days now with this question . Almost nothing is mention in the module about JSON and I am quite new to all this. I was able to get the Request Headers into a File and then try to run sqlmap -r file.txt , but it gave me an error. If anyone can point me into the right direction i will appreciate it, I have been trying everyting and there is almost no information online about sqlmap addresing JSON. Thanks in advance for the help it is much appreciated.

Hey, without seeing the whole command you are using I can only take a guess. Feel free to DM me the line you are using.

However, make sure that you are structuring your data right. If you try to send: --data 'uid=1&name=test' to a server app expecting JSON, then its probably going to error out. Make sure your --data field is in JSON format when you run SQLMap. Also, as a soft rule, make sure you use --batch and --dump they are major time savers.

Try running with that, and DM me for if you need more clarity.

2 Likes

thanks! I actually was able to solve it with your help

No problem! Glad to hear that you got it.
-onthesauce