sqlmap 使用文件作为参数进行测试,以博客详情为例
1.选择一个想要测试的接口,在调试的状态下,点击该接口,然后鼠标右键选择复制为curl命令
2.转换 https://curlconverter.com/http/
3.写为一个文件,修改转换后的数据
4.进行测试
python3 sqlmap.py -r test_linlinfun_blog_show -v 3 --string='"code":0'返回结果:
[<span style="color:#ffa07a">15:29:50</span>] [<span style="color:#ffa07a">DEBUG</span>] skipping test <span style="color:#abe338">'PostgreSQL</span> > <span style="color:#f5ab35">8.1</span> time-based blind - ORDER BY, GROUP BY clause' because the level (<span style="color:#ffa07a">3</span>) is higher than the provided (<span style="color:#ffa07a">1</span>)
[<span style="color:#ffa07a">15:29:50</span>] [<span style="color:#ffa07a">DEBUG</span>] skipping test <span style="color:#abe338">'PostgreSQL</span> time-based blind - ORDER BY, GROUP BY clause (<span style="color:#ffa07a">heavy</span> query)' because the risk (<span style="color:#ffa07a">2</span>) is higher than the provided (<span style="color:#ffa07a">1</span>)
[<span style="color:#ffa07a">15:29:50</span>] [<span style="color:#ffa07a">DEBUG</span>] skipping test <span style="color:#abe338">'Microsoft</span> SQL Server/Sybase time-based blind - ORDER BY clause (<span style="color:#ffa07a">heavy</span> query)' because the risk (<span style="color:#ffa07a">2</span>) is higher than the provided (<span style="color:#ffa07a">1</span>)
[<span style="color:#ffa07a">15:29:50</span>] [<span style="color:#ffa07a">DEBUG</span>] skipping test <span style="color:#abe338">'Oracle</span> time-based blind - ORDER BY, GROUP BY clause (<span style="color:#ffa07a">DBMS_LOCK.SLEEP</span>)' because the level (<span style="color:#ffa07a">3</span>) is higher than the provided (<span style="color:#ffa07a">1</span>)
[<span style="color:#ffa07a">15:29:50</span>] [<span style="color:#ffa07a">DEBUG</span>] skipping test <span style="color:#abe338">'Oracle</span> time-based blind - ORDER BY, GROUP BY clause (<span style="color:#ffa07a">DBMS_PIPE.RECEIVE_MESSAGE</span>)' because the level (<span style="color:#ffa07a">3</span>) is higher than the provided (<span style="color:#ffa07a">1</span>)
[<span style="color:#ffa07a">15:29:50</span>] [<span style="color:#ffa07a">DEBUG</span>] skipping test <span style="color:#abe338">'Oracle</span> time-based blind - ORDER BY, GROUP BY clause (<span style="color:#ffa07a">heavy</span> query)' because the risk (<span style="color:#ffa07a">2</span>) is higher than the provided (<span style="color:#ffa07a">1</span>)
[<span style="color:#ffa07a">15:29:50</span>] [<span style="color:#ffa07a">DEBUG</span>] skipping test <span style="color:#abe338">'HSQLDB</span> >= <span style="color:#f5ab35">1.7</span>.<span style="color:#f5ab35">2</span> time-based blind - ORDER BY, GROUP BY clause (<span style="color:#ffa07a">heavy</span> query)' because the risk (<span style="color:#ffa07a">2</span>) is higher than the provided (<span style="color:#ffa07a">1</span>)
[<span style="color:#ffa07a">15:29:50</span>] [<span style="color:#ffa07a">DEBUG</span>] skipping test <span style="color:#abe338">'HSQLDB</span> > <span style="color:#f5ab35">2.0</span> time-based blind - ORDER BY, GROUP BY clause (<span style="color:#ffa07a">heavy</span> query)' because the risk (<span style="color:#ffa07a">2</span>) is higher than the provided (<span style="color:#ffa07a">1</span>)
[<span style="color:#ffa07a">15:29:50</span>] [<span style="color:#ffa07a">INFO</span>] testing <span style="color:#abe338">'Generic</span> UNION query (<span style="color:#ffa07a">NULL</span>) - <span style="color:#f5ab35">1</span> to <span style="color:#f5ab35">10</span> columns'
[<span style="color:#ffa07a">15:29:50</span>] [<span style="color:#ffa07a">PAYLOAD</span>] <span style="color:#f5ab35">1202</span>) ORDER BY <span style="color:#f5ab35">1</span>-- MJmi
[<span style="color:#ffa07a">15:29:50</span>] [<span style="color:#ffa07a">PAYLOAD</span>] <span style="color:#f5ab35">1202</span> ORDER BY <span style="color:#f5ab35">1</span>-- njcQ
[<span style="color:#ffa07a">15:29:51</span>] [<span style="color:#ffa07a">PAYLOAD</span>] <span style="color:#f5ab35">1202</span>') ORDER BY <span style="color:#f5ab35">1</span>-- wsRQ
[<span style="color:#ffa07a">15:29:51</span>] [<span style="color:#ffa07a">PAYLOAD</span>] <span style="color:#f5ab35">1202</span>' ORDER BY <span style="color:#f5ab35">1</span>-- MwCu
[<span style="color:#ffa07a">15:29:51</span>] [<span style="color:#ffa07a">PAYLOAD</span>] <span style="color:#f5ab35">1202</span> ORDER BY <span style="color:#f5ab35">1</span>-- GcAo
[<span style="color:#ffa07a">15:29:51</span>] [<span style="color:#ffa07a">DEBUG</span>] skipping test <span style="color:#abe338">'Generic</span> UNION query (<span style="color:#ffa07a">random</span> number) - <span style="color:#f5ab35">1</span> to <span style="color:#f5ab35">10</span> columns' because the level (<span style="color:#ffa07a">3</span>) is higher than the provided (<span style="color:#ffa07a">1</span>)
[<span style="color:#ffa07a">15:29:51</span>] [<span style="color:#ffa07a">DEBUG</span>] skipping test <span style="color:#abe338">'Generic</span> UNION query (<span style="color:#ffa07a">NULL</span>) - <span style="color:#f5ab35">11</span> to <span style="color:#f5ab35">20</span> columns' because the level (<span style="color:#ffa07a">2</span>) is higher than the provided (<span style="color:#ffa07a">1</span>)
[<span style="color:#ffa07a">15:29:51</span>] [<span style="color:#ffa07a">DEBUG</span>] skipping test <span style="color:#abe338">'Generic</span> UNION query (<span style="color:#ffa07a">random</span> number) - <span style="color:#f5ab35">11</span> to <span style="color:#f5ab35">20</span> columns' because the level (<span style="color:#ffa07a">3</span>) is higher than the provided (<span style="color:#ffa07a">1</span>)
[<span style="color:#ffa07a">15:29:51</span>] [<span style="color:#ffa07a">DEBUG</span>] skipping test <span style="color:#abe338">'Generic</span> UNION query (<span style="color:#ffa07a">NULL</span>) - <span style="color:#f5ab35">21</span> to <span style="color:#f5ab35">30</span> columns' because the level (<span style="color:#ffa07a">3</span>) is higher than the provided (<span style="color:#ffa07a">1</span>)
[<span style="color:#ffa07a">15:29:51</span>] [<span style="color:#ffa07a">DEBUG</span>] skipping test <span style="color:#abe338">'Generic</span> UNION query (<span style="color:#ffa07a">random</span> number) - <span style="color:#f5ab35">21</span> to <span style="color:#f5ab35">30</span> columns' because the level (<span style="color:#ffa07a">4</span>) is higher than the provided (<span style="color:#ffa07a">1</span>)
[<span style="color:#ffa07a">15:29:51</span>] [<span style="color:#ffa07a">DEBUG</span>] skipping test <span style="color:#abe338">'Generic</span> UNION query (<span style="color:#ffa07a">NULL</span>) - <span style="color:#f5ab35">31</span> to <span style="color:#f5ab35">40</span> columns' because the level (<span style="color:#ffa07a">4</span>) is higher than the provided (<span style="color:#ffa07a">1</span>)
[<span style="color:#ffa07a">15:29:51</span>] [<span style="color:#ffa07a">DEBUG</span>] skipping test <span style="color:#abe338">'Generic</span> UNION query (<span style="color:#ffa07a">random</span> number) - <span style="color:#f5ab35">31</span> to <span style="color:#f5ab35">40</span> columns' because the level (<span style="color:#ffa07a">5</span>) is higher than the provided (<span style="color:#ffa07a">1</span>)
[<span style="color:#ffa07a">15:29:51</span>] [<span style="color:#ffa07a">DEBUG</span>] skipping test <span style="color:#abe338">'Generic</span> UNION query (<span style="color:#ffa07a">NULL</span>) - <span style="color:#f5ab35">41</span> to <span style="color:#f5ab35">50</span> columns' because the level (<span style="color:#ffa07a">5</span>) is higher than the provided (<span style="color:#ffa07a">1</span>)
[<span style="color:#ffa07a">15:29:51</span>] [<span style="color:#ffa07a">DEBUG</span>] skipping test <span style="color:#abe338">'Generic</span> UNION query (<span style="color:#ffa07a">random</span> number) - <span style="color:#f5ab35">41</span> to <span style="color:#f5ab35">50</span> columns' because the level (<span style="color:#ffa07a">5</span>) is higher than the provided (<span style="color:#ffa07a">1</span>)
[<span style="color:#ffa07a">15:29:51</span>] [<span style="color:#ffa07a">DEBUG</span>] skipping test <span style="color:#abe338">'MySQL</span> UNION query (<span style="color:#ffa07a">NULL</span>) - <span style="color:#f5ab35">1</span> to <span style="color:#f5ab35">10</span> columns' because the level (<span style="color:#ffa07a">2</span>) is higher than the provided (<span style="color:#ffa07a">1</span>)
[<span style="color:#ffa07a">15:29:51</span>] [<span style="color:#ffa07a">DEBUG</span>] skipping test <span style="color:#abe338">'MySQL</span> UNION query (<span style="color:#ffa07a">random</span> number) - <span style="color:#f5ab35">1</span> to <span style="color:#f5ab35">10</span> columns' because the level (<span style="color:#ffa07a">3</span>) is higher than the provided (<span style="color:#ffa07a">1</span>)
[<span style="color:#ffa07a">15:29:51</span>] [<span style="color:#ffa07a">DEBUG</span>] skipping test <span style="color:#abe338">'MySQL</span> UNION query (<span style="color:#ffa07a">NULL</span>) - <span style="color:#f5ab35">11</span> to <span style="color:#f5ab35">20</span> columns' because the level (<span style="color:#ffa07a">2</span>) is higher than the provided (<span style="color:#ffa07a">1</span>)
[<span style="color:#ffa07a">15:29:51</span>] [<span style="color:#ffa07a">DEBUG</span>] skipping test <span style="color:#abe338">'MySQL</span> UNION query (<span style="color:#ffa07a">random</span> number) - <span style="color:#f5ab35">11</span> to <span style="color:#f5ab35">20</span> columns' because the level (<span style="color:#ffa07a">3</span>) is higher than the provided (<span style="color:#ffa07a">1</span>)
[<span style="color:#ffa07a">15:29:51</span>] [<span style="color:#ffa07a">DEBUG</span>] skipping test <span style="color:#abe338">'MySQL</span> UNION query (<span style="color:#ffa07a">NULL</span>) - <span style="color:#f5ab35">21</span> to <span style="color:#f5ab35">30</span> columns' because the level (<span style="color:#ffa07a">3</span>) is higher than the provided (<span style="color:#ffa07a">1</span>)
[<span style="color:#ffa07a">15:29:51</span>] [<span style="color:#ffa07a">DEBUG</span>] skipping test <span style="color:#abe338">'MySQL</span> UNION query (<span style="color:#ffa07a">random</span> number) - <span style="color:#f5ab35">21</span> to <span style="color:#f5ab35">30</span> columns' because the level (<span style="color:#ffa07a">4</span>) is higher than the provided (<span style="color:#ffa07a">1</span>)
[<span style="color:#ffa07a">15:29:51</span>] [<span style="color:#ffa07a">DEBUG</span>] skipping test <span style="color:#abe338">'MySQL</span> UNION query (<span style="color:#ffa07a">NULL</span>) - <span style="color:#f5ab35">31</span> to <span style="color:#f5ab35">40</span> columns' because the level (<span style="color:#ffa07a">4</span>) is higher than the provided (<span style="color:#ffa07a">1</span>)
[<span style="color:#ffa07a">15:29:51</span>] [<span style="color:#ffa07a">DEBUG</span>] skipping test <span style="color:#abe338">'MySQL</span> UNION query (<span style="color:#ffa07a">random</span> number) - <span style="color:#f5ab35">31</span> to <span style="color:#f5ab35">40</span> columns' because the level (<span style="color:#ffa07a">5</span>) is higher than the provided (<span style="color:#ffa07a">1</span>)
[<span style="color:#ffa07a">15:29:51</span>] [<span style="color:#ffa07a">DEBUG</span>] skipping test <span style="color:#abe338">'MySQL</span> UNION query (<span style="color:#ffa07a">NULL</span>) - <span style="color:#f5ab35">41</span> to <span style="color:#f5ab35">50</span> columns' because the level (<span style="color:#ffa07a">5</span>) is higher than the provided (<span style="color:#ffa07a">1</span>)
[<span style="color:#ffa07a">15:29:51</span>] [<span style="color:#ffa07a">DEBUG</span>] skipping test <span style="color:#abe338">'MySQL</span> UNION query (<span style="color:#ffa07a">random</span> number) - <span style="color:#f5ab35">41</span> to <span style="color:#f5ab35">50</span> columns' because the level (<span style="color:#ffa07a">5</span>) is higher than the provided (<span style="color:#ffa07a">1</span>)
[<span style="color:#ffa07a">15:29:51</span>] [<span style="color:#ffa07a">WARNING</span>] URI parameter '#<span style="color:#f5ab35">1</span>*' does not seem to be injectable
[<span style="color:#ffa07a">15:29:51</span>] [<span style="color:#ffa07a">CRITICAL</span>] all tested parameters do not appear to be injectable. Try to increase values for <span style="color:#abe338">'--level</span><span style="color:#abe338">'/</span><span style="color:#abe338">'--risk</span>' options if you wish to perform more tests. Also, you can try to rerun by providing a valid value for option <span style="color:#abe338">'--string</span>' as perhaps the string you have chosen does not match exclusively True responses. If you suspect that there is some kind of protection mechanism involved (<span style="color:#ffa07a">e.g.</span> WAF) maybe you could try to use option <span style="color:#abe338">'--tamper</span>' (<span style="color:#ffa07a">e.g.</span> <span style="color:#abe338">'--tamper=space2comment</span>') and/or switch <span style="color:#abe338">'--random-agent</span>'
[<span style="color:#ffa07a">15:29:51</span>] [<span style="color:#ffa07a">WARNING</span>] HTTP error codes detected during run:
<span style="color:#f5ab35">404</span> (<span style="color:#ffa07a">Not</span> Found) - <span style="color:#f5ab35">5</span> times
[<span style="color:#ffa07a">15:29:51</span>] [<span style="color:#ffa07a">DEBUG</span>] too many <span style="color:#f5ab35">4</span>xx and/or <span style="color:#f5ab35">5</span>xx HTTP error codes could mean that some kind of protection is involved (<span style="color:#ffa07a">e.g.</span> WAF)
[<span style="color:#f5ab35">*</span>] ending @ <span style="color:#f5ab35">15</span>:<span style="color:#f5ab35">29</span>:<span style="color:#f5ab35">51</span> /<span style="color:#f5ab35">2023</span><span style="color:#f5ab35">-12</span><span style="color:#f5ab35">-22</span>/
[<span style="color:#ffa07a">15:29:50</span>] [<span style="color:#ffa07a">DEBUG</span>] skipping test <span style="color:#abe338">'PostgreSQL</span> > <span style="color:#f5ab35">8.1</span> time-based blind - ORDER BY, GROUP BY clause' because the level (<span style="color:#ffa07a">3</span>) is higher than the provided (<span style="color:#ffa07a">1</span>)
[<span style="color:#ffa07a">15:29:50</span>] [<span style="color:#ffa07a">DEBUG</span>] skipping test <span style="color:#abe338">'PostgreSQL</span> time-based blind - ORDER BY, GROUP BY clause (<span style="color:#ffa07a">heavy</span> query)' because the risk (<span style="color:#ffa07a">2</span>) is higher than the provided (<span style="color:#ffa07a">1</span>)
[<span style="color:#ffa07a">15:29:50</span>] [<span style="color:#ffa07a">DEBUG</span>] skipping test <span style="color:#abe338">'Microsoft</span> SQL Server/Sybase time-based blind - ORDER BY clause (<span style="color:#ffa07a">heavy</span> query)' because the risk (<span style="color:#ffa07a">2</span>) is higher than the provided (<span style="color:#ffa07a">1</span>)
[<span style="color:#ffa07a">15:29:50</span>] [<span style="color:#ffa07a">DEBUG</span>] skipping test <span style="color:#abe338">'Oracle</span> time-based blind - ORDER BY, GROUP BY clause (<span style="color:#ffa07a">DBMS_LOCK.SLEEP</span>)' because the level (<span style="color:#ffa07a">3</span>) is higher than the provided (<span style="color:#ffa07a">1</span>)
[<span style="color:#ffa07a">15:29:50</span>] [<span style="color:#ffa07a">DEBUG</span>] skipping test <span style="color:#abe338">'Oracle</span> time-based blind - ORDER BY, GROUP BY clause (<span style="color:#ffa07a">DBMS_PIPE.RECEIVE_MESSAGE</span>)' because the level (<span style="color:#ffa07a">3</span>) is higher than the provided (<span style="color:#ffa07a">1</span>)
[<span style="color:#ffa07a">15:29:50</span>] [<span style="color:#ffa07a">DEBUG</span>] skipping test <span style="color:#abe338">'Oracle</span> time-based blind - ORDER BY, GROUP BY clause (<span style="color:#ffa07a">heavy</span> query)' because the risk (<span style="color:#ffa07a">2</span>) is higher than the provided (<span style="color:#ffa07a">1</span>)
[<span style="color:#ffa07a">15:29:50</span>] [<span style="color:#ffa07a">DEBUG</span>] skipping test <span style="color:#abe338">'HSQLDB</span> >= <span style="color:#f5ab35">1.7</span>.<span style="color:#f5ab35">2</span> time-based blind - ORDER BY, GROUP BY clause (<span style="color:#ffa07a">heavy</span> query)' because the risk (<span style="color:#ffa07a">2</span>) is higher than the provided (<span style="color:#ffa07a">1</span>)
[<span style="color:#ffa07a">15:29:50</span>] [<span style="color:#ffa07a">DEBUG</span>] skipping test <span style="color:#abe338">'HSQLDB</span> > <span style="color:#f5ab35">2.0</span> time-based blind - ORDER BY, GROUP BY clause (<span style="color:#ffa07a">heavy</span> query)' because the risk (<span style="color:#ffa07a">2</span>) is higher than the provided (<span style="color:#ffa07a">1</span>)
[<span style="color:#ffa07a">15:29:50</span>] [<span style="color:#ffa07a">INFO</span>] testing <span style="color:#abe338">'Generic</span> UNION query (<span style="color:#ffa07a">NULL</span>) - <span style="color:#f5ab35">1</span> to <span style="color:#f5ab35">10</span> columns'
[<span style="color:#ffa07a">15:29:50</span>] [<span style="color:#ffa07a">PAYLOAD</span>] <span style="color:#f5ab35">1202</span>) ORDER BY <span style="color:#f5ab35">1</span>-- MJmi
[<span style="color:#ffa07a">15:29:50</span>] [<span style="color:#ffa07a">PAYLOAD</span>] <span style="color:#f5ab35">1202</span> ORDER BY <span style="color:#f5ab35">1</span>-- njcQ
[<span style="color:#ffa07a">15:29:51</span>] [<span style="color:#ffa07a">PAYLOAD</span>] <span style="color:#f5ab35">1202</span>') ORDER BY <span style="color:#f5ab35">1</span>-- wsRQ
[<span style="color:#ffa07a">15:29:51</span>] [<span style="color:#ffa07a">PAYLOAD</span>] <span style="color:#f5ab35">1202</span>' ORDER BY <span style="color:#f5ab35">1</span>-- MwCu
[<span style="color:#ffa07a">15:29:51</span>] [<span style="color:#ffa07a">PAYLOAD</span>] <span style="color:#f5ab35">1202</span> ORDER BY <span style="color:#f5ab35">1</span>-- GcAo
[<span style="color:#ffa07a">15:29:51</span>] [<span style="color:#ffa07a">DEBUG</span>] skipping test <span style="color:#abe338">'Generic</span> UNION query (<span style="color:#ffa07a">random</span> number) - <span style="color:#f5ab35">1</span> to <span style="color:#f5ab35">10</span> columns' because the level (<span style="color:#ffa07a">3</span>) is higher than the provided (<span style="color:#ffa07a">1</span>)
[<span style="color:#ffa07a">15:29:51</span>] [<span style="color:#ffa07a">DEBUG</span>] skipping test <span style="color:#abe338">'Generic</span> UNION query (<span style="color:#ffa07a">NULL</span>) - <span style="color:#f5ab35">11</span> to <span style="color:#f5ab35">20</span> columns' because the level (<span style="color:#ffa07a">2</span>) is higher than the provided (<span style="color:#ffa07a">1</span>)
[<span style="color:#ffa07a">15:29:51</span>] [<span style="color:#ffa07a">DEBUG</span>] skipping test <span style="color:#abe338">'Generic</span> UNION query (<span style="color:#ffa07a">random</span> number) - <span style="color:#f5ab35">11</span> to <span style="color:#f5ab35">20</span> columns' because the level (<span style="color:#ffa07a">3</span>) is higher than the provided (<span style="color:#ffa07a">1</span>)
[<span style="color:#ffa07a">15:29:51</span>] [<span style="color:#ffa07a">DEBUG</span>] skipping test <span style="color:#abe338">'Generic</span> UNION query (<span style="color:#ffa07a">NULL</span>) - <span style="color:#f5ab35">21</span> to <span style="color:#f5ab35">30</span> columns' because the level (<span style="color:#ffa07a">3</span>) is higher than the provided (<span style="color:#ffa07a">1</span>)
[<span style="color:#ffa07a">15:29:51</span>] [<span style="color:#ffa07a">DEBUG</span>] skipping test <span style="color:#abe338">'Generic</span> UNION query (<span style="color:#ffa07a">random</span> number) - <span style="color:#f5ab35">21</span> to <span style="color:#f5ab35">30</span> columns' because the level (<span style="color:#ffa07a">4</span>) is higher than the provided (<span style="color:#ffa07a">1</span>)
[<span style="color:#ffa07a">15:29:51</span>] [<span style="color:#ffa07a">DEBUG</span>] skipping test <span style="color:#abe338">'Generic</span> UNION query (<span style="color:#ffa07a">NULL</span>) - <span style="color:#f5ab35">31</span> to <span style="color:#f5ab35">40</span> columns' because the level (<span style="color:#ffa07a">4</span>) is higher than the provided (<span style="color:#ffa07a">1</span>)
[<span style="color:#ffa07a">15:29:51</span>] [<span style="color:#ffa07a">DEBUG</span>] skipping test <span style="color:#abe338">'Generic</span> UNION query (<span style="color:#ffa07a">random</span> number) - <span style="color:#f5ab35">31</span> to <span style="color:#f5ab35">40</span> columns' because the level (<span style="color:#ffa07a">5</span>) is higher than the provided (<span style="color:#ffa07a">1</span>)
[<span style="color:#ffa07a">15:29:51</span>] [<span style="color:#ffa07a">DEBUG</span>] skipping test <span style="color:#abe338">'Generic</span> UNION query (<span style="color:#ffa07a">NULL</span>) - <span style="color:#f5ab35">41</span> to <span style="color:#f5ab35">50</span> columns' because the level (<span style="color:#ffa07a">5</span>) is higher than the provided (<span style="color:#ffa07a">1</span>)
[<span style="color:#ffa07a">15:29:51</span>] [<span style="color:#ffa07a">DEBUG</span>] skipping test <span style="color:#abe338">'Generic</span> UNION query (<span style="color:#ffa07a">random</span> number) - <span style="color:#f5ab35">41</span> to <span style="color:#f5ab35">50</span> columns' because the level (<span style="color:#ffa07a">5</span>) is higher than the provided (<span style="color:#ffa07a">1</span>)
[<span style="color:#ffa07a">15:29:51</span>] [<span style="color:#ffa07a">DEBUG</span>] skipping test <span style="color:#abe338">'MySQL</span> UNION query (<span style="color:#ffa07a">NULL</span>) - <span style="color:#f5ab35">1</span> to <span style="color:#f5ab35">10</span> columns' because the level (<span style="color:#ffa07a">2</span>) is higher than the provided (<span style="color:#ffa07a">1</span>)
[<span style="color:#ffa07a">15:29:51</span>] [<span style="color:#ffa07a">DEBUG</span>] skipping test <span style="color:#abe338">'MySQL</span> UNION query (<span style="color:#ffa07a">random</span> number) - <span style="color:#f5ab35">1</span> to <span style="color:#f5ab35">10</span> columns' because the level (<span style="color:#ffa07a">3</span>) is higher than the provided (<span style="color:#ffa07a">1</span>)
[<span style="color:#ffa07a">15:29:51</span>] [<span style="color:#ffa07a">DEBUG</span>] skipping test <span style="color:#abe338">'MySQL</span> UNION query (<span style="color:#ffa07a">NULL</span>) - <span style="color:#f5ab35">11</span> to <span style="color:#f5ab35">20</span> columns' because the level (<span style="color:#ffa07a">2</span>) is higher than the provided (<span style="color:#ffa07a">1</span>)
[<span style="color:#ffa07a">15:29:51</span>] [<span style="color:#ffa07a">DEBUG</span>] skipping test <span style="color:#abe338">'MySQL</span> UNION query (<span style="color:#ffa07a">random</span> number) - <span style="color:#f5ab35">11</span> to <span style="color:#f5ab35">20</span> columns' because the level (<span style="color:#ffa07a">3</span>) is higher than the provided (<span style="color:#ffa07a">1</span>)
[<span style="color:#ffa07a">15:29:51</span>] [<span style="color:#ffa07a">DEBUG</span>] skipping test <span style="color:#abe338">'MySQL</span> UNION query (<span style="color:#ffa07a">NULL</span>) - <span style="color:#f5ab35">21</span> to <span style="color:#f5ab35">30</span> columns' because the level (<span style="color:#ffa07a">3</span>) is higher than the provided (<span style="color:#ffa07a">1</span>)
[<span style="color:#ffa07a">15:29:51</span>] [<span style="color:#ffa07a">DEBUG</span>] skipping test <span style="color:#abe338">'MySQL</span> UNION query (<span style="color:#ffa07a">random</span> number) - <span style="color:#f5ab35">21</span> to <span style="color:#f5ab35">30</span> columns' because the level (<span style="color:#ffa07a">4</span>) is higher than the provided (<span style="color:#ffa07a">1</span>)
[<span style="color:#ffa07a">15:29:51</span>] [<span style="color:#ffa07a">DEBUG</span>] skipping test <span style="color:#abe338">'MySQL</span> UNION query (<span style="color:#ffa07a">NULL</span>) - <span style="color:#f5ab35">31</span> to <span style="color:#f5ab35">40</span> columns' because the level (<span style="color:#ffa07a">4</span>) is higher than the provided (<span style="color:#ffa07a">1</span>)
[<span style="color:#ffa07a">15:29:51</span>] [<span style="color:#ffa07a">DEBUG</span>] skipping test <span style="color:#abe338">'MySQL</span> UNION query (<span style="color:#ffa07a">random</span> number) - <span style="color:#f5ab35">31</span> to <span style="color:#f5ab35">40</span> columns' because the level (<span style="color:#ffa07a">5</span>) is higher than the provided (<span style="color:#ffa07a">1</span>)
[<span style="color:#ffa07a">15:29:51</span>] [<span style="color:#ffa07a">DEBUG</span>] skipping test <span style="color:#abe338">'MySQL</span> UNION query (<span style="color:#ffa07a">NULL</span>) - <span style="color:#f5ab35">41</span> to <span style="color:#f5ab35">50</span> columns' because the level (<span style="color:#ffa07a">5</span>) is higher than the provided (<span style="color:#ffa07a">1</span>)
[<span style="color:#ffa07a">15:29:51</span>] [<span style="color:#ffa07a">DEBUG</span>] skipping test <span style="color:#abe338">'MySQL</span> UNION query (<span style="color:#ffa07a">random</span> number) - <span style="color:#f5ab35">41</span> to <span style="color:#f5ab35">50</span> columns' because the level (<span style="color:#ffa07a">5</span>) is higher than the provided (<span style="color:#ffa07a">1</span>)
[<span style="color:#ffa07a">15:29:51</span>] [<span style="color:#ffa07a">WARNING</span>] URI parameter '#<span style="color:#f5ab35">1</span>*' does not seem to be injectable
[<span style="color:#ffa07a">15:29:51</span>] [<span style="color:#ffa07a">CRITICAL</span>] all tested parameters do not appear to be injectable. Try to increase values for <span style="color:#abe338">'--level</span><span style="color:#abe338">'/</span><span style="color:#abe338">'--risk</span>' options if you wish to perform more tests. Also, you can try to rerun by providing a valid value for option <span style="color:#abe338">'--string</span>' as perhaps the string you have chosen does not match exclusively True responses. If you suspect that there is some kind of protection mechanism involved (<span style="color:#ffa07a">e.g.</span> WAF) maybe you could try to use option <span style="color:#abe338">'--tamper</span>' (<span style="color:#ffa07a">e.g.</span> <span style="color:#abe338">'--tamper=space2comment</span>') and/or switch <span style="color:#abe338">'--random-agent</span>'
[<span style="color:#ffa07a">15:29:51</span>] [<span style="color:#ffa07a">WARNING</span>] HTTP error codes detected during run:
<span style="color:#f5ab35">404</span> (<span style="color:#ffa07a">Not</span> Found) - <span style="color:#f5ab35">5</span> times
[<span style="color:#ffa07a">15:29:51</span>] [<span style="color:#ffa07a">DEBUG</span>] too many <span style="color:#f5ab35">4</span>xx and/or <span style="color:#f5ab35">5</span>xx HTTP error codes could mean that some kind of protection is involved (<span style="color:#ffa07a">e.g.</span> WAF)
[<span style="color:#f5ab35">*</span>] ending @ <span style="color:#f5ab35">15</span>:<span style="color:#f5ab35">29</span>:<span style="color:#f5ab35">51</span> /<span style="color:#f5ab35">2023</span><span style="color:#f5ab35">-12</span><span style="color:#f5ab35">-22</span>/可以看到结果提示,“
[<span style="color:#ffa07a">CRITICAL</span>] all tested parameters do not appear to be injectable.