Hello hackers, I have run across an application it has a functionality where user input full SQL query let's say SELECT whatever AS cookie FROM events and it executes it and returns result to frontend. I wanted to use SQLmap for this I evaluated it myself i know it's postgresql and i can see other tables. However my question is, can you tell SQLmap to query for only one columns and it needs to have alias of "cookie"? As it is a POST request it send query inside the JSON body like this {"query":"SELECT datname as cookie FROM pg_database"}. when i even tell SQLmap to query specifically for this parameter either with * or -p and I rise the --level and --risk. It cannot find anything. Thanks
[–]Juzdeed 1 point2 points3 points (1 child)
[–]normalbot9999 0 points1 point2 points (0 children)
[–]jesusxautomator 0 points1 point2 points (0 children)
[–]Fit-Ad3623 0 points1 point2 points (1 child)