tamper-script

1 article
sort: new top best
clear filter
0 7/10

A researcher discovered SQL injection in an AWS-hosted sports company's X-Forwarded-Host header by chaining host header enumeration with time-based SQLi, then bypassed character blacklisting using sqlmap's between.py tamper script to extract the entire database.

Avinash Jain logicbomb AWS CloudFront ELB sqlmap between.py
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details