Blind SQL injection is tricky because it usually involves brute-forcing to retrieve information.
While SQLMap is a great tool to retrieve information, custom scripts can be a better alternative in certain scenarios. For example:
- If the web application works differently where they b64-encode the SQL queries before submitting the web requests, SQLMap might not work well.
- If we have determined a payload that will bypass the target web application firewall, we may want to stick to it by defining the payload in our script instead of using SQLMap.
Overall, an exploit script will offer more flexibility.
- Add better algorithms like binary search