what tool are people using to brute force things like current user and current database on endpoints vulnerable to blind and time based sqli? SQLmap identified it, but now i want to brute force it a character at a time instead of using a wordlist like —common-tables